CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
421commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 41 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedupdate app versionby Omar · 6df6108d · Aug 29, 2026 · 2 filesMessage 28 · OpaqueInformational 15Details
Commit message · Omar

update app version

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply bumps the version and build numbers for the Cake Wallet and Monero.com apps in two shell scripts used for Android and iOS packaging. There are no code changes, no bug fixes, and no security-related modifications visible in the diff.

Security candidatefeat: redesign the pre-seed and seed verification screensby Blazebrain · 837c4d7d · Aug 28, 2026 · 26 filesMessage 72 · AdequateInformational 11Details
Commit message · Blazebrain

feat: redesign the pre-seed and seed verification screens

72/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
defensive validationseed or entropy pathsigning or wallet path
AI analysis · Informational 11/100

This commit is a user-interface redesign for the screens that introduce and verify the wallet's recovery seed phrase. It adds new pages, moves image assets, updates navigation, and changes some labels. There is no direct evidence in the diff of a security vulnerability; it appears to be a normal feature/refactoring change.

Security candidatefeat: persist whether a wallet still needs its recovery phrase backed upby Blazebrain · e95d9d14 · Aug 28, 2026 · 6 filesMessage 62 · AdequateInformational 19Details
Commit message · Blazebrain

feat: persist whether a wallet still needs its recovery phrase backed up

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet pathauthentication path
AI analysis · Informational 19/100

This commit adds a persistent reminder for users to back up their wallet recovery phrase. It stores a new flag in the app's database, shows a reminder on the dashboard when the wallet has funds, and clears the reminder once the user completes a seed verification flow. It also adds the seed page to the list of screens that always require authentication before opening. There is no direct security vulnerability in the change; it is a user-experience and safety improvement.

AI review queuedfeat: add recovery phrase wording for the redesigned seed flowby Blazebrain · 9a66b511 · Aug 28, 2026 · 31 filesMessage 62 · AdequateInformational 15Details
Commit message · Blazebrain

feat: add recovery phrase wording for the redesigned seed flow

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 15/100

This commit only changes translated text strings in the Cake Wallet app. It renames user-facing labels like 'seed' to 'Recovery Phrase' and adds new onboarding messages for the redesigned seed backup flow. There is no code that handles money, keys, network requests, or permissions, and no security bug is introduced or fixed.

Security candidatefeat: zano hf + bip39 (#3359)by cyan · 905db64f · Aug 28, 2026 · 27 filesMessage 88 · StrongLow 35Details
Commit message · cyan

feat: zano hf + bip39 (#3359)

* feat: bip39 zano hf

* fix: correct monero_c hash

* lockfile [skip ci]

* fix: zano: proper bip32
fix: zano respect 24 word setting
fix: rename / delete

* fix: nonBip39WalletTypes

* fix: zano wallet rename

* fix: passphrase store zano

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
secret or key materialaccess controlcryptography-sensitive pathseed or entropy pathsigning or wallet path
AI analysis · Low 35/100

This commit adds BIP39 seed phrase support for the Zano cryptocurrency in Cake Wallet, alongside a Zano hard-fork update. It changes how Zano wallets are created, restored, opened, renamed, and saved, and stores the seed/passphrase in encrypted sidecar files. The change also bumps the underlying monero_c library to a newer commit. There is no vendor statement that this fixes a security vulnerability; it reads as a feature/upgrade patch. Some implementation choices (custom key reduction, hard-coded derivation path, fallback to native seed, and sidecar key management) introduce areas where key-handling mistakes could occur, but the diff itself does not show an obvious exploitable bug.

AI review queuedv6.4.2 (#3566)by Omar Hatem · 14167a85 · Aug 28, 2026 · 39 filesMessage 61 · AdequateInformational 15Details
Commit message · Omar Hatem

v6.4.2 (#3566)

* Rush Release please test quickly

* Fix Zcash Lag

61/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 15/100

This commit is a routine version bump from 6.4.1 to 6.4.2 for the Cake Wallet/Monero.com apps. It updates translated changelog text, bumps build numbers, refreshes some third-party library references, and adjusts iOS project metadata. There is no code change visible in the diff that fixes or introduces a security vulnerability.

AI review queuedimportby Robert Malikowski · 7b5ffe88 · Aug 27, 2026 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Robert Malikowski

import

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit adds a single missing import statement to a Dart file. It does not change any logic, behavior, or security properties of the application. By itself, it is not a security fix or vulnerability.

AI review queuedaddress review commentsby Robert Malikowski · 09a34282 · Aug 27, 2026 · 12 filesMessage 28 · OpaqueInformational 23Details
Commit message · Robert Malikowski

address review comments

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 23/100

This commit is a routine code cleanup and bug-fix pass for the buy/sell feature in Cake Wallet. It removes an unused money-parsing helper, fixes memory leaks by disposing controllers and focus nodes, improves localization, and tweaks buy/sell amount calculations. There is no clear security vulnerability introduced or fixed in the diff itself.

AI review queuedCyjan zec mutex 2 (#3569)by cyan · 3ba43ede · Aug 27, 2026 · 4 filesMessage 68 · AdequateLow 26Details
Commit message · cyan

Cyjan zec mutex 2 (#3569)

* fix: mutex on zec

* refactor: simplify orchard migratable balance checks and update related methods

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 26/100

This commit changes how the Cake Wallet app tracks Zcash (ZEC) balance data and migration readiness. It adds a lock (mutex) around database access to prevent multiple operations from interfering with each other, and replaces a live balance-checking reaction with a simpler computed property. The changes appear aimed at fixing race-condition or consistency bugs rather than introducing a security vulnerability.

AI review queuedshowSymbol: false,by Robert Malikowski · c2441b16 · Aug 26, 2026 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · Robert Malikowski

showSymbol: false,

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit changes a single UI setting in the buy/sell screen so that the currency symbol is no longer shown next to a displayed money amount. It is a cosmetic/layout change with no apparent security relevance.

AI review queuedCW-1615: Harden walletconnect auth (#3547)by David Adegoke · 06e75551 · Aug 26, 2026 · 39 filesMessage 81 · StrongHigh 72Details
Commit message · David Adegoke

CW-1615: Harden walletconnect auth (#3547)

* fix android CI

* fix: harden walletconnect auth so a connected session won't transfer on dApp when wallet is switched within the app

* refactor: improve session mgmt and better error handling, also added a loader to the listing page

* feat: switch to newer id for solana dapps connections and fix requests not triggering

81/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · High 72/100

This update fixes a security weakness in Cake Wallet's WalletConnect feature. Previously, if a user switched to a different wallet inside the app while still connected to a decentralized app (dApp), the dApp could keep sending signing or transaction requests that might be handled by the wrong wallet. The patch now checks that each incoming request truly belongs to the currently active wallet, rejects mismatched requests with a clear message, and refreshes or clears WalletConnect sessions when wallets are switched. It also updates Solana connection identifiers and improves loading/error feedback.

AI review queuedUpdate `breez_sdk_spark_flutter` to v0.23.0 and adjust pubspec overrides (#3558)by Konstantin Ullrich · bd362279 · Aug 25, 2026 · 3 filesMessage 73 · AdequateLow 29Details
Commit message · Konstantin Ullrich

Update `breez_sdk_spark_flutter` to v0.23.0 and adjust pubspec overrides (#3558)

* chore: update `breez_sdk_spark_flutter` to v0.23.0 and update pubspec overrides

* feat: use latest breez sdk

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 29/100

This commit updates the Breez Lightning SDK used by Cake Wallet from version 0.14.0 to 0.23.0 and tweaks the wallet code to match the new SDK's API. It is a routine dependency upgrade, not a clearly labeled security fix. The update could include bug fixes or security improvements from the upstream SDK, but the commit itself does not describe any specific vulnerability or attack.

Security candidatefeat: bip39 decred (#3348)by cyan · 3d9b79f5 · Aug 25, 2026 · 20 filesMessage 55 · ThinLow 27Details
Commit message · cyan

feat: bip39 decred (#3348)

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
secret or key materialsigning or wallet path
AI analysis · Low 27/100

This commit adds BIP39 seed phrase support for Decred wallets in Cake Wallet. It changes how Decred wallets are created, restored, and saved, including storing an encrypted backup of the seed/passphrase and switching the underlying Decred library call used to build transactions. There is no explicit security bug in the diff, but the change touches sensitive wallet-key handling and transaction creation code, so it warrants careful review.

Lower-priorityfix icons in card customizer in light theme (#3552)by malik1004x · b72c5c32 · Aug 24, 2026 · 1 fileMessage 58 · ThinTriage 0Details
Commit message · malik1004x

fix icons in card customizer in light theme (#3552)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Security candidateHide broken options in Bitcoin wallets without a private key (#3532)by malik1004x · 9b50011e · Aug 24, 2026 · 9 filesMessage 96 · StrongLow 25Details
Commit message · malik1004x

Hide broken options in Bitcoin wallets without a private key (#3532)

* hide unavailable receive page options

* hide broken options in wallets without a private key

* hide exporting unavailable logs

* hide sign/verify on airgapped wallets

* hide mweb on hwws

* hide mweb ad for hww

96/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
secret or key materialsigning or wallet path
AI analysis · Low 25/100

This commit hides certain wallet features in the Cake Wallet app when they cannot actually work—specifically for hardware wallets, air-gapped wallets, and wallets that do not contain a private key. The changes prevent users from seeing or tapping options like Payjoin, Lightning, silent payments, message signing/verification, MWEB, and some log exports when those features are unsupported. It is a defensive UI fix rather than a patch for an active exploit.

Security candidatefix: solana wallet bugs and security issues (#3484)by David Adegoke · 703cc22b · Aug 24, 2026 · 52 filesMessage 100 · StrongModerate 59Details
Commit message · David Adegoke

fix: solana wallet bugs and security issues (#3484)

* fix android CI

* fix: duplicate outgoing tx for jup swaps and stuck pending state

* fix solana security risk by handling duplicate token symbols in wallet transactions

* feat: implement additional cost handling for pending transactions in Solana wallet.

* fix: Items on security audit list for solana wallet

* refactor: streamline fee payer index handling and improve error logging

* fix: verifySignature for solana and handle wrong mint on default token

* fix: token decimals defaulting to zero and breaking amount parsing in solana

* fix: use token mask in tx history

* refactor: apply lint to modified code

* fix: merge conflicts

* fix: use Money and mint decimals when parsing sol swaps

* test: add unit tests for SPL token amount handling and parsing

* test: add more tests

* fix: update decimal handling for fetched token and remove unused fields

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
signing boundarysigning or wallet path
AI analysis · Moderate 59/100

This commit fixes several Solana wallet bugs and security issues in Cake Wallet. The main security-relevant changes are: (1) preventing users from accidentally sending the wrong token when two tokens share the same symbol, by matching on the unique mint address instead of the symbol; (2) using the correct token decimals from the blockchain rather than defaulting to zero, so amounts are parsed and displayed accurately; (3) adding a warning and proper accounting for the extra SOL cost when a recipient's token account must be created; and (4) improving signature verification and transaction-history parsing. The commit title and message explicitly call these 'security issues' and mention an audit list.

Lower-priorityfix(ui): make unchecked NewSimpleCheckbox visible in light themesby Claude · a8ca70b4 · Aug 24, 2026 · 1 fileMessage 85 · StrongTriage 0Details
Commit message · Claude

fix(ui): make unchecked NewSimpleCheckbox visible in light themes

The unchecked background resolved to colorScheme.surfaceContainerHighest,
which is pure white in LightTheme, so the unselected checkbox was an
invisible white disc on near-white list rows. In light brightness use
onSurfaceVariant with alpha 80 instead; dark themes are unchanged.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Lower-priorityEnhance Money class with precision handling and zero trimming (#3548)by Konstantin Ullrich · c8380129 · Aug 24, 2026 · 8 filesMessage 73 · AdequateTriage 0Details
Commit message · Konstantin Ullrich

Enhance Money class with precision handling and zero trimming (#3548)

* feat: enhance Money class with precision handling, scale alignment, and trailing zero trimming

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
AI review queuedrevert unrelated changeby Robert Malikowski · cba928b1 · Aug 24, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Robert Malikowski

revert unrelated change

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a pure whitespace/indentation fix that reverts an unrelated formatting change. It moves one closing brace to the correct indentation level. There is no functional code change and no security relevance.

AI review queuedrevert unrelated changeby Robert Malikowski · 7eeb9c1b · Aug 24, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Robert Malikowski

revert unrelated change

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply undoes a prior formatting-only change in a single Dart file. It reverts a line break so that a fallback token definition appears on one line instead of two. There is no functional code change, no security fix, and no behavior alteration.

AI review queuedfixby Robert Malikowski · 91330b01 · Aug 24, 2026 · 4 filesMessage 0 · OpaqueInformational 18Details
Commit message · Robert Malikowski

fix

0/100 · OpaqueMessage clarity
! Generic or placeholder subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 18/100

This commit is a routine UI polish/fix. It swaps plain text widgets for specialized money/currency widgets in buy/sell screens and fixes indentation in a hardware-wallet connection callback. There is no clear security-relevant change.

Lower-priorityUpdate lib/entities/fiat_currency.dartby malik1004x · a8727d21 · Aug 24, 2026 · 1 fileMessage 60 · AdequateTriage 0Details
Commit message · malik1004x

Update lib/entities/fiat_currency.dart

Co-authored-by: Konstantin Ullrich <konstantin@cakewallet.com>

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Lower-priorityUpdate lib/entities/fiat_currency.dartby malik1004x · 58579c13 · Aug 24, 2026 · 1 fileMessage 60 · AdequateTriage 0Details
Commit message · malik1004x

Update lib/entities/fiat_currency.dart

Co-authored-by: Konstantin Ullrich <konstantin@cakewallet.com>

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI review queuedfix rive_common dependencyby Robert Malikowski · 9d302252 · Aug 23, 2026 · 1 fileMessage 35 · OpaqueLow 46Details
Commit message · Robert Malikowski

fix rive_common dependency

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: broader security terminologysecond-pass: opaque commit message
AI analysis · Low 46/100

This commit changes the source of a software dependency called rive_common from one GitHub account (MrCyjaneK) to another (malik1004x). Dependencies are external code packages the app relies on. Switching to a different, unverified source could introduce malicious or vulnerable code into the wallet app, but the commit itself does not show any harmful code—only the source change. There is no vendor explanation or security disclosure provided.

AI review queuedparse -> tryParse in fiatby Robert Malikowski · 185ee4be · Aug 23, 2026 · 1 fileMessage 35 · OpaqueLow 34Details
Commit message · Robert Malikowski

parse -> tryParse in fiat

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 34/100

This commit changes how the app converts a crypto amount into a fiat money value. It swaps strict number parsing for safer versions that fall back to zero when the input is invalid, instead of crashing. This is a defensive fix that prevents unhandled exceptions if a user's entered amount cannot be parsed as a number.