Skip to content

No hardware wallet (Ledger) signing path exists anywhere in the codebase #92

Description

@ndii-dev

For a wallet product, especially post the custody-model decision (see mock-db.ts issue above), non-custodial hardware-wallet signing is a common expectation. Nothing in lib/services or components references Ledger, WalletConnect, or any external signer interface — the entire codebase assumes either a mock or (once real) a server/browser-held key.

Definition of done:

  • Signing abstraction that can target either an in-app key or an external signer (Ledger via @ledgerhq/hw-transport-webhid or similar) without changing the transaction-building code above it
  • At minimum, Ledger XLM app integration for the send flow

Before opening a PR for this issue, read CONTRIBUTING.md.

This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:

  • Root cause / design-decision rationale in your own words — not a restatement of this issue
  • Every Definition of done bullet above addressed explicitly, with a one-line note on how
  • Evidence the code actually runs: pasted test/build output, a screen recording or before/after screenshots for UI changes, or real (non-mocked) logs for network/contract-facing work
  • New or updated tests included and shown passing (paste the output)
  • Any adjacent/related behavior this issue calls out re-verified, not assumed unaffected

PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.

Metadata

Metadata

Assignees

Labels

GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions