CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

768 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates335second-pass queue447AI analyses
65commits · 30 days
151commits · 60 days
423commits · 180 days
753commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
142Strong · 80–100
252Adequate · 60–79
236Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem55839165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]834075
Cindy635076
Analysis record

Published AI watches

Last scanned 1 hour ago

Informational 24 AI analysisMessage 79 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.5.0 rc (#3674)

This is a routine release-candidate commit for Cake Wallet/Monero.com version 6.5.0. It bumps the Monero core library version, adds a new Robinhood Chain wallet, enables price charts and Bitcoin accounts, reverts a database table that was …

Database schema reverts creation of DeprecatedWalletSeeds table, reducing persistent seed storage surfaceAlchemy API key fallback hardcoded to empty string, preventing unintended use of a bundled/secret key for Alchemy RPC endpointsmonero_c dependency updated to a newer commit, which may include upstream Monero fixes, but the specific changes are not shown in this diff
5f91c4d2by Omar Hatem+111−6222 files
No security note in commit
Low 26 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Don't force max brightness when showing seed QR (#3682)

This commit removes a feature that automatically cranked screen brightness to maximum when showing a wallet's seed/keys as a QR code. In some cases the brightness stayed stuck at max after closing the QR screen, which could let someone nea…

Removal of forced-max-brightness wrapper around sensitive QR displayPotential shoulder-surf / camera-surveillance risk from bright screen showing seed/keysState-cleanup bug in brightness restoration on non-normal route returns
c6f5865aby claude[bot]+5−81 file
No security note in commit
Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-priorityupdate discord link [skip ci]by Omar · 5cccde53 · May 31, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Omar

update discord link [skip ci]

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedfeat Add gradient-only card design and icon style picker (#3054)by David Adegoke · 0c3b06d3 · May 31, 2026 · 115 filesMessage 81 · StrongInformational 15Details
Commit message · David Adegoke

feat Add gradient-only card design and icon style picker (#3054)

* feat Add gradient-only card design and icon style picker

* refactor: Migrate card icon style to index-based storage

* feat: Add new card icons/styles for icon panel

* feat: add generic cake card icon

* Update coin icons and add opacity

* Remove vector icon files

* Remove vector icon files

* add xmr-og.webp

* feat: add animated switcher to icon style panel

* Enhance icson style preview
fix special gradient bug on plain style card

* Fix card styles ignoring special gradient text color combination

* Improve icon mgmt for card design handling, other fixes also based on review too

* fix: Add bounds check to icon style index

* fix: monero classic icon not displaying

---------

Co-authored-by: tuxsudo <tuxsudo@tux.pizza>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: broader security terminologysecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a user-facing feature update for the Cake Wallet app. It adds a new 'gradient-only' card background option and lets users pick different icon styles for their wallet balance cards. It also updates the local database to store these new preferences and refreshes many coin icon graphics. There is nothing in the changes that suggests a security vulnerability or malicious behavior.

AI review queuedCw 1438 v2 (#3252)by Omar Hatem · 997201e0 · May 28, 2026 · 4 filesMessage 59 · ThinLow 34Details
Commit message · Omar Hatem

Cw 1438 v2 (#3252)

* refactor address discovery and response handling

* refactor input tx fetching and mweb tagging

* add batch unspent fetching

* add batch balance fetching

* extend batch fetching to all Electrum wallets

* minor fixes

* [skip ci] Update cw_bitcoin/lib/electrum_wallet.dart

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* Revert "minor fixes"

This reverts commit 631e6258d25cc8717178bbc2b39407443f030677.

* used addresses anywhere in gap

* refresh receive and change addresses on set

* add isLegacyDerivation flag to address flows

---------

Co-authored-by: Serhii <17529954+serhii-bor@users.noreply.github.com>

59/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 34/100

This commit refactors how Cake Wallet's Bitcoin-family wallets (Bitcoin, Litecoin, Bitcoin Cash, Dogecoin) talk to Electrum servers. It adds batch RPC calls for balances, unspent outputs, and transaction history, and fixes some address-discovery edge cases. There is no direct evidence in the commit that this fixes an active security vulnerability; it appears to be a performance and reliability improvement. However, any bug in wallet balance or transaction discovery logic can affect whether users see correct funds, so it has indirect financial-relevance.

Security candidateMinor UI fixes (#3260)by tuxsudo · 4c95b85c · May 28, 2026 · 34 filesMessage 51 · ThinInformational 15Details
Commit message · tuxsudo

Minor UI fixes (#3260)

* Fix swap wallet icons not showing up

* Fix usdt icon

* Update QR code restoration string

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit is a routine user-interface polish. It swaps one image-loading widget for another so wallet icons appear correctly on the swap page, replaces the USDT icon SVG with a cleaned-up version, and updates a translated user-facing label from 'Add a read-only wallet from Cupcake or a cold wallet or recover a paper wallet' to 'Add an air-gapped cold wallet or recover a paper wallet' across all supported languages. There is no security-relevant code change.

AI review queuedlinux fixes (#3262)by cyan · 8979811d · May 28, 2026 · 5 filesMessage 71 · AdequateLow 27Details
Commit message · cyan

linux fixes (#3262)

* linux fixes

fix: use ints instead of bools in SQLite to prevent crashes on linux
fix: disable lightning if it's unsupported
ui: start linux app in portrait mode instead of landscape so it looks
nicer

* minor cleanup

---------

Co-authored-by: Omar <omarh.ismail1@gmail.com>

71/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 27/100

This commit fixes Linux-specific app crashes and UI glitches in Cake Wallet. The main functional change is making the wallet correctly store and read true/false settings as numbers (1 or 0) in its SQLite database on Linux, where storing raw booleans was causing crashes. It also disables Lightning payments on platforms that don't support them and forces the Linux app to start in a tall phone-like shape instead of a wide landscape shape. There is no clear security vulnerability being patched; it reads as a stability and UI polish fix.

Lower-priority26-05-05_Translation_de_DE (#3212)by BSN ∞/21M · 2f5757de · May 27, 2026 · 1 fileMessage 66 · AdequateTriage 0Details
Commit message · BSN ∞/21M

26-05-05_Translation_de_DE (#3212)

* 26-03-14_Update Translation_de_DE

* 26-03-31_Update Translation_de_DE

* 26-03-31_Update Fix

* 26-04-08_Update Translation_de_DE

* 26-05-05_TRanslation_de_DE

* 26-05-21_Update Translation_de_DE

66/100 · AdequateMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
AI review queuedfix id column nameby Robert Malikowski · ea0b6841 · May 26, 2026 · 1 fileMessage 28 · OpaqueLow 27Details
Commit message · Robert Malikowski

fix id column name

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 27/100

This commit fixes a small but potentially important bug in how the app looks up saved Monero node/server records by their ID. Previously, the code searched for a column literally named 'id', but the actual stored column name is held in a variable called selfIdColumn. If those names differ, lookups by ID would fail or behave unexpectedly. The change makes the lookup use the correct column name. There is no direct evidence this is a security vulnerability, but incorrect database lookups can sometimes cause app crashes, missing data, or in rare cases be chained into other issues.

AI review queuedfix buildby Omar Hatem · 1043c898 · May 26, 2026 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Omar Hatem

fix build

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This is a one-character Dart syntax fix that adds parentheses around a logical expression. It resolves a build/compilation error and does not change the intended behavior of the code. There is no security relevance.

AI review queuedfix settingsStore.reloadby Robert Malikowski · c6f68322 · May 26, 2026 · 3 filesMessage 28 · OpaqueLow 25Details
Commit message · Robert Malikowski

fix settingsStore.reload

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 25/100

This commit fixes how the wallet's settings store reloads its saved server/node list after a backup restore. Previously it relied on an in-memory box of Node objects passed as an argument; now it fetches each node directly from the local database by ID. The change also re-enables the reload call that had been commented out during backup restore. There is no direct evidence this is a security fix, but using stale or missing node records after a restore could in theory leave a wallet pointed at the wrong server.

Lower-priorityrevert exception handler wrong conflic resolve [skip ci]by Omar · a4ab691c · May 26, 2026 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · Omar

revert exception handler wrong conflic resolve [skip ci]

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedRebase node-sqlite-migration onto devby Omar · ac05166e · May 26, 2026 · 72 filesMessage 68 · AdequateLow 36Details
Commit message · Omar

Rebase node-sqlite-migration onto dev

Squashed migration of node Hive→SQLite, default-node handling,
isPow/proxy support, arbitrum node updates, and related fixes.
Replays node-sqlite-migration on top of current dev without the
amount-refactor merge that the original branch carried.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Low 36/100

This is a large code refactor that moves Cake Wallet's saved blockchain node list from the Hive key-value store to a SQLite database. It also updates the bundled default nodes for many cryptocurrencies, changes which node is the default for several coins, and adds labels/official flags. The change touches how the app picks which server it talks to when sending or receiving transaction data. There is no clear security bug in the diff, but any data migration this large carries some risk of losing or mis-mapping user node settings, which could cause wallets to connect to an unexpected server after update.

AI review queuedfix: monero address display in tx history (#3249)by David Adegoke · f3de4b25 · May 26, 2026 · 2 filesMessage 88 · StrongInformational 19Details
Commit message · David Adegoke

fix: monero address display in tx history (#3249)

* fix: monero address display in tx history

* chore: Add comment for regex function [skip ci]

* chore: Add doc comment

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit fixes how Monero recipient addresses are shown in transaction history. Previously, saved descriptions could contain extra text (such as account names or labels) alongside the actual address, causing the app to display or copy a malformed address. The patch extracts only the valid Monero address portion when displaying it, reducing the chance a user accidentally copies or shares the wrong thing. It is a UI/data-sanitization fix rather than a cryptographic or network vulnerability.

Lower-priorityfix:near intents fixed-rate underpayment (#3247)by Serhii · d38db977 · May 26, 2026 · 1 fileMessage 53 · ThinTriage 0Details
Commit message · Serhii

fix:near intents fixed-rate underpayment (#3247)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedminor fix [skip ci]by Omar · fe049577 · May 25, 2026 · 1 fileMessage 28 · OpaqueInformational 20Details
Commit message · Omar

minor fix [skip ci]

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 20/100

This commit makes a tiny defensive change in the wallet's balance display code. It swaps two uses of elementAt(0) for elementAtOrNull(0), which prevents the app from crashing if the balance list is unexpectedly empty. There is no indication this fixes an exploitable security vulnerability; it appears to be a routine robustness fix for a user-interface crash.

Security candidatefeat: add support for Zcash names resolution (#3237)by David Adegoke · baac6eea · May 24, 2026 · 10 filesMessage 100 · StrongInformational 20Details
Commit message · David Adegoke

feat: add support for Zcash names resolution (#3237)

* feat: Add memo support for swap

* fix: Error on swap page select receiver bottomsheet when picking receiveing currency that's not a wallet type

* feat: exclude providers that do not support memo when receive currency needs it, also show passed memo in confirmation and trade history sheets

* fix: overflow for destination tag on swap confirmation

* feat: add support for Zcash names resolution

* fix conflict because github is shit

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
memory safety
AI analysis · Informational 20/100

This commit adds a new feature that lets users type human-friendly Zcash names (like 'alice.zec' or 'bob.zcash') instead of long wallet addresses. The app looks up the real address from a remote service called zcashnames.com. The change also includes a few small swap-screen fixes and a safety catch around another name lookup. There is no clear security bug in the diff, but any name-to-address lookup adds a small risk that a malicious or compromised server could redirect payments.

AI review queued26-05-21_Update Translation_de_DEby BSN ∞/21M · 87ea0ced · May 21, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · BSN ∞/21M

26-05-21_Update Translation_de_DE

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a routine German translation update. It fixes typos, corrects misspelled string keys (for example 'durres_PIN' to 'duress_PIN' and 'ignor' to 'ignore'), translates a few remaining English phrases into German, and tidies whitespace. There is no security-relevant change.

Lower-priorityfix: Handle ethereum QR for pay anything (#3250)by David Adegoke · 087c2b94 · May 21, 2026 · 1 fileMessage 65 · AdequateTriage 0Details
Commit message · David Adegoke

fix: Handle ethereum QR for pay anything (#3250)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedbump breez_sdk_spark_flutter to v0.14.0 (#3245)by Omar Hatem · d40e4c69 · May 20, 2026 · 5 filesMessage 68 · AdequateInformational 23Details
Commit message · Omar Hatem

bump breez_sdk_spark_flutter to v0.14.0 (#3245)

* bump breez_sdk_spark_flutter to v0.14.0

* Fix accessing parsed address without checking if it's parsed

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 23/100

This commit updates a Lightning payment library (breez_sdk_spark_flutter) from version 0.11.0 to 0.14.0 and makes small matching code changes. It also fixes one app crash bug where the wallet tried to read a parsed address before checking whether an address had actually been parsed. The crash fix is a straightforward stability improvement; the library bump itself is a routine dependency update whose security implications are not described in the commit.

AI review queuedfix github stupid web editorby Omar · e4ef1a11 · May 20, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · Omar

fix github stupid web editor

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a trivial cleanup of a duplicate function signature that was accidentally introduced, likely by GitHub's web editor. It removes leftover duplicated lines and keeps the same retry logic. There is no security relevance.

Security candidatefeat: Add memo support for swap (#3229)by David Adegoke · 1d652c76 · May 20, 2026 · 56 filesMessage 93 · StrongLow 28Details
Commit message · David Adegoke

feat: Add memo support for swap (#3229)

* feat: Add memo support for swap

* fix: Error on swap page select receiver bottomsheet when picking receiveing currency that's not a wallet type

* feat: exclude providers that do not support memo when receive currency needs it, also show passed memo in confirmation and trade history sheets

* fix: overflow for destination tag on swap confirmation

* Update lib/view_model/exchange/exchange_view_model.dart [skip ci]

* Update lib/exchange/provider/trocador_exchange_provider.dart [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

93/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
memory safety
AI analysis · Low 28/100

This commit adds support for memos and destination tags when swapping to currencies that require them (like XRP, XLM, TON, EOS, HBAR). Previously, these currencies were excluded from swap receiving options. The change lets users enter a memo/destination tag, passes it to exchange providers that support it, filters out providers that don't support it, and stores it with the trade record. It also fixes a UI crash when selecting a receive currency that isn't a wallet type.

AI review queuedmigrate to svg icons for ios/macos (#3243)by malik1004x · d10f2f2a · May 20, 2026 · 109 filesMessage 76 · AdequateInformational 15Details
Commit message · malik1004x

migrate to svg icons for ios/macos (#3243)

* svg icons for apple

* update gitignore

* revert bundle id change

* rename svg

* Update ios/Runner.xcodeproj/project.pbxproj [skip ci]

* Update ios/Runner.xcodeproj/project.pbxproj [skip ci]

* Update ios/Runner.xcodeproj/project.pbxproj [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a routine visual update: it swaps the iOS and macOS app icons from many fixed-size PNG image files to a single scalable SVG icon format for each app variant. It also updates the build scripts and Xcode project files to use the new icon source. There is no change to wallet logic, security code, or user data handling.

AI review queuedfix: Better handle expired session and auth data for walletconnect (#3228)by David Adegoke · d325ece6 · May 20, 2026 · 1 fileMessage 98 · StrongLow 34Details
Commit message · David Adegoke

fix: Better handle expired session and auth data for walletconnect (#3228)

* fix: Better handle expired session and auth data for walletconnect

* fix: handle dApp disconnected sessions, reflecting the state locally

* Update lib/src/screens/wallet_connect/services/walletkit_service.dart [skip ci

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

98/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 34/100

This commit fixes how Cake Wallet's WalletConnect feature handles expired or disconnected sessions. Previously, the app's local list of sessions and authentication data could become out of sync with the actual WalletConnect state, potentially leaving stale connection data around or showing outdated session information. The patch clears and refreshes these lists more reliably when sessions end, expire, or pairings are deleted, and adds retry logic for network-related event emission.

Lower-priorityPay anything fixes (#3224)by David Adegoke · c6843183 · May 20, 2026 · 2 filesMessage 66 · AdequateTriage 0Details
Commit message · David Adegoke

Pay anything fixes (#3224)

* fix: Default to current chain for generic evm format addresses

* fix: Handle pay anything triggers in monero.com builds

66/100 · AdequateMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Security candidatesafeguards for monero subaddress list (#3242)by malik1004x · 0fadbac0 · May 18, 2026 · 3 filesMessage 53 · ThinLow 26Details
Commit message · malik1004x

safeguards for monero subaddress list (#3242)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
privacy or spend-authorization protocolsigning or wallet path
AI analysis · Low 26/100

This commit adds safety checks to prevent the Cake Wallet app from crashing when its Monero subaddress list is unexpectedly empty. It does not appear to fix a security vulnerability that an attacker could exploit; rather, it is a robustness improvement against a rare, observed production crash.

AI review queuedAllow Exporting transaction history to a CSV file (#3230)by Omar Hatem · 4125c5fe · May 18, 2026 · 38 filesMessage 73 · AdequateLow 28Details
Commit message · Omar Hatem

Allow Exporting transaction history to a CSV file (#3230)

* Allow Exporting transaction history to a CSV file

* fix: improve safety for share dialog bounds and navigation pop

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Low 28/100

This commit adds a feature that lets users export their transaction history to a CSV file. The export includes details such as dates, amounts, transaction IDs, addresses, and notes. It is a normal data-export feature, not a code vulnerability. However, because the exported file can contain sensitive financial information, users should be careful where they save or share it. The commit also includes two small safety fixes: it checks whether a screen can be closed before trying to close it, and it clips the share-dialog position on iOS so it does not go off-screen.