CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
421commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 22 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidatefeat: show Bitcoin master fingerprint in wallet keys (#3489)by Seth For Privacy · b60b5a59 · Aug 7, 2026 · 4 filesMessage 98 · StrongInformational 15Details
Commit message · Seth For Privacy

feat: show Bitcoin master fingerprint in wallet keys (#3489)

* feat: show Bitcoin master fingerprint in wallet keys

Add the BIP-32 master fingerprint (XFP) to the Bitcoin wallet keys shown
under Settings > Seed & Keys > Keys, labeled "Master fingerprint".

* fix: keep xPub in Keys tab by splitting silent payment keys into a dedicated list

The Keys tab / Silent Payments tab split relied on a hardcoded item index
(`items.sublist(0, 4)` / `sublist(4)`) that assumed the first four items
were always WIF/private key/public key/xPub. Adding the master fingerprint
as the first item pushed xPub into the Silent Payments tab.

Route Bitcoin silent payment keys into their own `silentPaymentItems` list
instead, and render each tab from its list.

98/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
secret or key materialsigning or wallet path
AI analysis · Informational 15/100

This commit is a user-facing feature, not a security fix. It adds a new 'Master fingerprint' value to the Bitcoin wallet keys screen and fixes a small UI bug where adding that new item accidentally moved another key (xPub) into the wrong tab. There is no indication of a vulnerability being patched.

AI review queued26-08-07_Update Translation_de_DEby bsn21m · 6728f75b · Aug 7, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · bsn21m

26-08-07_Update Translation_de_DE

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates German translation strings in a single language file. It removes a few duplicate entries, fixes typos, rewords some user-facing messages, and adds new German translations for recently introduced app features. There are no code or security changes.

AI review queuedfix: display proper address in zcash transactions (#3457)by cyan · c93843f3 · Aug 7, 2026 · 2 filesMessage 70 · AdequateInformational 22Details
Commit message · cyan

fix: display proper address in zcash transactions (#3457)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 22/100

This commit fixes how Zcash wallet transactions display recipient addresses. Previously, the app could misidentify which addresses belong to the user's own wallet, causing it to show the wrong address (or even the user's own address) as the destination for a payment. The fix builds a single, authoritative list of addresses the wallet actually owns and uses that to decide which outputs are real external payments. There is no direct evidence this is a security vulnerability that can be exploited by an attacker; it appears to be a UI correctness bug that could confuse users or make transaction records less trustworthy.

Lower-priorityHide the receive rotation notice for static Zcash address types (#3444)by Seth For Privacy · fb790120 · Aug 7, 2026 · 4 filesMessage 58 · ThinTriage 0Details
Commit message · Seth For Privacy

Hide the receive rotation notice for static Zcash address types (#3444)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedAdd tbb to solana default tokens (#3461)by David Adegoke · 14d2862b · Aug 6, 2026 · 41 filesMessage 86 · StrongLow 28Details
Commit message · David Adegoke

Add tbb to solana default tokens (#3461)

* fix android CI

* deat: add The Bitcoin Bull to solana default tokens list

* add verification status for solana tokens

86/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Low 28/100

This commit adds a new Solana token called 'The Bitcoin Bull' (TBB) to Cake Wallet's default token list and introduces a Jupiter verification check to help flag potentially scam tokens. It also includes many unrelated translation string updates. The main security-relevant change is the new Jupiter verification lookup, which makes the wallet trust tokens verified by Jupiter when users add custom Solana tokens. There is no direct evidence of a vulnerability being fixed or introduced, but the change alters how the app decides whether a token is trustworthy.

Security candidateCW-1581-trezor-fixes-enhancements (#3462)by Konstantin Ullrich · feeec2e4 · Aug 6, 2026 · 46 filesMessage 76 · AdequateLow 27Details
Commit message · Konstantin Ullrich

CW-1581-trezor-fixes-enhancements (#3462)

* feat: add Trezor auto connect

* chore: update `trezor_flutter`

* fix: correct method name for retrieving Trezor auto-pairing credentials

* fix: update device connection prompt text across all languages [skip ci]

* feat: add Trezor key image synchronization ui and improve hardware wallet UX

* feat: add sync-balance icon asset for settings row visuals [skip ci]

* feat: add sync-balance icon asset for settings row visuals [skip ci]

* fix: remove unused Monero and sync key images settings actions from menus [skip ci]

* fix: re-enable routing for UR QR Animated Page [skip ci]

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
credential or privilege stateprivacy or spend-authorization protocolsigning or wallet path
AI analysis · Low 27/100

This commit improves how Cake Wallet connects to Trezor hardware wallets and synchronizes Monero 'key images' (data that proves coins haven't already been spent). It adds automatic reconnection, a new user interface for syncing key images, and stores an encrypted Trezor pairing state on the device. The changes are mostly user-experience and reliability fixes rather than a clear security patch, though they touch on sensitive areas such as encrypted storage, hardware wallet pairing, and transaction signing flow.

Lower-prioritya11y: send flow and QR scanner semantics (fields, errors, status announcements) (#3466)by Seth For Privacy · 76b04580 · Aug 5, 2026 · 15 filesMessage 100 · StrongTriage 0Details
Commit message · Seth For Privacy

a11y: send flow and QR scanner semantics (fields, errors, status announcements) (#3466)

* Make send flow controls announce their purpose and state

Wraps the send-flow inputs and controls in localized Semantics so a screen
reader can operate them:

- address, amount, memo and manual scan fields get a persistent name and
announce their validation errors as live regions
- the asset picker, max-balance chip, recipient dots, dropdown toggles and
scan page buttons become real buttons with selected/expanded state
- send progress, send errors, sync status and multi-part QR progress are
exposed as single status nodes (announced once, not per tick)
- purely visual duplicates (address overlay, memo counter, max caption,
full-screen tap-to-exit target, hidden confirm-sheet page) stop producing
extra nodes
- LoadingPrimaryButton/PrimaryButton keep their name while showing a spinner
and report the disabled state
- replaces hard-coded English "Synchronizing...", "Coin Control" and 'ok'
with localized strings

* Scope mounted guard to the new announcement only

* Address review: liveRegion success, loading tap guard, drop redundant PrimaryButton wrapper

* Stop the currency picker from swallowing the amount field node

An on-device audit (CW-1574, D1) found the send screen's amount field
missing from the Android accessibility tree entirely: without this branch
the tree held an "Amount:" text node plus an EditText, with it there was
no node for the field at all. The address field, wrapped the same way on
the same branch, survived.

The difference is FormField. Flutter wraps a FormField's builder output in
its own non-container Semantics(validationResult:) annotation, and that
annotation becomes the node parenting everything the field renders. The
currency picker's Semantics had no `container: true`, so it is not a
boundary either and its configuration was absorbed into that same wrapper
node. The result was one node carrying isButton + a tap action + the
picker's label, with the amount TextField as its child - so screen readers
surfaced the container and never reached the field.

Declaring `container: true` on the picker gives it a node of its own and
leaves the FormField wrapper unlabelled, so the field, the paste button
and the picker are three sibling nodes again. No visual change.

The address field is unaffected because every Semantics inside its
FormField is already a boundary; the memo field and the scan manual-entry
field have no FormField and no absorbing sibling, so they were never hit.

Also replaces the two send-page caption comments, whose "the field
announces this label itself" claim is what let the regression through,
with a statement of what actually guarantees it.

* Name the amount field from its caption instead of labelling the field

Closure audit of the D1 fix found the amount announced twice on device:

[o420] ImageView "Amount: 0.00"
[k527] EditText "Amount: 0.00"
"BTC"

The framework tree has no such duplication. Post-D1-fix it holds exactly
one node carrying the label, and that node *is* the text field: a merge
boundary with no children, reporting no children to the engine, with
isImage false on every node in the tree. The only thing above it is
FormField's own unlabelled Semantics(validationResult:) node, whose
children are the field, the paste button and the currency. That wrapper is
[o420] - its Flutter label is empty, so the text and the ImageView role the
device shows on it are synthesized platform-side from its descendants.

We cannot delete FormField's wrapper, so the only lever is to stop
authoring a label on the field for the wrapper to reflect. This restores
the pre-#3466 shape, which the device A/B already verified as good: the
visible "Amount:" caption goes back into the semantics tree and the field
carries no label of its own, giving caption + field as two adjacent stops.

Both halves are required - un-excluding the caption while keeping the
wrapper label produces two "Amount"-bearing nodes in the framework tree
itself.

The tradeoff is that the field has no programmatic accessible name any
more; it is named by reading-order adjacency to its caption, so focusing
it directly announces the value without the word "Amount". That is exactly
how the field behaved before #3466.

The address field keeps its merged label and excluded caption, because the
device audit shows it as a single correct node. Memo and scan manual entry
are untouched. The `container: true` D1 fix on the picker stays - it is
what got the field node back in the first place.

* Set headingLevel on the confirm-sheet title for the 3.41 engine

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Lower-prioritya11y: receive flow semantics (copy control, pickers, selection state) (#3467)by Seth For Privacy · 930397cb · Aug 5, 2026 · 18 filesMessage 81 · StrongTriage 0Details
Commit message · Seth For Privacy

a11y: receive flow semantics (copy control, pickers, selection state) (#3467)

* Add strings for receive-flow accessibility labels

New English keys: info, long_press_to_copy, standard, token. They replace
hard-coded English in the receive amount modal, the payjoin copy modal and
the addresses long-press menu, and name the copy hint.

* Collapse copy-to-clipboard controls to one accessible button

CopyWrapper gains an optional controlBuilder that hands the copy callback to
the control it builds instead of stacking its own gesture layer on top, and it
now announces the copy through SemanticsService so screen-reader users get the
same feedback the copied state gives sighted users. When there is nothing to
copy it no longer leaves a gesture detector behind that reads as actionable
but does nothing. Its own tap/long-press wrapper is exposed as one merged
button node with a copy hint and a Copy custom action, so tap-to-copy stays
reachable on rows that also navigate.

The receive copy button used an outer gesture detector for the real work while
the visible ModernButton had a no-op onPressed behind two IgnorePointers.
It is now a single ModernButton whose onPressed copies, or opens the payjoin
copy modal when there is no direct URI to copy; the AnimatedSwitcher copied
state is unchanged. The payjoin modal announces the copy and no longer
hard-codes "Standard".

* Add screen-reader semantics to receive flow and address pickers

Every control touched here becomes exactly one merged semantics node with a
localized name, the right role and, where it exists, its selection state:

- receive page: the label chip is a button hinted with set_label and is kept
out of the semantics tree while it is collapsed to zero height.
- amount modal: token picker and currency picker are buttons named by
select_token / select_fiat_currency_title, the amount field carries the
amount label instead of relying on its placeholder, and the visible captions
are excluded so they are not announced twice.
- amount display: amount, symbol and fiat equivalent are announced together.
- info box: Dismiss is a real button, the info icon and the illustrative
currency stack are decorative (the message text carries their meaning).
- address type: the row and its chevron triggered the same picker; only the row
is exposed now, named by address_type.
- address type selector: More Options exposes its expanded state, each option
row reports selected + inMutuallyExclusiveGroup (its checkbox is excluded so
the state is announced once), and the collapsed options are unreachable.
- label modal quick-label chips are buttons.
- addresses page: rows are buttons reporting selection, with the long-press
actions (set label, hide/unhide, info) also exposed as custom semantics
actions; the checkmark is decorative; the search field keeps a name once it
has text; show-hidden-addresses is a button.
- currency picker: search field, clear button, currency rows, chain chips and
network rows get names, roles and selection state; icons and chevrons are
decorative.

No visual or pointer behaviour changes.

* Drop single-use locals to keep the diff minimal

* Address review: replace deprecated copy announcements with semantic state

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Security candidatefix:quick actions cold start (#3476)by Serhii · 061f36a6 · Aug 5, 2026 · 4 filesMessage 68 · AdequateInformational 17Details
Commit message · Serhii

fix:quick actions cold start (#3476)

* fix:quick actions cold start

* route receive links to new receive page

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
authentication path
AI analysis · Informational 17/100

This commit fixes a bug where app shortcuts (quick actions) didn't work correctly when the wallet app was started from a cold state. It also updates the 'receive' shortcut to open the newer receive page instead of the older address page. There is no clear security issue here; it is a routine UI/UX bug fix.

Security candidateWrap long passphrase value on the wallet seed/keys screen (#3480)by claude[bot] · 0e42f162 · Aug 5, 2026 · 1 fileMessage 58 · ThinInformational 15Details
Commit message · claude[bot]

Wrap long passphrase value on the wallet seed/keys screen (#3480)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
access controlsigning or wallet path
AI analysis · Informational 15/100

This commit is a minor user-interface fix that makes very long wallet passphrases wrap to multiple lines instead of overflowing the screen. It does not change security behavior, cryptography, or how secrets are stored or protected.

Lower-priorityreplace asserts for semantic labels with lints (#3483)by malik1004x · 0b93bafe · Aug 4, 2026 · 7 filesMessage 58 · ThinTriage 0Details
Commit message · malik1004x

replace asserts for semantic labels with lints (#3483)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
AI review queuedcw-1584-ironwood-migration-modal (#3481)by malik1004x · 0257f5cf · Aug 4, 2026 · 11 filesMessage 76 · AdequateInformational 18Details
Commit message · malik1004x

cw-1584-ironwood-migration-modal (#3481)

* ironwood migration modal

* auto-show when migration begins

* remove restricted import

* new condition

* string fix

* only activate if ironwood is active

* reaction safeguards

* migration*

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100

This commit adds a user-interface feature for Zcash wallets that displays an informational modal when the user's funds are being automatically migrated to the new Zcash 'Ironwood' network upgrade. It does not change how funds are secured, sent, or received; it only shows explanatory text and a 'Learn more' link. There is no indication of a security vulnerability in this change.

AI review queuedfix: hide dust balance from "confirming" (#3456)by cyan · dc213417 · Aug 3, 2026 · 2 filesMessage 65 · AdequateLow 26Details
Commit message · cyan

fix: hide dust balance from "confirming" (#3456)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 26/100

This commit changes how Cake Wallet's Zcash wallet calculates and displays balances that are still 'confirming' or otherwise unavailable. It filters out tiny 'dust' notes from the unavailable balance, adjusts which note pools are considered spendable during the Zcash Ironwood network upgrade, and changes the bitmask used when building transactions. The main user-visible effect is that small unspendable notes no longer appear as 'confirming' balance, which could previously make users think they had funds that were not actually usable.

AI review queueda11y: dashboard and navigation semantics (navbar, cards, sync, switchers) (#3468)by Seth For Privacy · a6bcf7c9 · Aug 3, 2026 · 19 filesMessage 81 · StrongInformational 15Details
Commit message · Seth For Privacy

a11y: dashboard and navigation semantics (navbar, cards, sync, switchers) (#3468)

* Label new-UI dashboard navigation and sync status for screen readers

Each bottom-nav tab becomes one button node carrying its localized name, its
selected state and mutual exclusion; the pill text no longer duplicates the
selected tab. The assets/history tabs gain selected state, the Bitcoin/Lightning
switcher becomes a labeled toggle, and the sync bar becomes a single button whose
label is the localized status (plus Tor/MWEB/Silent Payments badges) with a hint
pointing at node management. Compact mode's pulsing dot and the chain icon's
progress ring now have text equivalents, and the invisible pointer-absorbing
strip behind the nav bar is excluded from traversal.

* Make new-UI dashboard cards, lists and menus operable by screen readers

Collapse the wallet-name row into one labeled button (hardware-wallet glyph
folded into the label, inner accounts button no longer a second stop) and give
balance cards a labeled, selectable node with a long-press action for show/hide
balance. Balances hidden behind AnimatedOpacity, card artwork and decorative
glyphs leave the semantics tree; the 3-dots customize target and the card action
buttons are now named buttons. Assets/history rows, the history header, the MWEB
promo, long-press menu items, the account cards and the add-account and
generate-name controls become single button nodes, the phantom action chip in the
assets header is built conditionally instead of drawn at opacity 0, and app cards
get a close tooltip plus an 'opens externally' hint.

* Use expression bodies for the new a11y helpers

* Restore untouched expressions in cards_view

* Address review: state-aware balance hint, tooltip-free close label

* Address review: keep header height without the chip, name the selected index

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit improves accessibility for screen-reader users in the Cake Wallet app's new dashboard. It adds labels and roles to navigation tabs, balance cards, buttons, and status indicators so assistive technology can describe them properly. There is no security-relevant change here.

Security candidatesecurity: require app-level vulnerability proofsby sethforprivacy · 42019d86 · Aug 3, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · sethforprivacy

security: require app-level vulnerability proofs

62/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
explicit security languagedocumentation-only discount
AI analysis · Informational 15/100

This commit only updates the project's security policy document (SECURITY.md). It tightens the rules for vulnerability reports by requiring proof-of-concept code that actually runs against the Cake Wallet app, and it asks contributors not to use AI-generated comments. There are no code changes, no bug fixes, and no direct security impact on the app itself.

AI review queued26-08-03_Update Translation_de_DEby bsn21m · e946627e · Aug 3, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · bsn21m

26-08-03_Update Translation_de_DE

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a routine German translation update. It changes wording in user-facing text (for example, replacing 'Tausch' with 'Swap' and 'Gelder' with 'Guthaben'), adds a few missing translated strings, and updates navigation instructions. There are no code, logic, or security changes.

Security candidatea11y: expose ModernButton, CoinActionButton and ModalTopBar as single labeled button nodes (#3463)by Seth For Privacy · 26a16a4e · Aug 2, 2026 · 75 filesMessage 91 · StrongInformational 21Details
Commit message · Seth For Privacy

a11y: expose ModernButton, CoinActionButton and ModalTopBar as single labeled button nodes (#3463)

* Give ModernButton and CoinActionButton one labeled a11y node

ModernButton, CoinActionButton and the ModalTopBar chrome buttons were
icon-only IconButtons with no tooltip and a detached caption sibling, so
screen readers announced an unnamed "button" plus unrelated static text.

- Add optional semanticLabel to ModernButton; wrap the control in
MergeSemantics + Semantics(button: true, label: semanticLabel ?? label)
and exclude both the icon and the visible caption so exactly one node
is exposed. No visual or pointer change.
- Give CoinActionButton the same treatment, reusing the label callers
already pass (dashboard Send / Receive / Swap / Scan).
- Add leadingSemanticLabel / trailingSemanticLabel to ModalTopBar,
defaulting the leading button to "Close", and mark a non-empty title
as a semantics header.
- Migrate every ModernButton / ModalTopBar call site to pass a localized
label, and drop the now-redundant external Semantics wrapper in
base_page.dart so the back button is not labeled twice.
- Localize the hard-coded "Settings" modal title in settings_page.dart.

New English keys: rotate_address, swap_reverse_direction, switch_camera,
switch_input_currency, test_node_speeds, turn_flash_off, turn_flash_on.

* Require explicit accessible names on ModalTopBar and ModernButton icons

ModalTopBar defaulted every leading icon's accessible name to "Close", so
the ~40 callers that pass a back arrow announced the wrong action, and
trailingSemanticLabel was optional, leaving the trailing icon controls
unnamed.

- Drop the "?? close" fallback in ModalTopBar: the leading ModernButton
now gets exactly leadingSemanticLabel, and constructor asserts require a
non-empty label whenever leadingIcon / trailingIcon is supplied. Callers
that pass leadingWidget / trailingWidget instead are unaffected, and a
null icon still builds no button at all.
- Assert in both ModernButton constructors that the control has a name:
either semanticLabel or a non-empty visible label.
- Pass the matching localized label at every ModalTopBar call site: "Go
back" for back arrows, "Close" for close icons, and the action name for
trailing icons (History, Configure, Export CSV, Save, Scan, Close).
- Label the last unnamed ModernButton (wallet accounts, wallet_info.dart).

No new localization keys; all labels reuse existing strings_en.arb keys.

* fix(a11y): put ModalTopBar header flag on the title Text node

On-device audit (CW-1574, defect D2) found zero [heading] nodes in the
Android accessibility tree on the Receive page: Semantics(header:) wrapped
the AnimatedSwitcher rather than the Text inside it, so the flag never
landed on the node that carries the title label.

Move the header semantics inside the AnimatedSwitcher, directly around the
Text. The ValueKey(title) moves with it onto the Semantics wrapper, since
AnimatedSwitcher switches on its direct child's key -- keying the Semantics
by title preserves the existing switch/animation behavior exactly.

No test or robot resolves the title ValueKey through a Text-typed finder,
so the key relocation is not observable from the test suites on this branch.

* Set headingLevel so Android surfaces modal titles as headings

The Flutter 3.41 engine drives AccessibilityNodeInfo.setHeading from
headingLevel, not the IS_HEADER flag (which 3.35 used). Proven by an
on-device probe: header:-only headings print on a 3.35-engine build and
vanish on the 3.41-engine CI build.

91/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathauthentication path
AI analysis · Informational 21/100

This commit is an accessibility (a11y) improvement, not a security fix. It makes icon-only buttons and modal titles readable by screen readers by attaching proper labels to them. There is no vulnerability being patched and no way for an attacker to exploit these changes.

Security candidateEnforce passphrase confirmation match on the restore and create wallet flows (#3474)by claude[bot] · f6566e3b · Aug 2, 2026 · 2 filesMessage 81 · StrongModerate 52Details
Commit message · claude[bot]

Enforce passphrase confirmation match on the restore and create wallet flows (#3474)

* fix: enforce passphrase confirmation in restore passphrase bottom sheet

The confirm-passphrase field in AddPassphraseBottomSheet already had a
validator comparing it to the first field, but the fields were not inside
a Form and nothing ever called validate(), so the validator never ran.
Tapping "Restore" restored the wallet with the first field's value even
when the confirmation did not match, defeating the typo check.

Wrap both fields in a Form and validate it before completing the restore,
matching the existing pattern in advanced_privacy_settings_page.dart.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019DtLNfYw1H81p7zZrkNDXM

* Validate passphrase confirmation when the passphrase field is empty

---------

Co-authored-by: Claude <noreply@anthropic.com>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access controldefensive validationsigning or wallet pathauthentication path
AI analysis · Moderate 52/100

This commit fixes a bug in the wallet restore and creation screens where the 'confirm passphrase' field was not actually being checked. A user could type one passphrase and a different confirmation, yet still proceed. The wallet would then be created or restored using only the first passphrase, which could lock users out of their funds if they made a typo. The fix wraps the fields in a proper form and validates the confirmation before continuing.

Lower-priorityPoint changelog modal "View more info" at docs release notes (#3459)by claude[bot] · b50ceb24 · Jul 30, 2026 · 1 fileMessage 58 · ThinTriage 0Details
Commit message · claude[bot]

Point changelog modal "View more info" at docs release notes (#3459)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityfix: add reconnection logic to hardware wallet flow to handle tap-backs (#3458)by Konstantin Ullrich · 22015eb1 · Jul 30, 2026 · 4 filesMessage 70 · AdequateTriage 0Details
Commit message · Konstantin Ullrich

fix: add reconnection logic to hardware wallet flow to handle tap-backs (#3458)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Lower-priorityintoduce-moneytext (#3447)by Konstantin Ullrich · cb194fba · Jul 27, 2026 · 14 filesMessage 58 · ThinTriage 0Details
Commit message · Konstantin Ullrich

intoduce-moneytext (#3447)

* feat: Introduce `MoneyText` and `CurrencySymbolText` Widgets

* feat: add accessibility to `MoneyText`

58/100 · ThinMessage clarity
✓ Descriptive subject✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Lower-priorityupdate build numbers fix cw_zcash importby Omar · a6121350 · Jul 27, 2026 · 6 filesMessage 60 · AdequateTriage 0Details
Commit message · Omar

update build numbers
fix cw_zcash import

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Lower-priorityfix: zkool2 (#3445)by cyan · fe3a702e · Jul 27, 2026 · 1 fileMessage 48 · ThinTriage 0Details
Commit message · cyan

fix: zkool2 (#3445)

48/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Security candidatezec ironwood (#3425)by cyan · 92c2c5e0 · Jul 27, 2026 · 38 filesMessage 59 · ThinLow 35Details
Commit message · cyan

zec ironwood (#3425)

* initial

* wip

* ironwood detection, migration

* dev: zec address validation on rt

* fix: ironwood spend

* ironwood regressions

* fix: tx history

* bump: zkool2

* fix: tx amounts on pending
fix: ironwood pending balance
fix: orchard->ironwood migration
fix: orchard->any pre ironwood txs
fix: ironwood -> any txs
fix: WrongSpendAuthorizingKey
fix: tx history
fix: autoshield to ironwood
fix: zkool to latest version
break: my sleep schedule :sweating: :worksonmymachine:

* thx fable

* downgrade frb to 2.11.1

* fix: tx amounts in history

* Migating... / migration label for O->I txs

59/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
update trustsigning or wallet path
AI analysis · Low 35/100

This commit adds support for Zcash's Ironwood network upgrade to Cake Wallet. It changes how wallet balances, transactions, and addresses are handled when Ironwood activates, and it lets advanced users pick mainnet, testnet, or regtest for Zcash. The changes are mostly functional upgrades and bug fixes rather than a clear security patch, but they touch sensitive areas like balance calculation, transaction construction, and address validation. Because the commit is large and partially hardcodes dev-network settings (for example, a regtest node at 10.0.2.2), there is some risk of misconfiguration or incorrect balance reporting, though no direct exploit is visible in the diff.

Security candidateShuffle change output on hardware wallet and Bitcoin Cash sends (#3432)by Cindy · b73c46ac · Jul 26, 2026 · 5 filesMessage 81 · StrongLow 49Details
Commit message · Cindy

Shuffle change output on hardware wallet and Bitcoin Cash sends (#3432)

* Shuffle change output on hardware wallet sends

Hardware wallet BTC/LTC sends passed outputs to the PSBT/device in the
given order (change last), a position fingerprint. The outputOrdering
param was plumbed but ignored. Add orderOutputs() and apply it in both
buildHardwareWalletTransaction paths; set the send call site to shuffle.

Refs #3376 (the software send + RBF paths were covered by #3420).

* Shuffle change output on Bitcoin Cash sends

The BCH send path built via ForkedTransactionBuilder with
outputOrdering: none, leaving change deterministically last. The builder
shuffles natively and change is found by isChange, not position, so flip
it to shuffle (matches the BTC software path from #3420).

Refs #3376.

* Update cw_bitcoin/lib/electrum_wallet.dart

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 49/100

This commit fixes a privacy weakness in Cake Wallet's Bitcoin, Litecoin, and Bitcoin Cash sending flows. Previously, when using a hardware wallet or sending Bitcoin Cash, the app's own 'change' output was always placed last in the transaction. That predictable ordering acts like a fingerprint, making it easier for outside observers to identify which output belongs to the sender and trace the user's funds. The patch shuffles output order so the change output no longer sits in a fixed, telltale position.