generateKeypair() in src/services/stellar.ts calls StellarSdk.Keypair.random() directly, which under the hood depends on a CSPRNG being correctly polyfilled in the Hermes/Expo runtime (expo-crypto or react-native-get-random-values typically need explicit setup for crypto.getRandomValues to be cryptographically sound rather than falling back to a weak Math.random-based shim some libraries silently use). expo-crypto is a listed dependency but is never imported anywhere in the codebase — confirm it's actually wired into whatever @stellar/stellar-sdk's random source resolves to at runtime on-device, not just present in package.json.
Definition of done:
- Runtime-verified (not just code-read) proof of which RNG implementation actually executes on both iOS and Android release builds
- Automated check (even a startup self-test) that fails loudly if the CSPRNG polyfill isn't correctly linked
- Documented remediation if the audit finds a weak fallback in use
Before opening a PR for this issue, read CONTRIBUTING.md.
This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:
PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.
generateKeypair()insrc/services/stellar.tscallsStellarSdk.Keypair.random()directly, which under the hood depends on a CSPRNG being correctly polyfilled in the Hermes/Expo runtime (expo-cryptoorreact-native-get-random-valuestypically need explicit setup forcrypto.getRandomValuesto be cryptographically sound rather than falling back to a weak Math.random-based shim some libraries silently use).expo-cryptois a listed dependency but is never imported anywhere in the codebase — confirm it's actually wired into whatever@stellar/stellar-sdk's random source resolves to at runtime on-device, not just present inpackage.json.Definition of done:
Before opening a PR for this issue, read CONTRIBUTING.md.
This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:
PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.