CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
423commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 51 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-priorityv6.4.6 release candidate (#3681)by Omar Hatem · 7ce3cd75 · Oct 5, 2026 · 5 filesMessage 53 · ThinTriage 0Details
Commit message · Omar Hatem

v6.4.6 release candidate (#3681)

just monero patches

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Security candidatefix: add new images and fix integration tests (#3679)by David Adegoke · ad93901a · Oct 5, 2026 · 17 filesMessage 80 · StrongInformational 15Details
Commit message · David Adegoke

fix: add new images and fix integration tests (#3679)

80/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 15/100

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to point at the new Robinhood QR asset, and tweaks how stablecoins are filtered in the currency picker. There is no code change that introduces a security vulnerability.

Lower-prioritymake charts respect fiat api mode (#3678)by malik1004x · 1f1ba779 · Oct 5, 2026 · 11 filesMessage 68 · AdequateTriage 0Details
Commit message · malik1004x

make charts respect fiat api mode (#3678)

* make charts respect fiat api mode

* remove unused blocprovider

* https -> http

* https -> http

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Lower-priorityCharts: detect missing older cached prices in _firstUnavailablePrice (#3675)by claude[bot] · bd8cc690 · Oct 5, 2026 · 1 fileMessage 81 · StrongTriage 0Details
Commit message · claude[bot]

Charts: detect missing older cached prices in _firstUnavailablePrice (#3675)

* Charts: detect missing older cached prices in _firstUnavailablePrice

Only the newest cached point was checked, so after loading a short range
(e.g. 30D or 1H) a longer range (1Y/ALL or 1D) skipped the API fetch and
showed only the shorter range's data. Now walk the cached points aligned
to the requested precision from the range start and return the first
missing slot (before the oldest point, in a gap, or after the newest),
tolerating a single missing slot. The existing newest-point check is kept.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XHSNx4epaJ8hpwuFvWjTmy

* Charts: drop comment and logging, use explicit type in _firstUnavailablePrice

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XHSNx4epaJ8hpwuFvWjTmy

---------

Co-authored-by: Claude <noreply@anthropic.com>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Security candidateAdd Robinhood Chain (#3398)by David Adegoke · 046e57c5 · Oct 4, 2026 · 143 filesMessage 76 · AdequateLow 35Details
Commit message · David Adegoke

Add Robinhood Chain (#3398)

* fix android CI

* feat: Add Robinhood Chain, all major flows done. minor issue now is our providers don't support it yet as its still pretty early, two weeks from launch

* feat: Add Robinhood Chain, all major flows done. minor issue now is our providers don't support it yet as its still pretty early, two weeks from launch

* Cleanup

* auto-reformat

* fix ui issue and contact listing for tokens

* fix: missing icons and crash for fee priority in settings

* chore: cleanup

* fixes from feedbacks

* fix: review issues and sync to latest dev
feat: switch history api to etherscan, add history toggle to privacy settings, exclude robETH from exchange pickers, skip tokens discovery for chains that moralis hasn't indexed, add tests

* fix: address Robinhood review comments

* fix: show Solana token icons in history

* fix: address review comments and default Robinhood to PublicNode

* fix: revert filter and refuse unmapped networks in provider

---------

Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive pathseed or entropy pathsigning or wallet path
AI analysis · Low 35/100

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction history, settings, and UI assets. There is no direct evidence in the commit of a security vulnerability, but the size and breadth of the change introduce ordinary implementation risks typical of adding a new EVM chain.

AI review queuedchore: migrate to hosted scalable CI (#3620)by cyan · 77e4b946 · Oct 3, 2026 · 23 filesMessage 65 · AdequateInformational 16Details
Commit message · cyan

chore: migrate to hosted scalable CI (#3620)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 16/100

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a hard-coded developer test certificate and private key for CI builds. There is no direct change to the wallet's user-facing code, cryptography, or network behavior. The main security concern is that the new CI provider and the committed test signing material could, in theory, be misused if secrets or build outputs leak, but the commit itself does not introduce a known vulnerability in the app.

Security candidatecw-1683-prepare-zano-removal (#3668)by malik1004x · 86616811 · Oct 3, 2026 · 12 filesMessage 76 · AdequateInformational 23Details
Commit message · malik1004x

cw-1683-prepare-zano-removal (#3668)

* wip zano removal

* add zano removal popup

* constantly show popup if user keeps using deprecated wallet

* add confirmation before viewing seed

* fix viewed check

* prevent wallet staying open after seed backup

* Update lib/entities/default_settings_migration.dart

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* add passphrase

* make popup scrollable

* delete deprecated seeds when wallet is deleted

* encrypt seeds

* also deprecate decred

* remove decred from available types

* remove backup logic

* showArrow: false,

* Remove deprecated wallet seeds deletion

Removed deprecated wallet seeds deletion from delete method.

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access controlsigning or wallet path
AI analysis · Informational 23/100

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, and stops new Zano/Decred wallets from being created. It also fixes a minor cleanup bug where a cached Zano wallet might not be closed before deletion. There is no direct evidence in the commit of an exploitable security vulnerability; the changes are primarily user-facing deprecation and data-preservation work.

AI review queuedonly check address validation once for old addressesby Omar · 1972efd0 · Oct 3, 2026 · 3 filesMessage 50 · ThinLow 29Details
Commit message · Omar

only check address validation once for old addresses

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 29/100

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address labels incorrectly if a stored address didn't match either the normal or hidden chain. Now it checks each old address only once, marks it as checked, and only flips the label if the address actually re-derives from the opposite chain. New addresses created by the wallet are marked correct-by-construction and skipped. The change is a correctness/performance fix rather than a clear security patch, but a mislabeled change address could in theory cause a user to share or reuse an address unexpectedly.

AI review queuedfix balance being stale cuz it's overriden by an old valueby Omar · 1de16191 · Oct 2, 2026 · 3 filesMessage 50 · ThinLow 33Details
Commit message · Omar

fix balance being stale cuz it's overriden by an old value

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 33/100

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per account, avoid updating balances when the network connection is lost, and make address validation non-blocking so it doesn't freeze the app. There is no direct evidence this was exploited or treated as a security vulnerability by the vendor.

Lower-priorityupdate swap providers [skip ci]by Omar · ddb75488 · Oct 2, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Omar

update swap providers [skip ci]

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Security candidateCw 1551 quick bitcoin wallet sync (#3446)by Serhii · d7ebf428 · Oct 2, 2026 · 84 filesMessage 76 · AdequateLow 33Details
Commit message · Serhii

Cw 1551 quick bitcoin wallet sync (#3446)

* add Wallet Accounts page and integrate UI

* account model refactor

* add walletInfoAccount table and API

* add WalletAccountList API

* add multi-account support for Electrum wallets

* add Bitcoin lightning card and card style handling

* refine account filtering and card selection

* update current account balance on wallet changes

* update configure.dar

* Use named parameters for card design

* Add Bitcoin account handling and refactor lookup

* refactor dashboard

* refactor cards UI and account balance handling

* Improve Bitcoin account selection and balances

* restrict unspent coin usage to current account

* filter transactions by current Bitcoin account

* refactor electrum wallet

* refactor address generation

* add accountIndex to address fetch logic

* Update configure.dart

* reload transactions on Bitcoin account change

* restore multiple BTC accounts and improve fetch

* show account balance with in btc

* track account index in Bitcoin transactions

* discover btc BIP39 accounts during restore

* fix account switching and card ordering bugs

* fix card customizer

* limit account name length in modal

* update BTC account list balance display

* auto-reformat

* formating fix

* skip HD map validation

* fix 0 balance issue

* minor fix

* quick bitcoin wallet sync

* restore shuffle change output

* restore address lookup fix

* Update electrum.dart

* remove account customizer

* Merge branch 'CW-1142-Add-accounts-feature-to-BTC' into CW-1551-Quick-Bitcoin-Wallet-Sync

* probe only segwit in account discovery

* add account discovery limit and tracking

* Improve Electrum sync account handling [skip ci]

* remove legacy monero account and address list UI

* rework BTC account balance refres

* avoid unnecessary BTC account reloads

* refactor account header in addresses page

* fix blank popup when editing an account

* fix: dedupe UTXO balance

* minor fix

* add Bitcoin current account API

* Apply batched suggestions from code review [skip ci]

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* address PR review comments [skip ci]

* remove account customizer and fix accounts init

* restrict extra BTC accounts to SegWit

* add BTC multi-account toggle

* Fix BTC sync gating and account balance update

* minor fix

* Update electrum_wallet.dart

* store selected account on WalletInfo

* Refine wallet account reset visibility

* refactor BTC address prep and move accounts page

* refactor account stack and customizer routing

* migrate legacy Lightning card styles

* unify dashboard account change state

* fix account routing and Electrum balances

* fix account setup and wallet cards UI

* disable Bitcoin Accounts for all hardware

* merge conflicts fix

* minor fixes

* update cards_view [skip ci]

* reverted cards view update [skip ci]

* fix asset name

* moved the transaction filtering into the electrum wallet

* localization

* disable accounts for watch-only wallets

* fix: stop card render from switching the wallet account

* fix: restore Lightning transactions in tx history

* minor fix

* fix: skip duplicate legacy address generation [skip ci]

* fix: correct account balance/design mismatch bugs

* addressing review comments

---------

Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
secret or key materialsigning boundarysigning or wallet path
AI analysis · Low 33/100

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The changes are mostly architectural, but they touch sensitive wallet logic such as key derivation, transaction selection, balance calculation, and address discovery. There is no explicit vendor statement that this is a security fix, and no CVE or independent researcher attribution is present in the commit materials.

AI review queuedfeat: prefill rescan height with the saved Monero and Zcash restore height (#3669)by Seth For Privacy · 0503d542 · Oct 2, 2026 · 5 filesMessage 85 · StrongInformational 19Details
Commit message · Seth For Privacy

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid typing the wrong height when rescanning the blockchain. There is no direct security bug in the code, but it slightly reduces the chance that a user accidentally rescans from block 0 (which would be slower and expose more transaction history/metadata) or enters an incorrect height.

Lower-prioritymove FiatConversionService to newer charts api (#3544)by malik1004x · 9679f91a · Sep 29, 2026 · 2 filesMessage 81 · StrongTriage 0Details
Commit message · malik1004x

move FiatConversionService to newer charts api (#3544)

* move FiatConversionService to newer charts api

* remove debug print

* disable strict parsing on getLatestPrice

* fix for lack of toDouble

* ci

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Security candidateMerge pull request #3658 from cake-tech/integration-test-fixesby David Adegoke · bc302f0e · Sep 27, 2026 · 3 filesMessage 83 · StrongInformational 16Details
Commit message · David Adegoke

Merge pull request #3658 from cake-tech/integration-test-fixes

fix: flaky integration test runs on the CI emulator

83/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
authentication pathmerge-commit duplicate discount
AI analysis · Informational 16/100

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a direct 'dismiss' call on notification bars with a safer helper that checks whether the bar is actually showing before trying to dismiss it, preventing a possible crash or visual glitch during PIN entry.

Security candidatefix: handle flushbar dismissalby Blazebrain · 88a7e72c · Sep 27, 2026 · 2 filesMessage 47 · ThinInformational 23Details
Commit message · Blazebrain

fix: handle flushbar dismissal

47/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 23/100

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddly. The new helper checks whether the banner is actually visible before dismissing it, and removes it from the navigation stack if it isn't. The change is a stability fix rather than a security vulnerability.

AI review queuedAdd onionbalance Tor frontends to default node lists (#3431)by Seth For Privacy · c8cad835 · Sep 26, 2026 · 5 filesMessage 81 · StrongInformational 21Details
Commit message · Seth For Privacy

Add onionbalance Tor frontends to default node lists (#3431)

* Add onionbalance Tor frontends to default node lists

Update the primary Monero and Zcash onion nodes to the new
load-balanced onionbalance frontends, add missing Cake Wallet Tor
nodes for Bitcoin and Litecoin, and use the mempool onion frontend
for Bitcoin fee fetching when Tor is enabled. All Cake Tor nodes are
marked isOfficial so they get the official-node badge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Remove per-instance Zcash Tor #2 node, superseded by onionbalance frontend

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 21/100

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and makes Bitcoin fee estimates use a Tor address when Tor mode is on. The changes are infrastructure/configuration updates rather than code fixes for a vulnerability. There is no direct evidence in the commit that this is a security patch, but routing traffic through Tor can improve user privacy.

Lower-priorityfix: test failure due to animationby Blazebrain · 7e84412e · Sep 26, 2026 · 1 fileMessage 79 · AdequateTriage 0Details
Commit message · Blazebrain

fix: test failure due to animation

79/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Explains rationale or failure mode✓ Mentions testing or verification! No meaningful explanatory body
AI review queuedfix: enter Lightning invoice amounts in sats (#3525)by Omid · fdb82675 · Sep 26, 2026 · 2 filesMessage 93 · StrongInformational 19Details
Commit message · Omid

fix: enter Lightning invoice amounts in sats (#3525)

LN receive remapped btcln to BTC, so the default "sats (LN)" display mode never applied and the amount field stayed in BTC.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Konstantin Ullrich <konstantin@cakewallet.com>

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was being remapped incorrectly. The patch makes the receive screen explicitly set the currency to the Lightning-specific code so the amount field displays in sats as intended. There is no indication this allowed theft, unauthorized access, or code execution; it is a usability/display fix.

Lower-priorityfix: fail the integration tests check on branches without the test suitesby Blazebrain · 63d67da5 · Sep 25, 2026 · 1 fileMessage 72 · AdequateTriage 0Details
Commit message · Blazebrain

fix: fail the integration tests check on branches without the test suites

72/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
documentation-only discount
Lower-priorityfix: skip integration tests on branches without the test suitesby Blazebrain · 3a31bbac · Sep 25, 2026 · 1 fileMessage 72 · AdequateTriage 0Details
Commit message · Blazebrain

fix: skip integration tests on branches without the test suites

72/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
documentation-only discount
Lower-priorityfix: flaky integration test runs on the CI emulatorby Blazebrain · 45e06ec9 · Sep 25, 2026 · 2 filesMessage 72 · AdequateTriage 0Details
Commit message · Blazebrain

fix: flaky integration test runs on the CI emulator

72/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
documentation-only discount
AI review queuedRevert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)by Omar Hatem · 2d8d0684 · Sep 25, 2026 · 10 filesMessage 73 · AdequateModerate 60Details
Commit message · Omar Hatem

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This reverts commit dd58455ea6d2629eb1a28991e40bf6f9953d41d3.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 60/100

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. The change also fixes how non-English characters are stored and how user-chosen versus app-generated passwords are handled. Because this is a security-hardening change that was previously reverted and then re-applied, it is relevant to security, but the commit itself does not describe a specific vulnerability or incident.

Lower-prioritychange default charts range to 30 days (#3654)by malik1004x · 12634865 · Sep 24, 2026 · 1 fileMessage 53 · ThinTriage 0Details
Commit message · malik1004x

change default charts range to 30 days (#3654)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityadd commit/branch overlay for ci builds (#3653)by malik1004x · 0d14b57e · Sep 24, 2026 · 7 filesMessage 68 · AdequateTriage 0Details
Commit message · malik1004x

add commit/branch overlay for ci builds (#3653)

* add commit/branch overlay for ci builds

* add ability to show/hide overlay

* add alert when disabling the overlay

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Lower-priorityImplement apiString on the cw_core test FiatCurrency helper (#3649)by cyan · b7247dd0 · Sep 24, 2026 · 1 fileMessage 83 · StrongTriage 0Details
Commit message · cyan

Implement apiString on the cw_core test FiatCurrency helper (#3649)

Co-authored-by: sethforprivacy <40500387+sethforprivacy@users.noreply.github.com>

83/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference