Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Cashu: update SECURITY.md for the Cashu trust model before general availability

Open
#392 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
45/100
Issue type
Documentation
Clarity
Mostly clear
Activity status
Quiet
Tech stack
markdown, rust, sqlite

Research direction

Start with SECURITY.md, then read docs/cashu/README.md around C10 and the Cashu trust-model references in api/cashu.rs and the spec’s risk #9. Update the in-scope and out-of-scope lists, clarify mint custody, and make the seed-recovery advisory match the shipped restore and backup mechanisms, including NUT-09 and escrow limits. Done means the security guidance accurately reflects the shipped Cashu behavior and the release-blocking checklist is updated.

Written by the indexing model from the issue text.

Description

Summary

SECURITY.md describes a client that handles "private keys, Lightning payments, and end-to-end encrypted messages". Once Cashu mode reaches users (C5/C6 onward of docs/cashu/README.md), that model is materially incomplete. This issue tracks updating it as part of the Cashu release-blocking checklist (Wave 4 / C10), so it lands before general availability — not after.

What changes with Cashu mode

  1. A new in-scope attack surface: the embedded wallet. Ecash proofs are bearer assets stored in a local DB (cdk-sqlite). Theft or corruption of that DB is direct loss of user funds — a failure class that does not exist in Lightning mode. The Rust core scope list should name it.
  2. Third-party mints belong in the out-of-scope list, exactly as third-party relays, Lightning wallets and Mostro nodes already are: "Cashu mints operated by others — report to their own projects."
  3. The "non-custodial" framing needs a qualifier. In Cashu mode the mint custodies value while ecash is held and while an escrow is locked. The client remains non-custodial in the key sense, but the trust model shifts — the spec itself acknowledges this (risk #9) and asks the client for transparency. The Security Model section should say it plainly.
  4. The User Advisory needs precision about what the seed recovers. The C2 wallet deliberately uses the identity's BIP-39 seed (api/cashu.rs → current_bip39_seed(); the design comment says "the ecash is recoverable from it"), so a restore scan (NUT-09) can rebuild the spendable balance from seed alone — but that depends on three things the advisory should not gloss over: the scan feature is not implemented yet (no restore in the API surface — a C10 candidate next to backup), the mint must support NUT-09, and escrow-locked tokens are not seed-derived (they are recovered via the 2-of-3/refund paths instead). SECURITY.md should state exactly what the seed recovers and under which conditions, so a reinstalling user knows what to expect.

Proposal

  • Add a line to the C10 release-blocking list in docs/cashu/README.md: "SECURITY.md updated for the Cashu trust model (embedded bearer-asset wallet in scope, third-party mints out of scope, seed-vs-backup recovery advisory)".
  • Draft the actual SECURITY.md changes when C10 lands, so the text matches what shipped (e.g. exact backup mechanism).

Nothing here blocks the current PR series; filing it now so it cannot be forgotten between "the flows work" and "users can choose a Cashu node".

Dominant language
Dart
Stars
11
Forks
9
Avg merge
13h 4m
Merged PRs (30d)
259

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from MostroP2P/app

All issues in MostroP2P/app

Similar issues

More Dart issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.