CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
421commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 47 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-priorityupdate bitcoin base commit hashby Omar · 9b2aec6e · Aug 19, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Omar

update bitcoin base commit hash

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Security candidatePrivacy: randomized coin selection (BnB changeless + single random draw) (#3408)by Cindy · 3b098e35 · Aug 19, 2026 · 5 filesMessage 100 · StrongLow 38Details
Commit message · Cindy

Privacy: randomized coin selection (BnB changeless + single random draw) (#3408)

* Randomize coin selection with single random draw

The greedy selection walked the unspent pool in a predictable order (address generation order, then per-address server order), a fingerprint an analyst can exploit. Shuffle the pool before the accumulate-until-covered loop so the input set is chosen non-deterministically (single random draw). MWEB coins are still kept last.

Branch-and-bound (changeless exact match) is a larger follow-up.

* Add BnB + SRD coin selection primitives

Pure, wallet-independent coin selector: branch-and-bound for an exact
changeless match within the cost-of-change window, single-random-draw
fallback (shuffled, injectable RNG) when no exact match exists, and
selectCoins tying them together over effective values.

This is the basis for replacing the greedy accumulation in _createUTXOS
so sends produce no change when possible and a non-deterministic
selection otherwise. Validated with dart test (9 cases); wiring into
_createUTXOS is a separate step.

* Use BnB changeless matching in coin selection

Before the shuffled greedy walk, run branch-and-bound over effective
values (value minus per-input fee cost) looking for an input set whose
excess over amount plus fee stays below dust. When found, order those
inputs first and cap the walk at their count: the caller then computes
a change below dust, drops the change output, and absorbs the residue
into the fee, producing a changeless transaction with no residual
change fingerprint.

When no match exists, selection falls back to the shuffled pool, which
the greedy walk turns into a single random draw. BnB is skipped for
sendAll, forced input counts and pools holding MWEB coins.

changelessMatch filters non-positive effective values and maps indices
back to the original pool.

* Cover changeless fee bounds and BnB termination

Assert the end-to-end arithmetic the wallet performs around a
branch-and-bound match: with the 68/34/10 vBytes model, the leftover
the caller absorbs into the fee is never negative (no re-selection
loop) and never exceeds the dust limit (bounded fee overpay).

Also pin termination: a large pool with no possible match returns null
through the maxTries cap instead of exploring the full search tree.

* Use a secure RNG for coin selection randomness

The selection shuffle and the single-random-draw fallback exist to be
unpredictable, so seed them from Random.secure() instead of the default
PRNG, matching what Core and bdk use for coin selection. Pool sizes are
small, so the cost is negligible. Tests keep injecting a seeded Random
for determinism.

* Randomize RBF and payjoin input candidate order

Two secondary paths still consumed unspentCoins in wallet scan order
(address generation order, then per-address age), the same predictable
order removed from the main selection path:

- replaceByFee walked the unused-UTXO list in scan order when the fee
bump needed extra inputs
- the payjoin receiver handed input candidates to the payjoin library
in scan order, letting ties inside its selection mirror that order

Shuffle both with a secure RNG so no input-selection path exposes the
wallet's address or coin age ordering.

* ci: skip Linux PR build on forks (no secrets access)

* Account for script-type sizes in changeless matching

* Keep coin selection order stable within a transaction build

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
explicit security languageentropy or randomnesssigning boundaryaccess controldefensive validationsigning or wallet path
AI analysis · Low 38/100

This commit improves Bitcoin/Litecoin privacy in Cake Wallet by making coin selection less predictable. Previously, the wallet chose coins in a fixed order (based on address creation and age), which outside observers could use to fingerprint the wallet or trace its funds. The patch shuffles candidate coins using a secure random source, tries to build changeless transactions when possible, and also randomizes coin order in RBF fee-bump and PayJoin flows. It also adds a CI guard to skip Linux builds on fork pull requests because secrets are unavailable there.

Security candidateSet anti-fee-sniping locktime (exact-tip) on bitcoin sends (#3385)by Cindy · ca00370c · Aug 19, 2026 · 5 filesMessage 81 · StrongLow 30Details
Commit message · Cindy

Set anti-fee-sniping locktime (exact-tip) on bitcoin sends (#3385)

* Set anti-fee-sniping locktime on bitcoin sends

Current tip (exact-tip) via shared helper, wired into normal sends (path A) and payjoin/PSBT (path B). 0 when unsynced. Converges with the exact-tip cluster (payjoin-cli, ldk-node, Bull Bitcoin) and skips the ~10% backdate.

* Update cw_bitcoin/lib/locktime.dart

Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>

* Update cw_bitcoin/lib/locktime.dart

Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>

* Update cw_bitcoin/lib/locktime.dart [skip ci]

---------

Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 30/100

This commit changes how Cake Wallet sets the 'locktime' field on outgoing Bitcoin transactions. Previously, Cake Wallet apparently left this value at zero, which made its transactions stand out and easier to track. Now it sets the locktime to the current blockchain height when the wallet is synced, matching common behavior used by other Bitcoin wallets. This is a privacy improvement, not a fix for a vulnerability that lets someone steal funds directly.

Lower-priorityfix: linux sqlite issue (#3519)by cyan · 2ed93f40 · Aug 19, 2026 · 1 fileMessage 65 · AdequateTriage 0Details
Commit message · cyan

fix: linux sqlite issue (#3519)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
documentation-only discount
Security candidatefeat: pin all dependencies to git sources (#3381)by cyan · be694edc · Aug 18, 2026 · 64 filesMessage 65 · AdequateLow 27Details
Commit message · cyan

feat: pin all dependencies to git sources (#3381)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
access controlsigning or wallet path
AI analysis · Low 27/100

This commit changes how the Cake Wallet app manages its software building blocks (Dart/Flutter dependencies). It removes many per-package lock files, pins more dependencies to specific Git commit hashes instead of branch names, adds shared override files, and updates CI build scripts. The main security angle is supply-chain hardening: pinning to exact Git commits makes it harder for an attacker to silently swap in a malicious version of a library. However, the commit is a broad refactor, and the diff does not show a specific vulnerability being fixed or any malicious code being introduced. It is best treated as a defensive hygiene improvement.

AI review queuedrefactor: remove `toDouble` method and reverted other changes (#3531)by Konstantin Ullrich · 1f0f51fe · Aug 18, 2026 · 4 filesMessage 70 · AdequateLow 34Details
Commit message · Konstantin Ullrich

refactor: remove `toDouble` method and reverted other changes (#3531)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 34/100

This commit removes a shortcut method that converted cryptocurrency amounts directly into regular 'double' numbers and reverts some earlier helper-function changes. It also fixes one spot where Solana transactions were looking up the wrong asset type. The overall effect is to make amount formatting and parsing go through string-based conversions again, which reduces the risk of tiny rounding errors or precision loss when handling very small crypto balances.

Lower-priorityfix: allow spending with LAN-only node (#3529)by cyan · 026a171c · Aug 17, 2026 · 1 fileMessage 65 · AdequateTriage 0Details
Commit message · cyan

fix: allow spending with LAN-only node (#3529)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedfix: sanitize Electrum fee estimates (#3499)by Seth For Privacy · 86db8991 · Aug 16, 2026 · 2 filesMessage 98 · StrongModerate 59Details
Commit message · Seth For Privacy

fix: sanitize Electrum fee estimates (#3499)

* fix: sanitize Electrum fee estimates

* chore: drop test changes from this PR

Removes the test additions/modifications introduced by this branch so the
test design is left to the maintainers. Production code is unchanged.

98/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Moderate 59/100

This commit hardens how Cake Wallet handles Bitcoin fee estimates from Electrum servers. Previously, a malicious or misbehaving Electrum server could return extreme or negative fee numbers, which could lead to users paying far too much, far too little, or creating invalid transactions. The patch now clamps fee rates between 0 and 2000 sat/vB, rejects all-zero fee lists, and refuses to build transactions when the computed fee is zero or negative. Most of the rest of the diff is just code formatting cleanup.

AI review queuedfix: validate EVM restore mnemonic checksum (#3498)by Seth For Privacy · 8a366129 · Aug 16, 2026 · 3 filesMessage 100 · StrongModerate 62Details
Commit message · Seth For Privacy

fix: validate EVM restore mnemonic checksum (#3498)

* fix: validate EVM restore mnemonics

* chore: drop test changes from this PR

Removes the test additions/modifications introduced by this branch so the
test design is left to the maintainers. Production code is unchanged.

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Moderate 62/100

This commit adds a missing safety check when users restore an Ethereum-compatible (EVM) wallet from a seed phrase. Before the fix, the app accepted any 12 or 24 words that looked like a mnemonic, even if the words were wrong or the checksum was invalid. That could let a user create a wallet from a typo-ridden seed and later be unable to access their funds. The fix validates the seed phrase's checksum before restoring, and shows a clear error if it is invalid.

Lower-priorityadd lint and quick-fixes for Money.amount.toString()by Robert Malikowski · 8d6b3cd8 · Aug 15, 2026 · 3 filesMessage 50 · ThinTriage 0Details
Commit message · Robert Malikowski

add lint and quick-fixes for Money.amount.toString()

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedmove chain iconby Robert Malikowski · 694b8eaf · Aug 12, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Robert Malikowski

move chain icon

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit slightly increases the size of a small UI box that displays a token icon together with a tiny chain/network badge. It is a visual layout tweak with no security relevance.

Security candidatev6.4.1 Release Candidate (#3506)by Omar Hatem · 8f38ba6b · Aug 12, 2026 · 39 filesMessage 81 · StrongInformational 15Details
Commit message · Omar Hatem

v6.4.1 Release Candidate (#3506)

* v6.4.1 Release Candidate

* fix changelog overflow (#3510)

* update ios min version

---------

Co-authored-by: malik1004x <malikowskirobert@gmail.com>

81/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
memory safety
AI analysis · Informational 15/100

This commit is a routine version bump to 6.4.1 plus a small user-interface fix for a changelog text overflow and an iOS minimum version update. It also refreshes translated release notes and updates a dependency reference for the Trezor hardware wallet integration. There is no indication of a security fix or vulnerability being addressed.

Lower-priorityfix: anypay (#3507)by David Adegoke · 414b2ead · Aug 11, 2026 · 7 filesMessage 71 · AdequateTriage 0Details
Commit message · David Adegoke

fix: anypay (#3507)

* fix android CI

* fix: handle the parser seeing chainless QRs in the old flow as belonging to the current wallet, causing the error jack reported

* fix: handle network switch when anypay is interrupted mid flow and currency is changed

71/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
AI review queued"synced" indicator (#3512)by malik1004x · 3a71f6ad · Aug 11, 2026 · 34 filesMessage 43 · ThinInformational 18Details
Commit message · malik1004x

"synced" indicator (#3512)

* "synced" indicator

* safeguards

43/100 · ThinMessage clarity
✓ Descriptive subject✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 18/100

This commit is a user-interface change that adds a brief 'Synced' indicator when a wallet finishes synchronizing. It does not change how funds, keys, or network connections are handled, and it does not fix or introduce any security issue visible in the diff.

Lower-priorityadd compile graphics to linux ci (#3509)by malik1004x · 26bc7bda · Aug 11, 2026 · 1 fileMessage 53 · ThinTriage 0Details
Commit message · malik1004x

add compile graphics to linux ci (#3509)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
documentation-only discount
AI review queuedadd new currency selectionby Robert Malikowski · a6abf1bf · Aug 11, 2026 · 2 filesMessage 35 · OpaqueInformational 15Details
Commit message · Robert Malikowski

add new currency selection

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a routine user-interface update for Cake Wallet's buy/sell flow. It adds a new fiat-currency picker and a small widget that shows a token icon with its chain/network badge. There is nothing in the changes that suggests a security vulnerability or fix.

AI review queuedadd emojis to FiatCurrencyby Robert Malikowski · 1cf97874 · Aug 11, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · Robert Malikowski

add emojis to FiatCurrency

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a straightforward user-interface enhancement: it adds country-flag emoji icons next to fiat currency entries in the Cake Wallet app. There is no security-relevant change—no new network calls, no altered permissions, no cryptographic changes, and no data handling modifications.

AI review queuedadd if(mounted) guardsby Robert Malikowski · 399dabe1 · Aug 11, 2026 · 1 fileMessage 28 · OpaqueInformational 18Details
Commit message · Robert Malikowski

add if(mounted) guards

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 18/100

This commit adds safety checks in a buy/sell screen so the app doesn't try to show pop-ups or navigate after the user has already left the page. It also adds a screen-reader label to the close button and reformats some code. There is no clear security vulnerability being fixed.

AI review queuedfix: sorting of transactions (#3494)by cyan · 19653afe · Aug 11, 2026 · 3 filesMessage 88 · StrongInformational 23Details
Commit message · cyan

fix: sorting of transactions (#3494)

* fix: zcash address for exchange

* fix: honour the restore height the user entered

- Make Zcash rescan work in both directions by resetting sync from the new birth height
- Keep the entered height when restoring a wallet from keys
- Tolerate grouping separators in typed restore heights

* fix: sorting of transactions
fix: tx fee for outgoing transactions

---------

Co-authored-by: Vik Sharma <vik@cakewallet.com>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 23/100

This update fixes how Cake Wallet displays Zcash transactions. Previously, outgoing transaction fees were shown as zero and transaction timestamps could be wrong or missing. The patch makes fees show the real network fee and improves date/time handling for transactions. There is no direct evidence in the commit of a security vulnerability being exploited, but incorrect fee and time data could mislead users or cause accounting problems.

AI review queuedfix: zcash address for exchange (#3491)by cyan · 3b16f2fb · Aug 11, 2026 · 5 filesMessage 88 · StrongLow 42Details
Commit message · cyan

fix: zcash address for exchange (#3491)

* fix: zcash address for exchange

* fix: honour the restore height the user entered

- Make Zcash rescan work in both directions by resetting sync from the new birth height
- Keep the entered height when restoring a wallet from keys
- Tolerate grouping separators in typed restore heights

---------

Co-authored-by: Vik Sharma <vik@cakewallet.com>

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 42/100

This commit fixes two user-facing bugs in Cake Wallet's Zcash handling. First, it ensures the correct transparent Zcash address is used when sending funds to an exchange, which could previously lead to deposits going to the wrong address type. Second, it makes wallet restore respect the block height the user typed in, and allows that height to contain grouping separators like commas. The changes are bug fixes rather than a disclosed security vulnerability, but the wrong-address issue has clear financial-impact potential.

AI review queuedGive ConfirmSwiper an accessible-navigation button fallback (#3464)by Seth For Privacy · 8ed08fb1 · Aug 11, 2026 · 5 filesMessage 58 · ThinInformational 21Details
Commit message · Seth For Privacy

Give ConfirmSwiper an accessible-navigation button fallback (#3464)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 21/100

This commit improves accessibility for users who rely on screen readers (VoiceOver on iOS, TalkBack on Android). The app's 'swipe to confirm' control did not work well with screen readers because they intercept swipe gestures. The change adds a plain button fallback when a screen reader is active, so blind or low-vision users can still confirm transactions and approvals. It is an accessibility/usability fix, not a security vulnerability fix.

AI review queuedCW-1523-AnyPay Redesign (#3383)by David Adegoke · 90194f71 · Aug 11, 2026 · 69 filesMessage 98 · StrongLow 34Details
Commit message · David Adegoke

CW-1523-AnyPay Redesign (#3383)

* feat: Add network selector and compatible networks screen to send page for EVMs

* feat: add redesigned payanything flow and handle cases for evms, solana and tron

* feat: adding the swap part to the entire flow

* refactor: update navigation and error handling in send and swap flows

* adjust structuring and use the chain badge icons, also fix crypto and currency values not consistent on single network picker

* fix: modify guard for non-evm chains and minor cleanup

* use multipicker layout for receive section, streamline send to available balances and adjust colors as needed

* handle btc case for picker, update style and images across

* fix all pending issues with scanning qr and network handling for both evm and non evm, plus token and amount resolving

* fix all pending issues with scanning qr and network handling for both evm and non evm, plus token and amount resolving

* fix: expand fetch for tokens across networks and fix other issues regarding scanning from homepage

* auto-reformat

* fix conflict

* handle evm qr scan from homepage and add guards for swap and switch flows

* chore: Cleanup

* chore: set estimated fee to 0 when switching wallet

* fix merge conflicts

* fix to review comments and reformatting for lints

* fix: root cause for token bug reported

* chore: cleanup

* feat: add improved anypay swap screen which focuses on the receive amount
fix: fiat input toggle erro (also present on prod)
reformat: anypay related widgets

* feat: add alert for unsupported networks in payment requests

* fix: prevent rate and provider from showing until amount is calculated and loaded
fix: remove send icon in rate widget and align to center
fix: adjust network badge in swap confirm widget

* feat: embed tokens for solana and tron in QR generated for swap from external

* test: add unit tests for Tron, Solana, and ERC681 URI handling and detection

* fix: review comments

* fix: handle more edgecases

* feat: enhance ERC681URI to support raw token amounts and decimals

* refactor: streamline EVM chain ID retrieval in send page and recipient network row

* fix: minor review comments

---------

Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com>

98/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Low 34/100

This is a large user-interface redesign for Cake Wallet's 'AnyPay' payment flow. It changes how the app parses payment QR codes and links for Ethereum, Solana, and Tron, adds network selection, and integrates swaps when the scanned payment is on a different network than the current wallet. The commit also fixes several amount-formatting bugs for tokens that do not use 18 decimal places, which could previously cause wrong payment amounts to be sent.

AI review queuedguard regeneration of lightning addressby Omar · 931b6fb9 · Aug 9, 2026 · 4 filesMessage 45 · ThinLow 37Details
Commit message · Omar

guard regeneration of lightning address

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 37/100

This commit prevents users from rotating (regenerating) a Bitcoin Lightning address in the Cake Wallet app. Previously, the app may have allowed address regeneration for Lightning addresses, which could cause confusion, lost incoming payments, or funds sent to an old/unexpected address. The fix adds a guard that throws an error if code tries to rotate a Lightning address, and updates the UI logic to recognize when a Lightning address type is selected.

Lower-priorityfix ens resolution to use resolver from registry (#3453)by Serhii · 43ae37df · Aug 7, 2026 · 2 filesMessage 73 · AdequateTriage 0Details
Commit message · Serhii

fix ens resolution to use resolver from registry (#3453)

* fix ens resolution to use resolver from registry

* minor fix

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Lower-priorityfix: linux builds (#3485)by cyan · 43cd1259 · Aug 7, 2026 · 15 filesMessage 55 · ThinTriage 0Details
Commit message · cyan

fix: linux builds (#3485)

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body