Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…
This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…
New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…
Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …
New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…
Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…
Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…
Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…
UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…
No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…
UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…
Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…
No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…
Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…
Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…
Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…
New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …
Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…
Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…
This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…
Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 32/100
This commit disables the Exolix cryptocurrency exchange provider in the Cake Wallet app. It adds a one-time settings migration that turns Exolix off for all users and bumps the migration version so the change runs on app startup. The commit message gives no reason, and there are no supplied references explaining whether this is a security fix, a business decision, or a response to an incident.
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 44/100
This commit fixes how Cake Wallet looks up Bitcoin addresses when checking transaction history. Previously, the code mixed up 'change' (internal) addresses and 'receive' (external) addresses, and did not properly separate newer standard addresses from older legacy addresses. The fix organizes addresses into four clear groups—standard receive, standard change, legacy receive, and legacy change—and checks each group separately. This likely prevents the wallet from missing transactions or incorrectly marking address gaps, which could affect balance accuracy. There is no direct evidence in the commit that this was a security vulnerability or that it could be exploited by an attacker.
Lower-priorityFix domain lookup toggles for Yat and Zcash.me providers (#3439)by Seth For Privacy · 7f090c3a · Jul 24, 2026 · 2 filesMessage 81 · StrongTriage 0Details
Commit message · Seth For Privacy
Fix domain lookup toggles for Yat and Zcash.me providers (#3439)
Both providers checked the wrong SettingsStore flag in isEnabled(), so their toggles in Settings > Connection and sync > Domain lookups had no effect:
- YatAddressProvider read lookupsWellKnown instead of lookupsYatService, so the 'Yat' toggle did nothing and '.wellknown' unexpectedly gated it. - ZcashMeAddressProvider read lookupsZcashNames instead of lookupsZcashAddress, so the 'Zcash.me' toggle did nothing and it was gated by the 'Zcash Names' toggle.
Each provider now reads the flag its own toggle writes, matching the mapping in ConnectionSyncViewModel.lookupValue/setLookupValue.
81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Lower-priorityFix stale seed location path in seed_display_path (#3440)by Seth For Privacy · 1a0c3e0d · Jul 24, 2026 · 1 fileMessage 86 · StrongTriage 8Details
Commit message · Seth For Privacy
Fix stale seed location path in seed_display_path (#3440)
The string still described the old UI navigation ("Menu → Security and Backup → Show key/seeds"). With FeatureFlag.hasNewUi there is no Menu, and the Show seed/keys row is commented out of the Security page. Seeds and keys now live at Settings → Wallet settings → Seed & Keys.
Rendered in two places, both reachable: - seed_verification_success_view.dart:54 - wallet_group_existing_seed_description_page.dart:57
86/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
defensive validation
Lower-priorityFix mismatched support links for SwapTrade and Telegram (#3441)by Seth For Privacy · 6641549d · Jul 24, 2026 · 1 fileMessage 81 · StrongTriage 0Details
Commit message · Seth For Privacy
Fix mismatched support links for SwapTrade and Telegram (#3441)
Two entries in SupportViewModel's link list displayed one destination but opened another.
SwapTrade pointed at mailto:support@exolix.com, so a user with a SwapTrade trade problem emailed Exolix — who cannot help, and who absorbed another provider's support traffic. The entry was added as Quantex with Exolix's mailto already copy-pasted in from the entry above it; the Quantex -> SwapTrade rename updated the title, icon and linkTitle but carried the wrong link forward.
Point it at https://help.swaptrade.io/contact/, which matches what docs.cakewallet.com/support/swap lists for SwapTrade. Live chat is the only contact method that help center publishes — there is no SwapTrade support email — so the mailto form is not an option. Using a path below the displayed host follows the existing SideShift entry in this file.
Telegram had the inverse problem: linkTitle read t.me/cakewallet while the link went to the announcements channel. Here the link was correct — t.me/cakewallet is a group that self-describes as the inactive Cake Wallet Community and directs visitors to the announcements channel — so the stale label was updated to match the destination rather than the reverse.
The other 15 entries were audited and are consistent.
81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Lower-priorityci: sanitize branch name when naming test APK in reusable-buildby sethforprivacy · c50d0fc6 · Jul 24, 2026 · 1 fileMessage 95 · StrongTriage 0Details
Commit message · sethforprivacy
ci: sanitize branch name when naming test APK in reusable-build
The 'Rename apk file'/'Find APK file' steps used the raw ${BRANCH_NAME} as an APK filename, so any branch containing a '/' (e.g. claude/*) made cp target a non-existent test-apk/<prefix>/ subdirectory and failed the build. Derive the sanitized branch name from android/app.properties, the same approach already used in automated_integration_test.yml.
95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Fix typo in multichain receive infobox (addess -> address) (#3436)
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only updates the app's version and build numbers in build scripts for Android and iOS. It does not change any code that handles money, user data, security, or app behavior. There is no security issue here.
AI review queuedfix: stop resetting coin control on swap (#3433)by Konstantin Ullrich · 8056cfec · Jul 22, 2026 · 2 filesMessage 65 · AdequateLow 26Details
Commit message · Konstantin Ullrich
fix: stop resetting coin control on swap (#3433)
65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 26/100
This commit fixes a bug where the user's coin-control choices were being reset when swapping between send screens. Coin control lets a user choose exactly which coins (UTXOs) are spent. Previously, the app called a reset function after initial setup, clearing any selections the user had made. The patch removes that reset and also makes the code that tracks coins compare them by their unique transaction hash and output index rather than by a looser object equality, which should make coin tracking more reliable.
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only increments the app's build number from 4415 to 4416 on Android and from 425 to 426 on iOS. It changes no code, fixes no behavior, and has no security relevance visible in the diff.
Lower-priorityrevert and just show the change wallet button if it's a reconnectby Omar · d2521aa0 · Jul 21, 2026 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · Omar
revert and just show the change wallet button if it's a reconnect
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
✓ Descriptive subject✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 49/100
This commit changes how Zcash wallet addresses are stored in the app's local wallet info. Instead of saving the full address map to persistent storage, it now saves an empty map, while still saving related metadata like address info, used addresses, and hidden addresses. The commit title says this fixes 'address leaks,' which suggests the previous behavior may have exposed or stored more address data than intended. However, the diff alone does not show what specific sensitive data was leaking, to whom, or under what conditions.
Lower-priorityadd a back button so you can always go back from the hardware wallet connect screenby Omar · a43c32d6 · Jul 21, 2026 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · Omar
add a back button so you can always go back from the hardware wallet connect screen
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only updates version numbers and build numbers across platform-specific build scripts. It does not change any application code, cryptographic logic, network handling, or user-facing behavior. There is no security relevance.
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit only adds a few German translations for user-facing text strings (for example, labels related to passphrases and an 'Autoshield' feature). There are no code changes, no security fixes, and no behavior changes.
* v6.3.0 Release Candidate - the new transaction history - Radar in Apps screen - Zcash update - Flutter update - Parts of the Refactor should improve how amounts are handled in the app and fix any issue with amounts improve handling sending to aliases
- Improvements for Cake Pay mobile - Bug fixes
* don't use memo for note/message values
* save message in QR locally in the notes field
* Make stealth addresses generated from silent payment, not reliant on output index (#3420)
* - fix swaps showing only on primary account - switch tron default node - privacy fixes
* - enlarge destination tag and make it copiable - migrate users on hashvault - minor fix
76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
privacy or spend-authorization protocolsigning or wallet pathauthentication path
AI analysis · Low 45/100
This is a routine version-bump release candidate for Cake Wallet/Monero.com v6.3.0. The visible code changes include several privacy-related tweaks: Bitcoin transaction output ordering is now shuffled instead of fixed, a Tor/onion exchange provider now uses HTTPS instead of HTTP, default Tron and Monero nodes are switched/migrated away from TronGrid and HashVault, and a hardware-wallet passphrase field disables autocorrect. There are also UI fixes for destination tags and QR-code payment notes. The commit message itself mentions 'privacy fixes' but does not describe a specific vulnerability or disclose a security incident.
AI review queuedrefactor: remove deprecated payment URI classes and unify URI handling with `ERC681URI` implementation (#3423)by Konstantin Ullrich · b336da4a · Jul 20, 2026 · 3 filesMessage 93 · StrongInformational 14Details
Commit message · Konstantin Ullrich
refactor: remove deprecated payment URI classes and unify URI handling with `ERC681URI` implementation (#3423)
* refactor: remove deprecated payment URI classes and unify URI handling with `ERC681URI` implementation
* refactor: apply lint [skip ci]
93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 14/100
This commit is a code cleanup: it removes several old, near-duplicate payment-URI classes for Ethereum-compatible chains (Polygon, Base, Arbitrum, BSC) and makes every EVM chain use a single shared ERC-681 URI builder. It also adds a parser to read those URIs back. The change is mostly a refactor with no obvious security bug, but it touches code that formats crypto payment amounts and addresses, so a small risk of accidental parsing/formatting mistakes remains.
* security: add discretionary reward policy and marketing-site out-of-scope
98/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
This commit only updates the project's written security policy (docs/SECURITY.md). It does not change any application code, fix a bug, or patch a vulnerability. It clarifies how researchers should report security issues, adds safe-harbor language, defines scope, and introduces a discretionary reward policy. There is no direct security risk or security improvement to the software itself.
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body