CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

768 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates335second-pass queue447AI analyses
65commits · 30 days
151commits · 60 days
423commits · 180 days
753commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
142Strong · 80–100
252Adequate · 60–79
236Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem55839165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]834075
Cindy635076
Analysis record

Published AI watches

Last scanned 15 minutes ago

Informational 24 AI analysisMessage 79 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.5.0 rc (#3674)

This is a routine release-candidate commit for Cake Wallet/Monero.com version 6.5.0. It bumps the Monero core library version, adds a new Robinhood Chain wallet, enables price charts and Bitcoin accounts, reverts a database table that was …

Database schema reverts creation of DeprecatedWalletSeeds table, reducing persistent seed storage surfaceAlchemy API key fallback hardcoded to empty string, preventing unintended use of a bundled/secret key for Alchemy RPC endpointsmonero_c dependency updated to a newer commit, which may include upstream Monero fixes, but the specific changes are not shown in this diff
5f91c4d2by Omar Hatem+111−6222 files
No security note in commit
Low 26 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Don't force max brightness when showing seed QR (#3682)

This commit removes a feature that automatically cranked screen brightness to maximum when showing a wallet's seed/keys as a QR code. In some cases the brightness stayed stuck at max after closing the QR screen, which could let someone nea…

Removal of forced-max-brightness wrapper around sensitive QR displayPotential shoulder-surf / camera-surveillance risk from bright screen showing seed/keysState-cleanup bug in brightness restoration on non-normal route returns
c6f5865aby claude[bot]+5−81 file
No security note in commit
Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateGeneric fixes (#3292)by David Adegoke · 74c7de1c · Jun 4, 2026 · 55 filesMessage 59 · ThinInformational 20Details
Commit message · David Adegoke

Generic fixes (#3292)

* Add masked token image to to currency picker items and adjust estacked badge icon for node share qr

* fix: Missing chain images in bridge flow

* chore: Update image paths

* fix: WC connection not triggering for Solana from scan qr

* fix: Wallet icon and eth currency icon displaying wrongly in various places for Base wallets

59/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 20/100

This commit is a routine UI/UX bug-fix patch titled 'Generic fixes'. It mainly swaps old cryptocurrency icon paths for new ones, fixes WalletConnect QR-code handling for Solana, corrects how wallet/currency icons are chosen (especially for Base wallets), and updates translated user messages. There is no direct evidence of a security vulnerability being fixed; the changes are cosmetic and workflow-correctness improvements.

Lower-priorityfix send external qr size (#3299)by malik1004x · ba80309f · Jun 4, 2026 · 1 fileMessage 53 · ThinTriage 0Details
Commit message · malik1004x

fix send external qr size (#3299)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedfix sizing (#3298)by malik1004x · 8c1c700b · Jun 4, 2026 · 4 filesMessage 36 · OpaqueInformational 15Details
Commit message · malik1004x

fix sizing (#3298)

36/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
parser or protocol pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a routine user-interface layout fix. It wraps a currency picker in a SafeArea so content isn't hidden by device notches or system bars, removes an extra 24-pixel gap below search boxes, and sets the QR code display to 70% of screen width instead of letting it size automatically. There is no security-relevant change.

Lower-prioritychange color for urqr indicator on scan page (#3294)by malik1004x · 73187e6d · Jun 4, 2026 · 1 fileMessage 58 · ThinTriage 0Details
Commit message · malik1004x

change color for urqr indicator on scan page (#3294)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityValidate swap amounts before creating trade (#3296)by Serhii · ea4bdc70 · Jun 4, 2026 · 1 fileMessage 58 · ThinTriage 8Details
Commit message · Serhii

Validate swap amounts before creating trade (#3296)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
defensive validation
AI review queuedtx-confirmation-options-on-dev [cw-1463] (#3289)by malik1004x · 5099fa3b · Jun 4, 2026 · 22 filesMessage 76 · AdequateInformational 23Details
Commit message · malik1004x

tx-confirmation-options-on-dev [cw-1463] (#3289)

* add note and contact options to tx confirmation screen

* fix closing animation for confirm sheet

* fix note button for lightning

* sizing fix

* add local tx info for evm/sol/trx

* fix for xmr/zec

* merge

* fixes

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 23/100

This commit adds new UI options to the transaction confirmation screen, letting users save a recipient as a contact or add a note right after sending. It also changes how pending transactions are tracked for EVM, Solana, and Tron so they appear immediately in history instead of waiting for the next sync. There is no clear security fix or vulnerability being patched; it reads as a feature/UI improvement. Some of the new code introduces minor quality concerns (e.g., a likely copy-paste bug in Tron fee handling, FIXME comments about decimal parsing, and a broad removal of analysis exclusions), but nothing in the diff itself demonstrates an exploitable security flaw.

Lower-priority6.2 home ui fixes (#3290)by malik1004x · 1704bc51 · Jun 4, 2026 · 5 filesMessage 53 · ThinTriage 0Details
Commit message · malik1004x

6.2 home ui fixes (#3290)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityFix and update monero_c hashby Omar · 281725fa · Jun 3, 2026 · 3 filesMessage 45 · ThinTriage 0Details
Commit message · Omar

Fix and update monero_c hash

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedimproved scan screen [cw-1507] (#3281)by malik1004x · 86ea17d5 · Jun 3, 2026 · 17 filesMessage 76 · AdequateInformational 20Details
Commit message · malik1004x

improved scan screen [cw-1507] (#3281)

* (wip) new scan screen

* improved scan screen

* fixes for ui

* switch to modal sheet

* add urqr (cupcake) progress indicator

* fixes

* Update lib/new-ui/pages/scan_page.dart

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
parser or protocol pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100

This commit is a user-interface redesign of the QR code scanner in Cake Wallet. It replaces a placeholder screen with a full camera scanning page, adds manual text entry, a help sheet, and progress indicators for animated UR QR codes. There is no clear security fix or vulnerability being patched; it is primarily a feature and UX improvement.

Lower-priorityUnify svg and png rendering (#3288)by David Adegoke · 52c380a4 · Jun 3, 2026 · 1 fileMessage 76 · AdequateTriage 0Details
Commit message · David Adegoke

Unify svg and png rendering (#3288)

* Improve token image display with mask and background

* Enhance token image bg and remove wierd halo effect that was showing, also add token bg to disclaimer and picker

* Add token bg to more locations and give another shot at halo

* fix: halo around token images

* add token background to non-transparent images only

* another shot at bg based on transparency

* refactor: enhance token image widget shape handling and add filter quality option to cake image widget

* fix: another shot

* refactor: update token image shape handling for svg, no need to clip

* fix: bnb wallet image not displaying on receive token display

* Remove svg path and render all through token image widget

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Lower-priorityrefactor: token image updates (#3287)by David Adegoke · 0b4e52c5 · Jun 3, 2026 · 2 filesMessage 88 · StrongTriage 0Details
Commit message · David Adegoke

refactor: token image updates (#3287)

* Improve token image display with mask and background

* Enhance token image bg and remove wierd halo effect that was showing, also add token bg to disclaimer and picker

* Add token bg to more locations and give another shot at halo

* fix: halo around token images

* add token background to non-transparent images only

* another shot at bg based on transparency

* refactor: enhance token image widget shape handling and add filter quality option to cake image widget

* fix: another shot

* refactor: update token image shape handling for svg, no need to clip

* fix: bnb wallet image not displaying on receive token display

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Security candidatefeat: redesign for CurrencyPicker and FiatPicker, introduce recents and currency groupings (#3248)by David Adegoke · 8af85351 · Jun 3, 2026 · 62 filesMessage 93 · StrongInformational 20Details
Commit message · David Adegoke

feat: redesign for CurrencyPicker and FiatPicker, introduce recents and currency groupings (#3248)

* Redesign for CurrencyPicker and FiatPicker, introduce recents and currency groupings

* chore: cleanup

* refactor: switch recents to previously completed trades, specify stables to be displayed, fix scrollable and adjust badge

* refactor: switch recents to previously completed trades, specify stables to be displayed, fix scrollable, adjust badge, add fiat and multinetwork currency pickers to buy and sell flows

* fresh set of changes and fixes for new currency picker flow

* add chain label to items on search and smooth pop

* add chain pill and label to xstocks

* properly filter search results

* shorten chain pill name for BSC tokens

* Review fixes

* cleanups

* safe pop

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 20/100

This commit is a user-interface redesign for the currency and fiat pickers in the Cake Wallet app. It adds grouping labels (like 'stablecoin' or 'tokenized stock'), a 'recently used' section, and network-selection helpers. There is no obvious malicious change, but a small change in how wallet types are resolved now silently catches errors and returns null, which could hide unexpected behavior. Overall this looks like a routine feature refactor, not a security fix or vulnerability.

AI review queuedImprove token image display with mask and background (#3231)by David Adegoke · 43654622 · Jun 3, 2026 · 14 filesMessage 81 · StrongInformational 15Details
Commit message · David Adegoke

Improve token image display with mask and background (#3231)

* Improve token image display with mask and background

* Enhance token image bg and remove wierd halo effect that was showing, also add token bg to disclaimer and picker

* Add token bg to more locations and give another shot at halo

* fix: halo around token images

* add token background to non-transparent images only

* another shot at bg based on transparency

* refactor: enhance token image widget shape handling and add filter quality option to cake image widget

* fix: another shot

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a user-interface polish change. It introduces a new reusable widget for displaying cryptocurrency token icons with circular clipping and automatic background detection, and replaces older image widgets across many screens. There is no security-relevant behavior change.

Lower-priority26-06-03_Update Translation_de_DE (#3285)by BSN ∞/21M · 5ab91696 · Jun 3, 2026 · 1 fileMessage 76 · AdequateTriage 0Details
Commit message · BSN ∞/21M

26-06-03_Update Translation_de_DE (#3285)

* 26-03-14_Update Translation_de_DE

* 26-03-31_Update Translation_de_DE

* 26-03-31_Update Fix

* 26-04-08_Update Translation_de_DE

* 26-05-05_TRanslation_de_DE

* 26-05-21_Update Translation_de_DE

* 26-06-03_Update Translation_de_DE

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
AI review queued26-06-03_Update Translation_de_DEby bsn21m · cc72819b · Jun 3, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · bsn21m

26-06-03_Update Translation_de_DE

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates German translations for a handful of WalletConnect-related user-interface labels. There are no code, logic, or security changes.

Lower-prioritychore: upgrade trezor_flutter (#3280)by Konstantin Ullrich · b8cb5dac · Jun 2, 2026 · 1 fileMessage 55 · ThinTriage 0Details
Commit message · Konstantin Ullrich

chore: upgrade trezor_flutter (#3280)

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedfix naming on wallet type page (#3279)by malik1004x · 371c063b · Jun 2, 2026 · 5 filesMessage 68 · AdequateInformational 15Details
Commit message · malik1004x

fix naming on wallet type page (#3279)

* fix naming on wallet type page

* add long press copy to tx history amount

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a routine user-interface polish change. It splits wallet names into separate 'name' and 'ticker' fields (e.g., 'Monero' and 'XMR' instead of 'Monero (XMR)'), adds a small layout padding tweak, and lets users long-press a transaction amount to copy it. There is nothing in the code that affects security, funds, cryptography, or private data.

AI review queuedfeat: add wallet illustration SVG to resources (#3278)by Konstantin Ullrich · 1000e9e4 · Jun 2, 2026 · 1 fileMessage 70 · AdequateInformational 15Details
Commit message · Konstantin Ullrich

feat: add wallet illustration SVG to resources (#3278)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit simply adds a new decorative wallet illustration as an SVG image file. It is a static picture used in the app's user interface and does not change any code, security logic, or data handling.

Lower-priorityNode UI Fixes (#3275)by tuxsudo · a8a70f5b · Jun 2, 2026 · 15 filesMessage 69 · AdequateTriage 0Details
Commit message · tuxsudo

Node UI Fixes (#3275)

* UI fixes, updated icons, and temporarily revert Rescan button

* readd ping test button to node list, readd rescan to connections, fixup ui

* increase gap for node edit button

* remove rescan from connections for sp

* remove rescan from connections for mweb

---------

Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com>

69/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
AI review queuedchore: update trezor-flutter dependency to latest commit (#3277)by Konstantin Ullrich · e6969d86 · Jun 2, 2026 · 1 fileMessage 70 · AdequateInformational 15Details
Commit message · Konstantin Ullrich

chore: update trezor-flutter dependency to latest commit (#3277)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
second-pass: broader security terminology
AI analysis · Informational 15/100

This commit only updates the pinned version (commit reference) of an internal dependency called trezor-flutter used by the Monero wallet package. There is no information in the commit or supplied references about what changed in that dependency, why it was updated, or whether it fixes any security issue. By itself, this diff is a routine dependency bump with no visible security relevance.

AI review queuedrefactor: replace deprecated SVG resource, adjust device tap behavior, and improve wallet selection image rendering (#3276)by Konstantin Ullrich · 45cba318 · Jun 2, 2026 · 4 filesMessage 93 · StrongInformational 15Details
Commit message · Konstantin Ullrich

refactor: replace deprecated SVG resource, adjust device tap behavior, and improve wallet selection image rendering (#3276)

* refactor: replace deprecated SVG resource, adjust device tap behavior, and improve wallet selection image rendering

* fix: render wallet image and update text style on NewWalletTypePage

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a routine user-interface cleanup. It swaps an old icon file for a newer one, changes how a couple of wallet-selection images are loaded, makes a device-tap area respond to taps more reliably, and tweaks text color. There is nothing in the changes that affects passwords, keys, funds, or network security.

Security candidateCw 1379 add monero support to trezor rebase dev (#3273)by Omar Hatem · 5b2a8f67 · Jun 2, 2026 · 73 filesMessage 81 · StrongLow 33Details
Commit message · Omar Hatem

Cw 1379 add monero support to trezor rebase dev (#3273)

* refactor: migrate hardware wallet resources to `new-ui`, add Trezor model support, and streamline hardware wallet handling across services

* refactor: migrate hardware wallet resources to `new-ui`, add Trezor model support, and streamline hardware wallet handling across services

* fix: correctly check for Ledger hardware wallet type in `isHardwareWallet` logic

* refactor: unify `isConnected` method for hardware wallets, add Trezor-specific support, and update Monero sync logic

* refactor: add Trezor transaction signing support, streamline hardware wallet handling, and update Monero dependency

* refactor: improve Trezor transaction handling, adjust hardware wallet state logic, and update Monero dependency references

* fix: non-hww tx commit() in xmr
fix: prod monero_c
fix: keyImage import workaround for Trezor/Cupcake
chore: add kotlin's .salive to .gitignore

* fix: universal_ble builds on iOS
chore: remove prints
fix: proper CI prebuilt for linux

* new trezor connection ui

* fix page title

* typo

* fix page title anim

* refactor: enhance Trezor pairing flow, update state management, and simplify UI logic in hardware wallet integration

* fix: correct widget indentation in Trezor pairing failure state UI

* fix: extract Trezor pairing failure state UI to `_errorBox` widget and update Trezor dependency reference

* refactor: simplify hardware wallet pairing error UI, optimize `_errorBox` layout, and streamline widget logic

* Update cw_monero/lib/pending_monero_transaction.dart

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* Update lib/buy/robinhood/robinhood_buy_provider.dart

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* feat: add USB intent filters, device filter for hardware wallets, and update Trezor dependency reference

* Update cw_monero/pubspec.yaml [skip ci]

* Update cw_wownero/pubspec.yaml [skip ci]

* Update cw_zano/pubspec.yaml [skip ci]

* fix: use CryptoCurrency.title instead of amount-refactor-only .symbol getter

new_wallet_type_page used curr.symbol, which only exists on the
amount-refactor branch (String get symbol => title). On dev the
equivalent is curr.title. Adapts the Trezor feature to dev's API
without pulling in amount-refactor.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Fix wallet list screen not scrollable
minor fixes

---------

Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>
Co-authored-by: Czarek Nakamoto <cyjan@mrcyjanek.net>
Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com>
Co-authored-by: Konstantin Ullrich <konstantin@cakewallet.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarycryptography-sensitive pathsigning or wallet path
AI analysis · Low 33/100

This is a large feature commit that adds Trezor hardware wallet support for Monero to the Cake Wallet app, alongside Ledger and BitBox. It also refreshes the hardware wallet connection UI, updates dependencies, and bumps the Android minimum SDK. The changes are mostly new feature code rather than a fix for a known security flaw. There are no explicit security claims in the commit message or diff, and no independent vulnerability disclosure is referenced.

AI review queuednew-node-list-ui-on-dev (#3259)by malik1004x · 6c1ee165 · Jun 1, 2026 · 20 filesMessage 86 · StrongLow 35Details
Commit message · malik1004x

new-node-list-ui-on-dev (#3259)

* node list new ui

# Conflicts:
# cw_core/lib/node_list.dart

* increase touch target sizes

* fix scroll behavior

* fix concurrent modification

* Update lib/src/screens/settings/manage_nodes_page.dart [skip ci]

* Update lib/src/screens/nodes/node_create_or_edit_page.dart [skip ci]

* run speed test in parallel not sequential

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

86/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
second-pass: unusually broad change
AI analysis · Low 35/100

This commit redesigns the node list user interface and adds a way to scan or share node connection details via QR code. The most notable security-relevant change is that node connectivity checks now route through a 'ProxyWrapper' helper with a flag that allows bypassing SSL certificate validation for Monero nodes. That bypass could make it easier for an attacker on the same network to impersonate a node and intercept traffic. The commit also introduces a new constructor that parses node URIs, including username and password, from scanned QR codes or links.

Lower-priorityfix for Mastadon lookup (#3272)by Serhii · cfe332a8 · Jun 1, 2026 · 1 fileMessage 53 · ThinTriage 0Details
Commit message · Serhii

fix for Mastadon lookup (#3272)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Security candidateRefactor WalletConnect UI components and enhance transaction approval and signing flow (#3233)by David Adegoke · e13d9976 · Jun 1, 2026 · 67 filesMessage 81 · StrongLow 35Details
Commit message · David Adegoke

Refactor WalletConnect UI components and enhance transaction approval and signing flow (#3233)

* Refactor WalletConnect UI components and enhance transaction approval and signing flow

* Refactor WalletConnect UI components and enhance transaction approval and signing flow

* Remove unused ui components

* Enhance pairing details page and remove unused ui components

* adjust buttons on details page

* Add warning banner for scam dApps on connection requests

* General cleanup

* Parse and display estimated network fee for WalletConnect approval requests

* Revamp WalletConnect pair listing view

* Remove unused action buttons and walletkit methods

* update svg and sync with dev

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarysigning or wallet pathauthentication path
AI analysis · Low 35/100

This commit is a large user-interface refactor of Cake Wallet's WalletConnect feature. It redesigns connection, signing, and approval screens, adds a scam-warning banner, shows estimated network fees, and removes some unused session-management buttons. There is no direct evidence in the diff of a new vulnerability being introduced or fixed; it reads as a UX hardening and cleanup change.