Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…
This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…
New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…
Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …
New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…
Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…
Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…
Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…
UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…
No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…
UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…
Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…
No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…
Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…
Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…
Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…
New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …
Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…
Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…
This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…
Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit is a routine German translation update. It adds, removes, and tweaks German text strings used in the app's user interface. There is no code change and no security impact.
AI review queuedShuffle input order on bitcoin sends (#3379)by Cindy · 031a117f · Jul 14, 2026 · 1 fileMessage 53 · ThinLow 32Details
Commit message · Cindy
Shuffle input order on bitcoin sends (#3379)
53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 32/100
This change makes Bitcoin transactions shuffle the order of their inputs (the coins being spent). Shuffling input order is a common privacy improvement because it makes it harder for outside observers to guess which inputs belong to the same wallet or link transactions together. It does not fix a crash, theft bug, or direct exploit.
disable dismissing or dragging down SendConfirmSheet (#3386)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 27/100
This commit makes several small UI and error-handling tweaks in a cryptocurrency wallet app. The most user-relevant change is that address and amount text fields now disable autocorrect and predictive suggestions, which reduces the chance that a sensitive crypto address or amount gets leaked to a third-party keyboard/cloud service. Other changes clean up clipboard pasting, Bluetooth error handling, and which non-fatal errors are suppressed. There is no obvious severe security bug being fixed, but the autocorrect change is a privacy improvement.
AI review queuedadd paddingby Robert Malikowski · 90cbf677 · Jul 13, 2026 · 5 filesMessage 0 · OpaqueInformational 15Details
Commit message · Robert Malikowski
add padding
0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit is a routine UI polish: it adds bottom padding to a transaction history list and renames an internal counter from 'enabledProviders' to 'enabledProvidersCount' to make the code clearer. There is no security change.
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 44/100
This commit fixes two bugs in Cake Wallet's exchange flow. First, when creating a trade record for the NEAR Intents exchange provider, the app was accidentally recording the 'from' currency as both the source and destination currency. Second, the code that checks whether the user's wallet can send funds for a trade was refactored to return error strings instead of throwing exceptions, and logging of those errors was moved to the caller. The first fix is a real functional bug that could mislead users about what they are receiving in a trade. The second is mostly a code-quality and reliability improvement.
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100
This commit wraps a lightning balance lookup in a try/catch so that if the lookup fails, the app logs an error instead of crashing or throwing an unhandled exception. It is a defensive reliability fix; there is no direct evidence it fixes an exploitable security vulnerability.
refactor send validation and near token parsing (#3351)
* refactor send validation and near token parsing
* fix exchange send validation[skip ci]
73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Lower-prioritytentative fix for linux ciby Blazebrain · 49f5a24e · Jul 12, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Blazebrain
tentative fix for linux ci
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedImprove how wallets are renamed. (#3352)by Omar Hatem · 00088502 · Jul 12, 2026 · 16 filesMessage 76 · AdequateLow 32Details
Commit message · Omar Hatem
Improve how wallets are renamed. (#3352)
* Improve how wallets are renamed. affected wallets (Electrum-like) (BTC, LTC, BCH, Doge)
* more improvements also added Solana, Tron, EVM
76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 32/100
This commit refactors how Cake Wallet renames cryptocurrency wallets. Previously, each wallet type had its own rename code that opened the wallet, copied specific files, and deleted the old directory. The new code centralizes the file-copying logic and makes the process more consistent across Bitcoin-like coins, Litecoin, Bitcoin Cash, Dogecoin, EVM chains, Solana, and Tron. The change appears to be a code-quality and reliability improvement rather than an obvious security fix, but it does address some risky patterns in the old rename implementation—such as deleting the old wallet directory before confirming the new one is valid, and not checking whether the destination wallet already exists.
Lower-priorityfeat: add `ToMoney` extension for double type and refactor currency amount conversions (#3391)by Konstantin Ullrich · 77f305af · Jul 12, 2026 · 3 filesMessage 70 · AdequateTriage 0Details
Commit message · Konstantin Ullrich
feat: add `ToMoney` extension for double type and refactor currency amount conversions (#3391)
70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit changes the source of a software dependency (ledger-usb-plus) from a third-party developer's repository to Cake Wallet's own fork, and updates which version is used. The stated reason is to fix Android CI (continuous integration). There is no direct evidence in the commit that this is a security fix, but switching dependency sources can carry supply-chain security implications that are worth reviewing.
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
AI review queuedfix styling on new wallet type selection (#3392)by malik1004x · f4b17e33 · Jul 10, 2026 · 1 fileMessage 53 · ThinInformational 15Details
Commit message · malik1004x
fix styling on new wallet type selection (#3392)
53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit is a purely cosmetic UI fix for the wallet type selection screen in the Cake Wallet app. It wraps a list container in a rounded clipping widget, slightly increases row height from 48 to 50 pixels, and adjusts indentation. There is no security-relevant change.
payjoin: exclude 0-conf inputs from receiver candidates (#3389)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 48/100
This change stops Payjoin transactions from using unconfirmed (0-confirmation) coins as inputs when the wallet is acting as the receiver in a Payjoin swap. Before the fix, the receiver could accidentally propose or sign a Payjoin that relied on coins that had not yet been mined into a block. Such coins can disappear, be double-spent, or get replaced, which could cause the Payjoin to fail, be invalid, or expose the receiver to loss or confusion. The fix adds an optional 'confirmed only' filter and turns it on for Payjoin receiver candidate inputs.
✓ Descriptive subject✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedfeat: harden spam detection for solana and evm (#3322)by David Adegoke · a7073df4 · Jul 10, 2026 · 5 filesMessage 93 · StrongModerate 51Details
Commit message · David Adegoke
feat: harden spam detection for solana and evm (#3322)
* feat: harden spam detection for solana and evm
* fix: guard scam/impersonator tokens from auto-enabling on EVM and Solana
* feat: enhance token property validation for scam detection
93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Moderate 51/100
This commit strengthens the wallet's automatic detection and handling of scam, spam, and impersonator tokens on Ethereum-compatible (EVM) chains and Solana. It adds checks for suspicious names/symbols (e.g., fake 'ETH', 'SOL', 'USDC', or tokens with 'airdrop', 'claim', URLs), prevents auto-enabling tokens that look like well-known coins but aren't verified, and uses Moralis API data such as price, value, verified-contract status, and security score to decide whether a discovered token should be shown as enabled. It also re-runs a one-time cleanup on existing tokens to reclassify any previously missed scams. There is no direct exploit fixed in the diff; rather, it is a defensive hardening change against social-engineering/token-spam attacks.
Lower-priorityfeat(exchange): add TRX and USDT-on-Tron to Chainflip (#3341)by David Cumps · c9e0ac85 · Jul 9, 2026 · 1 fileMessage 100 · StrongTriage 0Details
Commit message · David Cumps
feat(exchange): add TRX and USDT-on-Tron to Chainflip (#3341)
Chainflip added Tron support with asset ids trx.tron and usdt.tron. Enable both for swaps in the Chainflip provider.
Tron needs explicit handling because Chainflip's network slug is 'tron', while Cake uses the 'TRX' tag (and null for native TRX), so the generic title.tag normalization can't produce the right ids: - _supported: add trx, usdttrc20 - _normalizeCurrency: map trx -> trx.tron, usdttrc20 -> usdt.tron - _normalizeNetworkName: TRON -> Tron (status lookup in findTradeById) - _toCurrency: reverse-map trx.tron/usdt.tron for trade resolution
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference
Lower-priorityfix failing test based on resolver refactor (#3384)by David Adegoke · da9f0d62 · Jul 9, 2026 · 1 fileMessage 68 · AdequateTriage 0Details
Commit message · David Adegoke
fix failing test based on resolver refactor (#3384)
68/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedif input transactions are not all fetched correctly or had a failure,… (#3353)by Omar Hatem · 910a5cd9 · Jul 8, 2026 · 3 filesMessage 81 · StrongLow 34Details
Commit message · Omar Hatem
if input transactions are not all fetched correctly or had a failure,… (#3353)
* if input transactions are not all fetched correctly or had a failure, still parse the transaction correctly instead of skipping it
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 34/100
This commit changes how Cake Wallet handles Bitcoin transactions when it cannot fetch all of their 'input' transaction data from the Electrum server. Previously, such transactions were skipped entirely and not shown in the wallet. Now they are still parsed and displayed, but with a warning ('Transaction has missing data') and a null fee. The change also makes the list of input transactions nullable and adds null checks in fee-calculation and replace-by-fee code paths, throwing errors if input data is missing there. This is primarily a robustness/usability fix, but it touches transaction parsing and fee logic, which are security-sensitive areas.
✓ Descriptive subject✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Low 39/100
This is a large code refactor of Cake Wallet's address resolver feature, which turns human-readable names (like Twitter handles, ENS domains, or email-style addresses) into cryptocurrency addresses. The change reorganizes existing lookup logic into a cleaner provider/service pattern and adds new address sources such as Nostr, BIP353, and Zcash names. It is primarily a structural rewrite rather than an obvious security fix, but because it touches many parts of how the app decides where to send money, any bugs in the new resolver could lead to payments going to the wrong address.
AI review queuedfeat: add lightning preimage to transaction detailsby Konstantin Ullrich · 6cb31493 · Jul 6, 2026 · 3 filesMessage 62 · AdequateInformational 18Details
Commit message · Konstantin Ullrich
feat: add lightning preimage to transaction details
62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100
This commit adds a new piece of information—the Lightning Network payment preimage—to the transaction details screen. The preimage is a proof that a Lightning payment completed, and it is already stored in the wallet's existing payment data. The change simply displays it to the user, similar to showing a receipt number. There is no indication it introduces a security vulnerability.
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 21/100
This commit contains three small, unrelated fixes. One adds a safety catch around a Lightning wallet disconnect call so the app doesn't crash if disconnect fails. Another trims spaces and trailing currency text from amount inputs before converting them to numbers, which could prevent user input errors or unexpected parsing. The third is an Italian translation correction for the word 'change'. There is no clear security vulnerability being patched.