CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
421commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 25 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidatefix: add new images and fix integration tests (#3679)by David Adegoke · ad93901a · Oct 5, 2026 · 17 filesMessage 80 · StrongInformational 15Details
Commit message · David Adegoke

fix: add new images and fix integration tests (#3679)

80/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 15/100

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to point at the new Robinhood QR asset, and tweaks how stablecoins are filtered in the currency picker. There is no code change that introduces a security vulnerability.

Security candidateAdd Robinhood Chain (#3398)by David Adegoke · 046e57c5 · Oct 4, 2026 · 143 filesMessage 76 · AdequateLow 35Details
Commit message · David Adegoke

Add Robinhood Chain (#3398)

* fix android CI

* feat: Add Robinhood Chain, all major flows done. minor issue now is our providers don't support it yet as its still pretty early, two weeks from launch

* feat: Add Robinhood Chain, all major flows done. minor issue now is our providers don't support it yet as its still pretty early, two weeks from launch

* Cleanup

* auto-reformat

* fix ui issue and contact listing for tokens

* fix: missing icons and crash for fee priority in settings

* chore: cleanup

* fixes from feedbacks

* fix: review issues and sync to latest dev
feat: switch history api to etherscan, add history toggle to privacy settings, exclude robETH from exchange pickers, skip tokens discovery for chains that moralis hasn't indexed, add tests

* fix: address Robinhood review comments

* fix: show Solana token icons in history

* fix: address review comments and default Robinhood to PublicNode

* fix: revert filter and refuse unmapped networks in provider

---------

Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive pathseed or entropy pathsigning or wallet path
AI analysis · Low 35/100

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction history, settings, and UI assets. There is no direct evidence in the commit of a security vulnerability, but the size and breadth of the change introduce ordinary implementation risks typical of adding a new EVM chain.

AI review queuedchore: migrate to hosted scalable CI (#3620)by cyan · 77e4b946 · Oct 3, 2026 · 23 filesMessage 65 · AdequateInformational 16Details
Commit message · cyan

chore: migrate to hosted scalable CI (#3620)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 16/100

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a hard-coded developer test certificate and private key for CI builds. There is no direct change to the wallet's user-facing code, cryptography, or network behavior. The main security concern is that the new CI provider and the committed test signing material could, in theory, be misused if secrets or build outputs leak, but the commit itself does not introduce a known vulnerability in the app.

Security candidatecw-1683-prepare-zano-removal (#3668)by malik1004x · 86616811 · Oct 3, 2026 · 12 filesMessage 76 · AdequateInformational 23Details
Commit message · malik1004x

cw-1683-prepare-zano-removal (#3668)

* wip zano removal

* add zano removal popup

* constantly show popup if user keeps using deprecated wallet

* add confirmation before viewing seed

* fix viewed check

* prevent wallet staying open after seed backup

* Update lib/entities/default_settings_migration.dart

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* add passphrase

* make popup scrollable

* delete deprecated seeds when wallet is deleted

* encrypt seeds

* also deprecate decred

* remove decred from available types

* remove backup logic

* showArrow: false,

* Remove deprecated wallet seeds deletion

Removed deprecated wallet seeds deletion from delete method.

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access controlsigning or wallet path
AI analysis · Informational 23/100

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, and stops new Zano/Decred wallets from being created. It also fixes a minor cleanup bug where a cached Zano wallet might not be closed before deletion. There is no direct evidence in the commit of an exploitable security vulnerability; the changes are primarily user-facing deprecation and data-preservation work.

AI review queuedonly check address validation once for old addressesby Omar · 1972efd0 · Oct 3, 2026 · 3 filesMessage 50 · ThinLow 29Details
Commit message · Omar

only check address validation once for old addresses

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 29/100

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address labels incorrectly if a stored address didn't match either the normal or hidden chain. Now it checks each old address only once, marks it as checked, and only flips the label if the address actually re-derives from the opposite chain. New addresses created by the wallet are marked correct-by-construction and skipped. The change is a correctness/performance fix rather than a clear security patch, but a mislabeled change address could in theory cause a user to share or reuse an address unexpectedly.

AI review queuedfix balance being stale cuz it's overriden by an old valueby Omar · 1de16191 · Oct 2, 2026 · 3 filesMessage 50 · ThinLow 33Details
Commit message · Omar

fix balance being stale cuz it's overriden by an old value

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 33/100

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per account, avoid updating balances when the network connection is lost, and make address validation non-blocking so it doesn't freeze the app. There is no direct evidence this was exploited or treated as a security vulnerability by the vendor.

Security candidateCw 1551 quick bitcoin wallet sync (#3446)by Serhii · d7ebf428 · Oct 2, 2026 · 84 filesMessage 76 · AdequateLow 33Details
Commit message · Serhii

Cw 1551 quick bitcoin wallet sync (#3446)

* add Wallet Accounts page and integrate UI

* account model refactor

* add walletInfoAccount table and API

* add WalletAccountList API

* add multi-account support for Electrum wallets

* add Bitcoin lightning card and card style handling

* refine account filtering and card selection

* update current account balance on wallet changes

* update configure.dar

* Use named parameters for card design

* Add Bitcoin account handling and refactor lookup

* refactor dashboard

* refactor cards UI and account balance handling

* Improve Bitcoin account selection and balances

* restrict unspent coin usage to current account

* filter transactions by current Bitcoin account

* refactor electrum wallet

* refactor address generation

* add accountIndex to address fetch logic

* Update configure.dart

* reload transactions on Bitcoin account change

* restore multiple BTC accounts and improve fetch

* show account balance with in btc

* track account index in Bitcoin transactions

* discover btc BIP39 accounts during restore

* fix account switching and card ordering bugs

* fix card customizer

* limit account name length in modal

* update BTC account list balance display

* auto-reformat

* formating fix

* skip HD map validation

* fix 0 balance issue

* minor fix

* quick bitcoin wallet sync

* restore shuffle change output

* restore address lookup fix

* Update electrum.dart

* remove account customizer

* Merge branch 'CW-1142-Add-accounts-feature-to-BTC' into CW-1551-Quick-Bitcoin-Wallet-Sync

* probe only segwit in account discovery

* add account discovery limit and tracking

* Improve Electrum sync account handling [skip ci]

* remove legacy monero account and address list UI

* rework BTC account balance refres

* avoid unnecessary BTC account reloads

* refactor account header in addresses page

* fix blank popup when editing an account

* fix: dedupe UTXO balance

* minor fix

* add Bitcoin current account API

* Apply batched suggestions from code review [skip ci]

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* address PR review comments [skip ci]

* remove account customizer and fix accounts init

* restrict extra BTC accounts to SegWit

* add BTC multi-account toggle

* Fix BTC sync gating and account balance update

* minor fix

* Update electrum_wallet.dart

* store selected account on WalletInfo

* Refine wallet account reset visibility

* refactor BTC address prep and move accounts page

* refactor account stack and customizer routing

* migrate legacy Lightning card styles

* unify dashboard account change state

* fix account routing and Electrum balances

* fix account setup and wallet cards UI

* disable Bitcoin Accounts for all hardware

* merge conflicts fix

* minor fixes

* update cards_view [skip ci]

* reverted cards view update [skip ci]

* fix asset name

* moved the transaction filtering into the electrum wallet

* localization

* disable accounts for watch-only wallets

* fix: stop card render from switching the wallet account

* fix: restore Lightning transactions in tx history

* minor fix

* fix: skip duplicate legacy address generation [skip ci]

* fix: correct account balance/design mismatch bugs

* addressing review comments

---------

Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
secret or key materialsigning boundarysigning or wallet path
AI analysis · Low 33/100

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The changes are mostly architectural, but they touch sensitive wallet logic such as key derivation, transaction selection, balance calculation, and address discovery. There is no explicit vendor statement that this is a security fix, and no CVE or independent researcher attribution is present in the commit materials.

AI review queuedfeat: prefill rescan height with the saved Monero and Zcash restore height (#3669)by Seth For Privacy · 0503d542 · Oct 2, 2026 · 5 filesMessage 85 · StrongInformational 19Details
Commit message · Seth For Privacy

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid typing the wrong height when rescanning the blockchain. There is no direct security bug in the code, but it slightly reduces the chance that a user accidentally rescans from block 0 (which would be slower and expose more transaction history/metadata) or enters an incorrect height.

Security candidateMerge pull request #3658 from cake-tech/integration-test-fixesby David Adegoke · bc302f0e · Sep 27, 2026 · 3 filesMessage 83 · StrongInformational 16Details
Commit message · David Adegoke

Merge pull request #3658 from cake-tech/integration-test-fixes

fix: flaky integration test runs on the CI emulator

83/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
authentication pathmerge-commit duplicate discount
AI analysis · Informational 16/100

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a direct 'dismiss' call on notification bars with a safer helper that checks whether the bar is actually showing before trying to dismiss it, preventing a possible crash or visual glitch during PIN entry.

Security candidatefix: handle flushbar dismissalby Blazebrain · 88a7e72c · Sep 27, 2026 · 2 filesMessage 47 · ThinInformational 23Details
Commit message · Blazebrain

fix: handle flushbar dismissal

47/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 23/100

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddly. The new helper checks whether the banner is actually visible before dismissing it, and removes it from the navigation stack if it isn't. The change is a stability fix rather than a security vulnerability.

AI review queuedAdd onionbalance Tor frontends to default node lists (#3431)by Seth For Privacy · c8cad835 · Sep 26, 2026 · 5 filesMessage 81 · StrongInformational 21Details
Commit message · Seth For Privacy

Add onionbalance Tor frontends to default node lists (#3431)

* Add onionbalance Tor frontends to default node lists

Update the primary Monero and Zcash onion nodes to the new
load-balanced onionbalance frontends, add missing Cake Wallet Tor
nodes for Bitcoin and Litecoin, and use the mempool onion frontend
for Bitcoin fee fetching when Tor is enabled. All Cake Tor nodes are
marked isOfficial so they get the official-node badge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Remove per-instance Zcash Tor #2 node, superseded by onionbalance frontend

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 21/100

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and makes Bitcoin fee estimates use a Tor address when Tor mode is on. The changes are infrastructure/configuration updates rather than code fixes for a vulnerability. There is no direct evidence in the commit that this is a security patch, but routing traffic through Tor can improve user privacy.

AI review queuedfix: enter Lightning invoice amounts in sats (#3525)by Omid · fdb82675 · Sep 26, 2026 · 2 filesMessage 93 · StrongInformational 19Details
Commit message · Omid

fix: enter Lightning invoice amounts in sats (#3525)

LN receive remapped btcln to BTC, so the default "sats (LN)" display mode never applied and the amount field stayed in BTC.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Konstantin Ullrich <konstantin@cakewallet.com>

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was being remapped incorrectly. The patch makes the receive screen explicitly set the currency to the Lightning-specific code so the amount field displays in sats as intended. There is no indication this allowed theft, unauthorized access, or code execution; it is a usability/display fix.

AI review queuedRevert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)by Omar Hatem · 2d8d0684 · Sep 25, 2026 · 10 filesMessage 73 · AdequateModerate 60Details
Commit message · Omar Hatem

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This reverts commit dd58455ea6d2629eb1a28991e40bf6f9953d41d3.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 60/100

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. The change also fixes how non-English characters are stored and how user-chosen versus app-generated passwords are handled. Because this is a security-hardening change that was previously reverted and then re-applied, it is relevant to security, but the commit itself does not describe a specific vulnerability or incident.

Security candidateIntegration tests (#3477)by David Adegoke · dfa51657 · Sep 23, 2026 · 137 filesMessage 93 · StrongLow 26Details
Commit message · David Adegoke

Integration tests (#3477)

* fix android CI

* feat: Add integration test harness and new-ui test keys

This change:
- Adds a BaseRobot with bounded waits to replace hard sleeps in integration tests
- Adds AppLauncher, TestConfig and TestWallets as the core test harness
- Adds onboarding flows composing the existing onboarding robots
- Adds robots for the new dashboard, home page and lightning username page
- Adds a tier0 onboarding create suite targeting the new UI
- Applies the declared navbar action keys that were never attached to the InkWell
- Fixes AlertWithOneAction dropping its buttonKey since the alert redesign
- Adds stable ValueKeys to the home page action row, wallet name, top bar and sync bar
- Makes the legacy tap and text entry helpers wait for widgets instead of sleeping

* fix: Test secrets drift and integration test runner parameterization

This change:
- Adds missing test wallet seed and receive address entries to the secrets generator
- Fixes trailing space typos in two secret key names
- Adds bloc_test to pubspec_base.yaml so pubspec regeneration keeps it
- Parameterizes the integration test runner with suite dir, tier, platform and device knobs
- Fixes the runner aborting on first failure and misaligning durations after retries
- Adds adb data reset so Android suites start from a fresh install

* feat: Android emulator integration test workflows for dev PRs

This change:
- Adds a reusable integration test workflow building the app with prebuilt native deps and running the suites on an Android emulator
- Adds the PR gate workflow triggering fund-free tier0 suites on pull requests into dev
- Fixes the old workflow discarding the test runner exit code so failures now fail the job
- Removes the disabled automated integration test workflow on the stale flutter image
- Removes the commit-message gated Linux desktop test steps, unit tests stay
- Removes the vestigial emulator config from the reusable build workflow

* feat: Revive fund-free integration test suites for the new UI

This change:
- Adds tier0 suites for restore, seed confirmation, wallet switching, receive address, settings navigation and the show keys auth gate
- Adds tier1 suites for sync status, swap quotes and transaction history running non-blocking on PRs
- Adds robots for the settings, receive, swap and send sheets
- Adds auth, wallet switching and restore flows
- Applies widget keys to settings rows through their route names, they were declared but never attached
- Adds keys to the swap amount fields, send inputs, confirm swiper and history tiles
- Adds an integrationTest wrapper containing background async app errors that are not test failures
- Makes taps wait out running route transitions before hitting the screen
- Adds a watchdog to the test runner so a wedged driver fails bounded instead of hanging
- Removes the old UI suites, robots, helpers and the stale widget_test counter template

* chore: Add integration testing docs and suite template

This change:
- Adds docs/INTEGRATION_TESTS.md covering the architecture, local runs, tier rules and the flakiness playbook
- Adds a copy-paste suite template teammates start new feature tests from

* feat: Manual funds integration test workflow with funded-chain auto-discovery

This change:
- Adds a funds suite sending a real self transaction on every funded chain
- Adds a funds suite creating a real swap and broadcasting its deposit
- Discovers funded chains from the funded wallet seeds map, adding a seed to the secret adds the chain
- Adds the manual workflow dispatched from the Actions tab with flow, chain and recording inputs
- Gates the run behind the funds-tests environment and posts the result to slack
- Keeps funded seeds out of PR builds, the checked in seed map is empty

* fix: Harden integration test harness from review findings

This change:
- Fixes body failures being swallowed by the guarded test zone, failing suites hung until the watchdog instead of failing fast
- Fixes multi chain CHAINS dispatch values being split apart by the define forwarding
- Fixes the swap limits wait timing out on pairs without a provider minimum
- Makes unknown chain names in CHAINS fail with a readable message
- Keys favorite token rows by index, duplicate token symbols crashed on duplicate keys
- Guards the recording encryption so a keyserver flake cannot eat the test result
- Removes the dead security and backup robot and corrects the screenshot claim in the docs

* chore: Hold two funded seeds per chain in the funded wallets map

This change:
- Changes the funded wallet seeds map to a list of seeds per chain
- Keeps the first seed as the primary for sends and swaps, the second is reserved for cross wallet scenarios

* feat: Try each funded wallet per chain until one has a balance

This change:
- Adds a funds flow restoring a chain's funded wallets in turn and using the first with a spendable balance
- Treats a wallet that finishes syncing while still empty as drained so the next seed gets its turn quickly
- Fails a chain with a top up message when every funded wallet of that chain is empty

* reformat integration test related files

* fix: Run the integration test emulator on the kvm capable runner

This change:
- Moves the test job to the linux-amd64 runner the old emulator workflow targeted, the android builders have no /dev/kvm
- Exposes /dev/kvm through a docker device flag instead of a volume, a bind mount materializes a directory when the host node is missing
- Fails the kvm check in seconds with a clear error instead of waiting out the emulator boot timeout

* fix: Queue the integration test job on the live android runner pool

This change:
- Moves the job back to the android runner labels, no runner carries the old linux-amd64 label anymore so the job queued forever
- Keeps the kvm device flag and check so a host without kvm fails immediately with a clear error

* feat: Run the integration test gate on github hosted runners

This change:
- Moves the test job to ubuntu-latest which has working kvm, the self-hosted android builders do not expose /dev/kvm yet
- Runs directly on the vm since the cake container image does not fit hosted disk, flutter is pinned through the flutter action
- Adds rust android targets for the breez cargokit build and java 17 for gradle
- Keeps the prebuilt native deps from the ghcr docker cache, they pull fine on hosted docker
- Adds pub, gradle and flutter caching plus a disk cleanup step
- Keeps every input, the runner script, tier1 soft run, recording and artifacts unchanged

* fix: Install flutter from the same source as the ci container image

This change:
- Clones the flutter 3.41.9 tag directly like the container image instead of using the release archive
- The archive ships a stricter dart that rejects the checked in mweb ffi bindings, the tag clone compiles them
- Caches the cloned sdk between runs

* fix: Regenerate the mweb ffi bindings with the workflow dart

This change:
- Regenerates cw_mweb/lib/generated_bindings.g.dart after the deps step, the docker deps builder generates it with an older dart whose ffigen output the current compiler rejects

* fix: Pin ffigen so fresh resolutions generate compliant mweb bindings

This change:
- Pins ffigen to ^20.1.1 in cw_mweb, the unconstrained dependency resolved to 7.1.0 on fresh checkouts
- Old ffigen emits ffi classes without the base or final modifiers the current dart compiler requires

* fix: Restore the pinned cw_mweb pubspec before regenerating bindings

This change:
- Restores cw_mweb/pubspec.yaml after the deps step, the deps image rsync clobbers it with the stale unpinned copy so the ffigen pin never applied
- Wipes the rsynced pubspec.lock and .dart_tool so pub resolves the pinned ffigen fresh
- Asserts the regenerated bindings carry class modifiers so a bad generation fails in seconds
- Skips the libclang install when it is already present, apt spent fourteen minutes on it

* fix: Run the emulator test logic from a file, the action splits script lines

This change:
- Moves the whole emulator script into a file written before the emulator step, the action executes every script line as a separate sh command so multi line logic broke with a syntax error
- Passes the action a single line script invoking that file with bash

* fix: Give the ci emulator a real phone profile

This change:
- Sets the avd to the pixel 5 profile, the default 320x640 skin cannot fit the seed word grid so every wallet creation suite failed its seed display checks
- Caps tier0 attempts at ten minutes, two failing suites at the thirty minute worst case blew the job timeout

* fix: Wait for pages on the ci emulator instead of asserting immediately

This change:
- Makes the legacy page assertion poll for the page, the wallet keys page arrives after the ci emulator finishes unlocking the wallet so both auth gated suites failed on a race
- Raises the tier0 attempt timeout, the first attempt for each suite compiles that target's kernel and was being killed then passing on retry
- Raises the job timeout to fit the per suite compiles

* fix: Recover from driver attach failures instead of burning the timeout

This change:
- Detects attempts where the flutter driver never attached to the app and retries them without spending the real retry, restarting adb first
- Lowers the ci attempt timeout back to ten minutes, every passing attempt finishes within four so a longer cap only makes an attach failure cost more

* fix: Bound the adb recovery and give up when the driver never attaches

This change:
- Bounds every adb call in the recovery path, adb wait-for-device blocks forever when the emulator is gone and silently ate a whole ci job
- Aborts the suite when adb cannot be brought back instead of retrying against a dead device
- Stops the run after a few driver attach failures, an environment that never attaches will not fix itself
- Dumps logcat after every failed attempt so a failure to start the app leaves evidence behind

* fix: Stop the runner failing when every suite passes

This change:
- Assigns the result arrays empty instead of only declaring them, set -u treats a declared but never assigned array as unbound so the summary died on the first run where nothing failed

* fix: Make the ci build cacheable and keep tier results when the runner dies

This change:
- Splits the flutter and pub caches into restore and save steps, actions/cache only saves when the whole job succeeds so they were never written and every run paid for a cold build
- Lets setup-gradle write its cache, it is read only on branches other than the default one
- Caps the gradle heap before the test phase, the six gigabyte daemon plus the emulator left the runner too little to stay alive
- Runs tier0 and tier1 as separate emulator steps so each uploads its logs before the next can take the runner down
- Logs memory and disk around each tier
- Documents how ci runs the suites and the two environment quirks that only bite there

* fix: token decimals defaulting to zero and breaking amount parsing in solana

(cherry picked from commit c220bbb46df9468faf9a8967cb0ef672af7cc664)

* fix: Install the test error handler after the app boots and drain benign errors

This change:
- Installs the test error handler after main() instead of before it, the app replaces FlutterError.onError while booting so the handler installed earlier never ran
- Replaces the app's async error handler during tests, it returns at its first await without recording anything so the framework asserted instead of reporting the real error
- Drains background errors the app tolerates at runtime from the wait loops, anything unrecognised still fails the test where it happened
- Collects the tolerated categories in one place, layout and semantics assertions from debug builds plus the transient network failures exception_handler.dart already ignores

* fix: Import FlutterExceptionHandler from foundation so the test build compiles

This change:
- Imports package:flutter/foundation.dart in the launcher, material.dart only re-exports Brightness and UniqueKey from foundation so FlutterExceptionHandler was not in scope
- Drops the material.dart import, every symbol the launcher uses comes from foundation

* chore: Drop the funds-tests environment from the funds workflow and docs

This change:
- Removes the environment input from the funds workflow, we no longer use a funds-tests GitHub environment so passing it would only auto create an unprotected one on the next dispatch
- Says plainly in the docs that nothing gates the dispatch, the doc still claimed the run waits for environment approval
- Names write_funds_secrets as the one thing keeping funded seeds out of a PR build, that used to be backed by environment scoping too

* chore: Trim the integration test comments down to the ones that carry weight

This change:
- Drops the doc comment sitting on top of every robot primitive, flow and config getter, they restated the method name and nothing else
- Collapses the multi paragraph docstrings on the launcher, the error drain and the funded wallet lookup into the one or two lines that actually explain why the code is shaped that way
- Removes the file and class header paragraphs, the funded wallets stub keeps a short note because an empty map needs one
- Keeps the notes worth having, the chain quirks in the onboarding flow, the route transition tap, the dust thresholds, the void attempt handling in the runner

* chore: Fold the components folder into core and clear out the leftover comments

This change:
- Moves common_test_cases.dart into core, the components folder was down to that one file after common_test_constants.dart went
- Drops six methods from it that nothing calls, dragUntilVisible alone was 95 lines of scroll logic with no caller
- Removes the comments narrating the line below them across the older robots, "Drag to the left" above a moveBy and "Confirmation for buttons 1-9" above the loop
- Deletes the commented out body of takeScreenshots and says instead that it does nothing, all fifteen callers have been no-ops
- Notes in the docs that new robots extend BaseRobot while the older ones still carry a CommonTestCases

* chore: Clear out pending items

* refactor: Move the onboarding robots onto BaseRobot and drop the sleeps

This change:
- Deletes common_test_cases.dart, the sixteen robots that held a CommonTestCases now extend BaseRobot like the newer ones do
- Moves the primitives those robots needed onto BaseRobot with the same behaviour, isSpecificPage, hasType, hasValueKey, hasText, hasTextAtLeastOnce and swipePage
- Renames each robot's page check to isDisplayed so every robot answers the same question the same way
- Removes the twenty six defaultSleepTime calls, every one of them sat in front of an action that already waits for what it needs
- Waits for the view model to move to the next word in seed verification instead of sleeping a second and hoping, and fails with a message when it does not
- Settles after opening a tab on the wallet keys page, the assertions there read the tree straight after the tap
- Drops the fifteen takeScreenshots calls, the method's body has been commented out the whole time so none of them did anything
- Formats the three files dart format was still rewriting

* fix: Wait out the navigation the removed sleeps used to cover

This change:
- Settles after a page mounts in isSpecificPage, the route being replaced stays in the tree while it animates out and assertions on text were matching both screens, seed_confirmation_test failed on finding two "Verify Seed" widgets
- Settles after the last pin digit, the gate sends itself away and returning early landed the caller's next navigation on a locked navigator, wallet_switching_test failed on the !_debugLocked assertion

Both are places where waiting for a widget to exist is not the same as waiting for the app to
be idle, which is what the sleeps were quietly doing.

* fix: Recognise every way a flutter drive attach fails and give tier1 a retry

This change:
- Matches the other wordings flutter drive uses when the driver never attaches, we had only the connect one and missed the isolate initialise, the service disappeared and the driver extension variants
- Gives tier1 the same single retry tier0 has, running it with none meant a driver that never attached was reported as a failing test

Two of the three tier1 failures on the last run were attaches that never happened, neither
of them reached any test code.

* fix: Sync status test watched the wrong status class, history scroll had no guard

This change:
- Accepts SyncronizingSyncStatus in the sync status suite, cw_core spells it without the h and it is a separate class from SyncingSyncStatus, so chains reporting it sat out the full three minute timeout and then failed saying the wallet never synced while printing Synchronizing
- Waits for the home scroll view before handing it to scrollUntilVisible, which calls single on the finder every drag and reported a missing scroll view as a bare Bad state: No element
- Skips the scroll entirely when the history tiles are already on screen

* fix: Test the transaction history the way the screen actually works

The suite looked for history tiles on the home page and scrolled for more when it found
none, which could never pass. The home page renders the history under a tab, and for a
wallet with tokens the assets tab is the one selected first, so the history section was
never built. It also shows a three item preview, itemsShort caps it at
shortHistoryLength, and everything else sits behind the All button in a modal.

This change:
- Opens the history tab before looking for tiles, wallets with no assets tab render the history with no tab bar at all and skip that step
- Asserts the preview never renders more than the three the view model hands it, instead of scrolling for tiles that were never coming
- Opens the All button and checks the full list in the modal, which nothing covered before
- Adds keys for the tab items, the All button, the single tab history bar and the modal root

* fix: Stop the runner wiping a real wallet install and document what CI does that the docs did not

Following app_config.sh and then running the tests locally clears com.cakewallet.cake_wallet
between every suite, which is a developer's own wallets. CI never hits this because the
workflow renames the app afterwards, a step that only existed in the workflow.

This change:
- Refuses to clear a package that is not named for testing, with the rename command in the message
- Adds that rename to the local prerequisites, next to the reason it matters
- Spells out the assets/images vector pass, compile_graphics.sh does not cover that folder and those vec files are neither committed nor ignored, so a fresh checkout fails on the welcome screen
- Notes that a second Gradle daemon from Android Studio deadlocks the build

* test: Make the tier0 and tier1 assertions check what they claim to

An audit of every robot against the screen it drives turned up assertions that pass without
telling you anything, the same shape as the transaction history suite looking for tiles on a
tab it never opened.

This change:
- Reads the receive address off the screen instead of the view model, the view model holding the right address says nothing about what the user is told to send to, and reads both the chunked and the plain render because only handling the first comes back empty
- Verifies a restored wallet knows the address its seed derives, restoring the wrong wallet from a correct seed used to look the same as success, and this found two stale addresses in the secrets
- Replaces the sync bar check, the key it asserted sits on a widget that renders for every status including none, so it was true whenever the home page was up
- Requires the All transaction view to render more than the home preview, it could not tell the two apart before
- Fails the keys page check when a wallet type matches none of its branches instead of passing having verified nothing

* refactor: Remove outdated items from integration tests

* test: Wait for the wallet to actually change instead of pumping a fixed half second

Tapping a wallet row does nothing when that wallet is already open, and the load runs behind
a progress overlay, so a tap that went nowhere looked the same as a successful switch.

This change:
- Waits for the app store to report the wallet before returning, and fails with a message when it never does

* test: Open wallet groups before looking for a wallet by name

Wallets that share a seed are listed as children of their group's tile and are not on screen
while it is closed, so switching to one would time out looking for a name that is only
rendered once the group is opened. Single seed wallets carry their own name as the tile
title, which is why this has not come up yet.

This change:
- Opens the group tiles when the wallet is not already on screen

* chore: Keep the receive address widget diff to the key it needed

A formatter pass rewrote the whole file, quotes, body style and trailing commas, for what was
a one line addition. Restored the original shape so the diff shows only the key.

* chore: Drop trailing whitespace left by the comment cleanup

* test: Cover the send screen refusing what it cannot send

Nothing covered the send screen, which is the one place in the app where getting it wrong
costs the user money. The property worth holding is that the swiper, the point of no return,
is only ever offered for a transaction the wallet actually built.

This change:
- Adds a tier0 suite driving an empty form, an address the chain cannot parse, and a well formed address on a wallet that has never held anything, and requires that none of the three ever produce a swiper
- Waits for the swiper and requires it not to arrive rather than checking once, the screen passes through syncing, building and failed states on the way and any of them can be the one you catch
- Notes in the docs that a merge from dev leaves the generated chain proxies and the assets/images vec files behind, which has broken the local build three times now

* test: Add send and swap dry runs and a flows mode that never spends

The funds suites were all or nothing: the only way to find out whether a funded wallet still
works was to spend from it. Almost everything worth checking happens before the swipe, the
wallet finds its balance, prices the fee and builds a transaction, or the provider returns a
live quote, and none of that costs anything.

This change:
- Adds a send dry run that stops at the swiper, reaching it means the transaction was really built
- Adds a swap dry run that stops before the swap button, creating a trade registers an order with the provider even though no funds move, so it goes no further than the quote
- Adds a dry-run value to FLOWS that runs both and neither of the spending suites, and makes it the default so a mis-click cannot send anything

* test: Cover a wallet name that is already taken being refused

Two wallets answering to the same name is how someone ends up sending from the wrong one, and
nothing checked that the form stops it.

This change:
- Adds a tier0 suite that creates a wallet, starts a second one and gives it the same name, and requires the form to refuse it and stay put
- Splits the walk to the naming form out of createAdditionalWalletFromWalletList so a suite can stop there instead of going through with the wallet

* test: Cover a seed the wallet cannot parse restoring nothing

Restoring from a seed the wallet does not understand either fails outright or, worse, derives
some other wallet the user has no keys for. The restore button is disabled until the words
check out and nothing checked that.

This change:
- Adds a tier0 suite that types twelve words outside the wordlist, presses restore, and requires the form to stay put
- Follows it with the real seed in the same run, so the refusal above cannot pass just because the form restores nothing for any seed at all
- Splits the walk to the restore form out of restoreFirstWalletFromSeed so a suite can stop there

* refactor: Make spending its own switch instead of a value hidden in flows

flows says which flow to run, so folding a dry-run value into it made the dropdown answer two
questions at once and buried the one that matters.

This change:
- Adds a spend input, off by default, and gates the broadcasting suites on it
- Puts flows back to all, send or swap
- Runs the dry runs whenever their flow is picked, they cost nothing either way

* chore: cleanup minor issues

* test: Cover one seed backing wallets on two chains

Wallet groups had no coverage at all, and the part that would break quietly is the seed: a
group member that derived its own seed instead of sharing one looks identical from the wallet
list. It is also the only way a wallet ends up inside a collapsed group tile, which is the
path switchToWallet handles and nothing exercised.

This change:
- Adds a tier0 suite that creates a solana wallet, adds an ethereum wallet to its seed, and requires both to report the same seed
- Switches back to the first afterwards, which only works by opening the group it now sits in
- Adds the flow for it, a child wallet skips the seed and verification screens for a page explaining it shares one, so it cannot reuse the normal creation steps
- Adds the one key the group page was missing, its next button

* test: Cover changing the pin replacing the one that unlocks the wallet

Nothing checked that changing the pin actually takes. Watching the setup screen close proves
nothing, the only evidence is the new pin opening something the old one guarded.

This change:
- Adds a tier0 suite that changes the pin and then unlocks the seed and keys page with the new one
- Goes through the pin gate on the way in, so it also covers the current pin being required before the change is allowed

* test: Cover changing the language, and make settings rows and pickers addressable

Writing this turned up two things in the app rather than the test.

Only ListItemRegularRow was given its keyValue as a widget key. Toggles, checkboxes,
dropdowns and selectors all took the same keyValue and dropped it, so every settings control
that is not a plain navigation row could not be found at all.

Picker named three item types and gave everything else an empty string, so a picker over
plain values, the language list among them, rendered every row with the same key.

This change:
- Passes keyValue through as a key for the other four row types
- Falls back to the item itself for the picker name, so each row is distinct
- Adds a tier0 suite that changes the language and requires the row to show the new one

* test: Cover switching the node the wallet talks to

Which node a wallet is pointed at decides what it sees, and a switch that quietly does not
take leaves someone on a node they believe they left. Nothing covered it.

This change:
- Adds a tier1 suite that reads the current node, switches to another one, confirms, and requires the wallet to be pointed somewhere new
- tier1 rather than tier0 because opening the page speed tests every node against the network

* test: Cover the address book keeping the address it was given

Pasting an address once and trusting it afterwards is the whole point of an address book, so
an entry that comes back changed is a way to lose money quietly. Nothing covered it.

This change:
- Adds a tier0 suite that saves a contact through the form and requires the stored address to match what was typed
- Checks the saved record rather than the rows, the list filters what it shows by the currency in play so a contact can be saved and correctly not on screen
- Adds keys for the add button, the name field, the currency picker, the address field and save

* fix: Key picker rows on a name that does not change with the language

Enumerable items fell through to toString, which is translated for some of them, so the
same row carried a different key depending on the language in use.

* test: Cover the fiat currency setting, transaction details and sending to a contact

This change:
- Adds a suite for turning the fiat api off and on, which is what decides whether the
currency setting is offered at all, then changes the currency through it
- Adds a suite that taps a transaction and checks the details that open belong to it
- Adds a suite that saves a contact and picks it from the send screen
- Adds a suite for restoring a 25 word monero seed, which takes a seed type and a restore
height the polyseed path never asks for
- Keys the address book button on the send screen so a test can reach it
- Lets SUITE_DIR take a single suite file, for iterating on one test
- Lists every suite and what it proves in the integration tests doc

* test: Cover renaming and deleting a wallet

This change:
- Adds a suite for renaming a wallet, including the refusal when the name is already held
by another wallet
- Adds a suite for deleting a wallet, checking it leaves storage and not only the list
- Keys the edit button in the wallet list and the name field, the two buttons and both
dialogs on the wallet edit page, none of which could be reached from a test before
- Fixes the wallets list robot, which looked for a single Wallets title even though the
navbar carries the same word, and looked for wallet names across the whole tree even
though every dashboard tab stays mounted in an IndexedStack

* ci: Report every integration test run to slack

This change:
- Posts a report to slack on every run, naming each tier's counts, duration and any suite
that failed, with the full list of what passed in a reply on the same message
- Adds a SUMMARY_FILE knob to the runner, which writes what it counted in a form the
report can be built from rather than parsing the run log
- Skips with a notice when SLACK_APP_TOKEN or SLACK_TESTS_CHANNEL is missing, and never
fails the gate when slack is unreachable
- Leaves the funds workflow alone, the new slack_notify input defaults to off

* chore: Removing unneeded items

* ci: Say which slack scope was missing when a report is rejected

A rejection carries the scope it wanted in a field of its own, and dropping it left the
warning saying missing_scope without saying what to go and add.

* ci: Report funds runs to the tests channel and say when slack refuses them

This change:
- Sends the funds report to SLACK_TESTS_CHANNEL, so both test workflows land in one place
and the apk channel is left to builds
- Checks the slack response, the post was going out unchecked so a rejected report looked
like a delivered one
- Builds the message from the environment instead of interpolating workflow inputs into
the shell, a quote in a dispatch input was enough to break the payload

* ci: Give the test reports their own slack app

Uploading apks and reporting test results are different jobs with different scopes, and
the name on a message is how anyone in the channel tells which one sent it. Both test
workflows now post through SLACK_TESTS_TOKEN, which only needs chat:write, and the apk
uploads keep SLACK_APP_TOKEN and its file scopes.

* fix: Restore the swap amount key and say when a suite never ran

The AnyPay redesign moved the deposit amount field into SwapAmountBox and it lost the key
the swap suite enters an amount through, so that suite could no longer reach it. Both
amount fields are keyed now, deposit and receive.

This change also:
- Records whether a failed suite failed on its own or because the driver never attached,
which is what happened to send_validation_test in run 31364715120 where the suite never
actually ran
- Rebuilds the slack report out of blocks, so the status is a heading, the tiers sit in
their own fields, failures name their reason and the run is a button rather than a bare
url

* perf: End an attempt early when the driver cannot attach

flutter drive says it is struggling to attach within about a minute and then, when it is
really wedged, sits there until TEST_TIMEOUT kills it. Run 31364715120 lost 20 minutes to
two attempts doing exactly that.

This change:
- Watches the attempt log and ends the attempt VOID_GRACE seconds after the driver first
reports trouble, 120 by default, so the retry starts on a fresh app instead of waiting
out the remaining eight minutes
- Starts that clock at the first complaint rather than at the attempt, since the attempt
spends its first minute building and installing
- Moves the marker list into one variable, the watchdog and the after the fact check were
going to drift apart otherwise

* perf: Drop the driver grace to 60s and take the whole drive down with it

Measured against run 31364715120: the 19 attempts that attached did so in under a second,
while the two that never attached had the warning out at 5 seconds. 60 leaves a wide
margin over a healthy attach on a runner that was already running slow, and saves another
minute on each dead attempt.

Ending the attempt now walks the process tree rather than signalling the wrapper. On linux
the drive runs under timeout, and a KILL to that cannot be forwarded, so the drive would
have been left holding the device just as the retry went looking for it.

* trigger another test run

* Triggering another run, its been green so far

* fix: Wait for the wallet to be ready before tapping send in the funds suites

The send button is disabled until isReadyForSend, which wants a synced wallet, but the
funds flow moves on as soon as a balance appears. Every funded chain was therefore tapping
a disabled button and then waiting ninety seconds for a confirm sheet that could never
open. The robot now waits on the same value the screen gates on, so a wallet that never
syncs says so instead of looking like a missing widget.

* test: Make a funds send failure say what went wrong and stop it spreading

A send that never reaches the confirm sheet was reported as a missing ConfirmSwiper, which
says nothing about the cause. It now reports the state of whichever sheet is up, what the
wallet holds, and the build error when the chain rejected the transaction.

Recovery between chains was a single pop, so the first chain to fail left the app somewhere
the next chain's restore could not start from and every chain after it failed too. It now
unwinds until the home page is back and stops the suite if it cannot get there.

* test: full testing of all the funded tests and fix issues that came up with them

* fix: update sync key to fix sync test

* fix: out of space error

* fix: integration test review issues

* fix: merge conflicts and update test suites

* fix: false test passes and add funded wallet passphrases
chore: remove unused integration test robot methods
feat: save integration test screenshots on Android
feat: pick the swap pair for the funds dispatch

* fix: Keep the runner output on the step log through a file descriptor

* fix: timeout because of runner crash

* test: handle new seed ui flow and fix hang for runner

* fix: emulator teardown not rendering succesfully
feat: use currency picker for selecting swap options for funded run selected swap currency

* test: add key for compact dot key for sync and link to robot

* minor fixes

* test: review fixes for integration tests

93/100 · StrongMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
secret or key materialaccess controldefensive validationseed or entropy pathsigning or wallet pathauthentication path
AI analysis · Low 26/100

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There is one minor production bug fix buried in the history: a Solana token-decimals default was corrected so amounts parse correctly. The commit does not appear to introduce a security vulnerability; if anything it improves quality assurance by adding many regression tests and hardening CI behavior.

AI review queuedfeat: warn when txCount != 1 (#3644)by cyan · 28d540d5 · Sep 23, 2026 · 3 filesMessage 65 · AdequateModerate 57Details
Commit message · cyan

feat: warn when txCount != 1 (#3644)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 57/100

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the user instead of proceeding. This appears to prevent a situation where a payment unexpectedly splits into multiple transactions, which could confuse users or cause funds to move in unintended ways.

Security candidatecharts (#3162)by malik1004x · b88fbf32 · Sep 22, 2026 · 94 filesMessage 49 · ThinInformational 22Details
Commit message · malik1004x

charts (#3162)

* charts (wip)

* charts (wip)

* wip

* add asset grid

* split files

* logic wip

* proper getPrices logic

* viewmodel (wip)

* charts

* remove unused import

* remove restricted import...?

* fix background gradient when scrolling

* add safeguards for broken db

* save new pin on removal

* add safeguards for concurrency

* add haptic feedback

* fix haptic feedback

* fix fiat ticker

* reduce chart padding

* add line touch indicator

* improve touch target size on range selector

* add date/time display when viewing past amount

* merge

* remove iconSvgPath reference

* merge

* fix state for date display

* merge

* auto-reformat

* only load charts when page is opened

* merge

* reformat and apply lints

* refactor to use `Money` instead of storing amount in `String`

* add slop comment

* fix exception on division by zero

* ci

* workaround toDouble being removed

* disable strict parsing and rounding

* fix abs()

* use new currency picker sheet

* safeguard for max flutter-supported decimals

* fix amount precision

* adjust to new buy/sell

* Update lib/new-ui/pages/charts_page.dart

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* adjust buy/sell di

* replace -> ignore

* reformat

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

49/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference! Too few words to establish purpose
Why it was queued
access controlcryptography-sensitive path
AI analysis · Informational 22/100

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the commit that this fixes a security vulnerability; it appears to be a normal feature addition. A few code-quality items (such as unimplemented error handling for some token types and network calls carrying an API key) are visible but do not by themselves prove an exploitable flaw.

Security candidateremove old ui (#3629)by malik1004x · d38c7481 · Sep 22, 2026 · 155 filesMessage 59 · ThinInformational 18Details
Commit message · malik1004x

remove old ui (#3629)

* remove old ui

* remove imports to nonexistent files

* remove old buy/sell

* remove unreachable pages

* readd Routes.exchange

* remove broken di

59/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive pathsigning or wallet pathboot or update pathauthentication path
AI analysis · Informational 18/100

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. There is no direct security fix here; it is ordinary maintenance that reduces code size and removes unused/commented-out functionality such as the Yat emoji-id integration and old buy/sell/exchange pages. Because so much code is removed, there is a small risk that something useful was accidentally deleted or that a route now points to a missing page, but the diff itself does not show an exploitable vulnerability.

AI review queuedignore pointless throw [skip ci]by Omar · c9635932 · Sep 21, 2026 · 1 fileMessage 45 · ThinInformational 17Details
Commit message · Omar

ignore pointless throw [skip ci]

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 17/100

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a minor behavior change, not a clear security fix, and the commit message explicitly calls the throw 'pointless'.

AI review queuedminor fix [skip ci]by Omar · 88498e84 · Sep 20, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Omar

minor fix [skip ci]

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state update to check whether the widget is still on screen before calling setState. There is no visible change in behavior for users and no indication of a security fix.

AI review queuedV6.4.5 rc (#3639)by Omar Hatem · 9fe23970 · Sep 20, 2026 · 74 filesMessage 69 · AdequateLow 33Details
Commit message · Omar Hatem

V6.4.5 rc (#3639)

* v6.4.5 Release candidate

* Apply patches for BLE session, locktime prompt, and monero coincontrol on hww [skip ci]

* include the fix for bluetooth prompt showing on app start

* include the fix for bluetooth prompt showing on app start

69/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Low 33/100

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usability improvements: making sure a mutex is always released, preventing concurrent updates to the Monero coin list, improving Trezor Bluetooth session handling, and temporarily disabling the Exolix exchange provider. Nothing in the diff clearly introduces a security vulnerability, and the vendor does not describe any of the changes as security fixes.

AI review queuedAdd thread-safety and BLE support for Ledger and Trezor devices (#3638)by Konstantin Ullrich · 3d03a62e · Sep 18, 2026 · 9 filesMessage 81 · StrongLow 35Details
Commit message · Konstantin Ullrich

Add thread-safety and BLE support for Ledger and Trezor devices (#3638)

* feat: support BLE device detection for Ledger and Trezor wallets, update trezor-flutter dependency

* feat: add BLE connection state listener for Trezor devices, handle disconnect events, and clean up resources on close

* feat: add mutex locking to MoneroTrezorService for thread-safe operations

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: broader security terminologysecond-pass: security-sensitive path
AI analysis · Low 35/100

This update adds Bluetooth Low Energy (BLE) support for Ledger and Trezor hardware wallets in Cake Wallet and adds a mutex lock around Trezor operations to prevent multiple actions from running at the same time. The changes are mostly feature additions and hardening, not a clear fix for an active security bug. There is no vendor statement saying this commit resolves a security vulnerability.

Security candidateCw 1624 trezor passphrase on trezor device instead of app (#3601)by Konstantin Ullrich · 98f58c28 · Sep 18, 2026 · 50 filesMessage 81 · StrongLow 26Details
Commit message · Konstantin Ullrich

Cw 1624 trezor passphrase on trezor device instead of app (#3601)

* feat: add support for Trezor device settings configuration and `AwaitingSettings` state in pairing flow

* fix ugly widgets

* trezor options ui

* feat: add support for Trezor on device passphrases

* chore: bump trezor_flutter deps

* fix: remove unused subtitle property in proceed_on_device_sheet [skip ci]

* chore: update trezor_flutter dependency to latest commit [skip ci]

* fix: set restore height and store wallet during initialization steps

---------

Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access controlsigning or wallet path
AI analysis · Low 26/100

This commit adds a new option for Trezor hardware wallet users to enter their passphrase directly on the Trezor device instead of typing it into the Cake Wallet app. It also updates the pairing flow to ask users about auto-connect and passphrase settings before finishing setup. The change is a feature improvement for hardware wallet usability and appears intended to reduce exposure of the passphrase to the app. There is no clear security vulnerability in the diff, but the commit is partial: it depends on an updated external Trezor library whose full behavior is not shown, and it removes some old passphrase-handling code while adding new session logic.

AI review queuedRevert "fix: unify encryption across platforms (#3470)" (#3634)by Omar Hatem · dd58455e · Sep 17, 2026 · 10 filesMessage 73 · AdequateModerate 59Details
Commit message · Omar Hatem

Revert "fix: unify encryption across platforms (#3470)" (#3634)

This reverts commit 90e25afc11f8e32a997d62abe5b8bed5428924b1.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 59/100

This commit reverts a previous change that unified wallet file encryption across all platforms. It brings back two separate encryption paths: a newer XChaCha20-based method for direct user passwords, and an older Salsa20-based method for generated keys. The older Salsa20 path is not authenticated, meaning a wrong password can produce believable-looking garbage instead of failing cleanly. The revert also removes safety checks and migration logic that prevented accidental re-encryption of files with wrong passwords, and deletes the related security tests. Because this is a partial revert and the surrounding context is limited, the exact security intent is unclear, but the change reintroduces weaker, less-safe cryptography and removes test coverage for it.

AI review queuedfeat: restrict history api calls when toggle is off in privacy settings (#3615)by David Adegoke · 3a04c7ff · Sep 16, 2026 · 6 filesMessage 93 · StrongLow 41Details
Commit message · David Adegoke

feat: restrict history api calls when toggle is off in privacy settings (#3615)

* feat: restrict history api calls when toggle is off in privacy settings

* refactor: remove unnecessary transaction timer cancellation

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 41/100

This commit adds a privacy toggle that stops EVM and Tron wallets from calling third-party blockchain history APIs (like Etherscan, PolygonScan, TronGrid) when the user turns the feature off in privacy settings. It also fixes preference key names for Base and Arbitrum scan providers so the toggle actually controls the right service. Previously, even with the toggle off, the app may have kept querying these external providers, potentially leaking the user's wallet address and transaction history to them.

AI review queuedfix linuxby Omar · 5ed6759e · Sep 15, 2026 · 3 filesMessage 0 · OpaqueInformational 17Details
Commit message · Omar

fix linux

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 17/100

This commit removes a Linux-specific workaround that manually loaded a bundled SQLite library and switches to a newer Flutter mechanism for copying native assets. It appears to be a build/packaging fix rather than a security patch. There is no indication in the commit that it addresses a security vulnerability.