CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
421commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 14 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedparenthesesby Robert Malikowski · 08978a06 · Aug 23, 2026 · 1 fileMessage 0 · OpaqueLow 48Details
Commit message · Robert Malikowski

parentheses

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 48/100

This commit fixes a simple but meaningful math bug caused by missing parentheses. In the original code, the conversion from fiat to crypto amount was calculated incorrectly because division happened before the fallback to zero. Depending on the value of quote.rate, this could produce wrong crypto amounts when a user buys or sells cryptocurrency through the app. The fix makes sure the fiat amount is determined first, then divided by the exchange rate.

AI review queuedtryParseby Robert Malikowski · 0260f3dc · Aug 23, 2026 · 1 fileMessage 0 · OpaqueLow 35Details
Commit message · Robert Malikowski

tryParse

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 35/100

This commit changes how the app converts a user's entered fiat amount into a cryptocurrency amount when getting a price quote. Previously, if the user's input couldn't be parsed as a number, the app would crash. Now it treats invalid input as zero instead. This is a defensive fix that prevents a crash but may silently produce a zero quote for bad input, which could confuse users. It is not obviously a security vulnerability on its own.

AI review queuedreplace , with .by Robert Malikowski · e4b62b38 · Aug 22, 2026 · 1 fileMessage 18 · OpaqueInformational 21Details
Commit message · Robert Malikowski

replace , with .

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 21/100

This commit changes how the app handles fiat amounts typed by users. In some countries, people use a comma (,) as the decimal separator instead of a period (.). The app now converts any commas to periods before processing the amount. This is likely a bug-fix for incorrect amounts, payment failures, or wrong quotes when buying or selling cryptocurrency. It is not clearly a security fix, but bad number parsing in a buy/sell flow can cause real money errors.

AI review queuednullable amountForQuoteby Robert Malikowski · c1366a4c · Aug 22, 2026 · 5 filesMessage 18 · OpaqueInformational 24Details
Commit message · Robert Malikowski

nullable amountForQuote

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 24/100

This commit makes the displayed cryptocurrency amount for a buy/sell quote nullable and adds a safer parsing helper. Previously, if a quote's rate produced an unparsable amount, the app could crash when formatting the value on several buy/sell screens. The change lets the app show an empty string instead of crashing. It is a robustness fix for a UI/data-handling edge case, not an obvious security vulnerability.

Security candidatefix: generic fixes after anypay (#3543)by David Adegoke · 419d8cde · Aug 22, 2026 · 5 filesMessage 88 · StrongInformational 21Details
Commit message · David Adegoke

fix: generic fixes after anypay (#3543)

* fix android CI

* feat: add anypay core models, parser and routing engine

* feat: add anypay resolver, anypay service and wallet switch service

* refactor: route the send page payment flow through anypay service

* fix: show message when there's no swap providers for a pair and reset the trade guard on dismissal

* refactor: merge the swap from network and send to network decision pages together and clean up anypay widgets

* feat: reapply deep links to a currently open send flow and register the solana scheme

* feat: add support for zcash address detection to anypay and other minor fixes

* refactor: remove trailing icon

* feat: hide swap flow for sp and mweb addresses

* feat: enhance zcash address detection and deeplink handling

* fix: pin bitcoin_base

* refactor: Move the anypay decision navigation out of the send page and address minor review comments

* refactor: Move the anypay decision navigation out of the send page and address minor review comments

* feat: handle exception in switch service and mvoe balance compute to call site

* refactor: combine anypay entry points to one and extract selected mode widget

* fix: tx priority for doge

* chore: add dogecoin to isElectrumWallet util

* fix: annoying mobx error

---------

Co-authored-by: Czarek Nakamoto <cyjan@mrcyjanek.net>

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access controlsigning or wallet path
AI analysis · Informational 21/100

This commit is a follow-up bug-fix patch after a larger 'AnyPay' feature rollout. It corrects a copy-paste error where Zcash and Decred shared the same transaction-priority storage key, adds missing Dogecoin transaction-priority support, fixes a Flutter/MobX state-management warning, and moves an object initialization out of a field declaration into the widget's initState() method. None of these changes appear to be security fixes on their own; they are stability and correctness cleanups.

Lower-priorityfix fallback icon for payment methodsby Robert Malikowski · 20ac39ed · Aug 21, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Robert Malikowski

fix fallback icon for payment methods

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedfix empty payment methodsby Robert Malikowski · f45db86b · Aug 21, 2026 · 1 fileMessage 35 · OpaqueInformational 19Details
Commit message · Robert Malikowski

fix empty payment methods

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 19/100

This is a small UI fix in the buy/sell confirmation screen. It hides the 'payment method' row when a selected quote has no payment method title, preventing an empty or confusing label from appearing. There is no indication this is a security issue.

AI review queuedfix nano decimalsby Robert Malikowski · 7cd5881e · Aug 21, 2026 · 1 fileMessage 28 · OpaqueInformational 20Details
Commit message · Robert Malikowski

fix nano decimals

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 20/100

This commit fixes a display/calculation bug when buying or selling Nano cryptocurrency through Cake Wallet. Nano supports very small decimal amounts (up to 30 places). The app was trying to format the calculated crypto amount using all of those decimals, which caused an error because the formatting function only supports up to 20 decimal places. The fix caps the decimals at 20. This is primarily a reliability/usability bug, not a direct security vulnerability, though it could cause failed transactions or user confusion in the buy/sell flow.

Lower-priorityfix tx history scroll behavior (#3549)by malik1004x · 484f42aa · Aug 21, 2026 · 2 filesMessage 53 · ThinTriage 0Details
Commit message · malik1004x

fix tx history scroll behavior (#3549)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedremove computedby malik1004x · 2a1b7389 · Aug 21, 2026 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · malik1004x

remove computed

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit removes a single '@computed' annotation from a Dart method in a cryptocurrency wallet app. The change is a code-style or framework-migration edit. There is no indication it fixes or introduces a security issue.

AI review queuedlight mode fixesby Robert Malikowski · 6d288832 · Aug 21, 2026 · 4 filesMessage 28 · OpaqueInformational 15Details
Commit message · Robert Malikowski

light mode fixes

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a cosmetic fix for the app's light mode theme. It changes several buy/sell screens so they display light-colored icons when the device is in light mode, instead of always showing dark-colored icons. There is no security issue here.

Lower-priorityguard for fiat amount being nullby Robert Malikowski · bf3e2e15 · Aug 21, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Robert Malikowski

guard for fiat amount being null

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedswitch to safeParseby Robert Malikowski · d3a29667 · Aug 21, 2026 · 2 filesMessage 28 · OpaqueLow 33Details
Commit message · Robert Malikowski

switch to safeParse

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 33/100

This commit replaces the standard Money.parse() with a new Money.safeParse() when converting cryptocurrency buy/sell quote amounts. The change appears aimed at preventing parsing failures or incorrect handling of numeric strings that could arise from floating-point division results, which in a financial app could lead to wrong displayed prices or transaction amounts. There is no explicit security claim in the commit, and the patch is small and partial, so the security relevance is speculative.

Lower-priority26-08-19_Update Transöation_de_DE (#3537)by BSN ∞/21M · 8eddd4d4 · Aug 21, 2026 · 1 fileMessage 53 · ThinTriage 0Details
Commit message · BSN ∞/21M

26-08-19_Update Transöation_de_DE (#3537)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityhide keyboard after restoring backup on ios (#3533)by malik1004x · c248a53a · Aug 20, 2026 · 1 fileMessage 58 · ThinTriage 0Details
Commit message · malik1004x

hide keyboard after restoring backup on ios (#3533)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-prioritysafeguard calls to coin integration classes (#3534)by malik1004x · 51761209 · Aug 20, 2026 · 2 filesMessage 58 · ThinTriage 0Details
Commit message · malik1004x

safeguard calls to coin integration classes (#3534)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityError: Not a constant expression.by Robert Malikowski · 5a15d564 · Aug 20, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Robert Malikowski

Error: Not a constant expression.

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedbump: torch_dart (#3542)by cyan · e9dec675 · Aug 20, 2026 · 1 fileMessage 36 · OpaqueLow 25Details
Commit message · cyan

bump: torch_dart (#3542)

36/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 25/100

This commit updates a script that downloads a third-party software package called torch_dart used by the Cake Wallet app. It changes the expected fingerprint (a Git commit hash) of the package from one value to another. On its own, this is a routine dependency bump, but because the commit message only says 'bump' and gives no details about what changed in torch_dart, we cannot tell from this diff alone whether the new version fixes a security issue, introduces one, or is benign. The change is not suspicious by itself, but it is also not verifiable as safe without inspecting the upstream torch_dart repository.

Lower-prioritya11y: decorative/meaningful image semantics, labeled icon buttons, audible addresses (#3465)by Seth For Privacy · c9974673 · Aug 20, 2026 · 12 filesMessage 58 · ThinTriage 0Details
Commit message · Seth For Privacy

a11y: decorative/meaningful image semantics, labeled icon buttons, audible addresses (#3465)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityfix text on fiat selectorby Robert Malikowski · 78c1e77a · Aug 20, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Robert Malikowski

fix text on fiat selector

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Security candidateCW1612: AnyPay Service Layer (#3516)by David Adegoke · 3b100eae · Aug 20, 2026 · 67 filesMessage 76 · AdequateLow 38Details
Commit message · David Adegoke

CW1612: AnyPay Service Layer (#3516)

* fix android CI

* feat: add anypay core models, parser and routing engine

* feat: add anypay resolver, anypay service and wallet switch service

* refactor: route the send page payment flow through anypay service

* fix: show message when there's no swap providers for a pair and reset the trade guard on dismissal

* refactor: merge the swap from network and send to network decision pages together and clean up anypay widgets

* feat: reapply deep links to a currently open send flow and register the solana scheme

* feat: add support for zcash address detection to anypay and other minor fixes

* refactor: remove trailing icon

* feat: hide swap flow for sp and mweb addresses

* feat: enhance zcash address detection and deeplink handling

* fix: pin bitcoin_base

* refactor: Move the anypay decision navigation out of the send page and address minor review comments

* refactor: Move the anypay decision navigation out of the send page and address minor review comments

* feat: handle exception in switch service and mvoe balance compute to call site

* refactor: combine anypay entry points to one and extract selected mode widget

---------

Co-authored-by: Czarek Nakamoto <cyjan@mrcyjanek.net>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access controlcryptography-sensitive pathsigning or wallet pathparser or protocol path
AI analysis · Low 38/100

This is a large feature commit that introduces a new 'AnyPay' service layer for routing cryptocurrency payments and swaps inside Cake Wallet. It refactors how the app parses payment requests, detects recipient networks, switches wallets, and handles deep links. The changes are mostly architectural and user-facing, but because they touch sensitive flows such as wallet switching, address parsing, and cross-chain swaps, they could introduce security bugs if the new routing logic makes incorrect decisions. The commit does not appear to be a disclosed security fix, and no CVE or vendor security statement is present.

AI review queuedMigrate EVM/Sol/TRX tokens to SQL (#3450)by David Adegoke · 4cc14956 · Aug 20, 2026 · 23 filesMessage 76 · AdequateLow 27Details
Commit message · David Adegoke

Migrate EVM/Sol/TRX tokens to SQL (#3450)

* fix android CI

* feat: Migrate EVM, Sol and Tron tokens to SQL

* handle rename edgecase

* refactor: enhance token migration logic and improve database handling

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Low 27/100

This commit replaces the way Cake Wallet stores EVM, Solana, and Tron token lists: it moves them from Hive (a local key-value store) into SQLite (a local SQL database). It also adds migration code that copies existing token data from the old Hive boxes into the new SQLite tables when the app starts or restores a backup. The change is a large data-layer refactor, not a clear security fix or vulnerability. There are some migration edge cases (duplicate wallet names, interrupted migrations, case-insensitive EVM contract addresses) that are explicitly handled and tested.

Lower-prioritynear intents btc asset id migration (#3536)by Serhii · 887e01a7 · Aug 19, 2026 · 1 fileMessage 53 · ThinTriage 0Details
Commit message · Serhii

near intents btc asset id migration (#3536)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedfix: move `updateBleState` to connection page initialization (#3539)by Konstantin Ullrich · 86906a7f · Aug 19, 2026 · 3 filesMessage 70 · AdequateInformational 16Details
Commit message · Konstantin Ullrich

fix: move `updateBleState` to connection page initialization (#3539)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 16/100

This commit moves a Bluetooth status check so it runs when the device-connection screen first appears, rather than when the wallet view model is first created. It appears to be a timing or state-refresh bug fix for hardware wallet pairing, not a security vulnerability. There is no evidence in the commit of malicious behavior, exploitation, or a disclosed security issue.

Lower-priorityfix: bitcoin_base (#3541)by cyan · adef1006 · Aug 19, 2026 · 1 fileMessage 55 · ThinTriage 0Details
Commit message · cyan

fix: bitcoin_base (#3541)

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body