CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
421commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 6 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateHide broken options in Bitcoin wallets without a private key (#3532)by malik1004x · 9b50011e · Aug 24, 2026 · 9 filesMessage 96 · StrongLow 25Details
Commit message · malik1004x

Hide broken options in Bitcoin wallets without a private key (#3532)

* hide unavailable receive page options

* hide broken options in wallets without a private key

* hide exporting unavailable logs

* hide sign/verify on airgapped wallets

* hide mweb on hwws

* hide mweb ad for hww

96/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
secret or key materialsigning or wallet path
AI analysis · Low 25/100

This commit hides certain wallet features in the Cake Wallet app when they cannot actually work—specifically for hardware wallets, air-gapped wallets, and wallets that do not contain a private key. The changes prevent users from seeing or tapping options like Payjoin, Lightning, silent payments, message signing/verification, MWEB, and some log exports when those features are unsupported. It is a defensive UI fix rather than a patch for an active exploit.

Security candidatefix: solana wallet bugs and security issues (#3484)by David Adegoke · 703cc22b · Aug 24, 2026 · 52 filesMessage 100 · StrongModerate 59Details
Commit message · David Adegoke

fix: solana wallet bugs and security issues (#3484)

* fix android CI

* fix: duplicate outgoing tx for jup swaps and stuck pending state

* fix solana security risk by handling duplicate token symbols in wallet transactions

* feat: implement additional cost handling for pending transactions in Solana wallet.

* fix: Items on security audit list for solana wallet

* refactor: streamline fee payer index handling and improve error logging

* fix: verifySignature for solana and handle wrong mint on default token

* fix: token decimals defaulting to zero and breaking amount parsing in solana

* fix: use token mask in tx history

* refactor: apply lint to modified code

* fix: merge conflicts

* fix: use Money and mint decimals when parsing sol swaps

* test: add unit tests for SPL token amount handling and parsing

* test: add more tests

* fix: update decimal handling for fetched token and remove unused fields

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
signing boundarysigning or wallet path
AI analysis · Moderate 59/100

This commit fixes several Solana wallet bugs and security issues in Cake Wallet. The main security-relevant changes are: (1) preventing users from accidentally sending the wrong token when two tokens share the same symbol, by matching on the unique mint address instead of the symbol; (2) using the correct token decimals from the blockchain rather than defaulting to zero, so amounts are parsed and displayed accurately; (3) adding a warning and proper accounting for the extra SOL cost when a recipient's token account must be created; and (4) improving signature verification and transaction-history parsing. The commit title and message explicitly call these 'security issues' and mention an audit list.

Security candidatefix: generic fixes after anypay (#3543)by David Adegoke · 419d8cde · Aug 22, 2026 · 5 filesMessage 88 · StrongInformational 21Details
Commit message · David Adegoke

fix: generic fixes after anypay (#3543)

* fix android CI

* feat: add anypay core models, parser and routing engine

* feat: add anypay resolver, anypay service and wallet switch service

* refactor: route the send page payment flow through anypay service

* fix: show message when there's no swap providers for a pair and reset the trade guard on dismissal

* refactor: merge the swap from network and send to network decision pages together and clean up anypay widgets

* feat: reapply deep links to a currently open send flow and register the solana scheme

* feat: add support for zcash address detection to anypay and other minor fixes

* refactor: remove trailing icon

* feat: hide swap flow for sp and mweb addresses

* feat: enhance zcash address detection and deeplink handling

* fix: pin bitcoin_base

* refactor: Move the anypay decision navigation out of the send page and address minor review comments

* refactor: Move the anypay decision navigation out of the send page and address minor review comments

* feat: handle exception in switch service and mvoe balance compute to call site

* refactor: combine anypay entry points to one and extract selected mode widget

* fix: tx priority for doge

* chore: add dogecoin to isElectrumWallet util

* fix: annoying mobx error

---------

Co-authored-by: Czarek Nakamoto <cyjan@mrcyjanek.net>

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access controlsigning or wallet path
AI analysis · Informational 21/100

This commit is a follow-up bug-fix patch after a larger 'AnyPay' feature rollout. It corrects a copy-paste error where Zcash and Decred shared the same transaction-priority storage key, adds missing Dogecoin transaction-priority support, fixes a Flutter/MobX state-management warning, and moves an object initialization out of a field declaration into the widget's initState() method. None of these changes appear to be security fixes on their own; they are stability and correctness cleanups.

Security candidateCW1612: AnyPay Service Layer (#3516)by David Adegoke · 3b100eae · Aug 20, 2026 · 67 filesMessage 76 · AdequateLow 38Details
Commit message · David Adegoke

CW1612: AnyPay Service Layer (#3516)

* fix android CI

* feat: add anypay core models, parser and routing engine

* feat: add anypay resolver, anypay service and wallet switch service

* refactor: route the send page payment flow through anypay service

* fix: show message when there's no swap providers for a pair and reset the trade guard on dismissal

* refactor: merge the swap from network and send to network decision pages together and clean up anypay widgets

* feat: reapply deep links to a currently open send flow and register the solana scheme

* feat: add support for zcash address detection to anypay and other minor fixes

* refactor: remove trailing icon

* feat: hide swap flow for sp and mweb addresses

* feat: enhance zcash address detection and deeplink handling

* fix: pin bitcoin_base

* refactor: Move the anypay decision navigation out of the send page and address minor review comments

* refactor: Move the anypay decision navigation out of the send page and address minor review comments

* feat: handle exception in switch service and mvoe balance compute to call site

* refactor: combine anypay entry points to one and extract selected mode widget

---------

Co-authored-by: Czarek Nakamoto <cyjan@mrcyjanek.net>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access controlcryptography-sensitive pathsigning or wallet pathparser or protocol path
AI analysis · Low 38/100

This is a large feature commit that introduces a new 'AnyPay' service layer for routing cryptocurrency payments and swaps inside Cake Wallet. It refactors how the app parses payment requests, detects recipient networks, switches wallets, and handles deep links. The changes are mostly architectural and user-facing, but because they touch sensitive flows such as wallet switching, address parsing, and cross-chain swaps, they could introduce security bugs if the new routing logic makes incorrect decisions. The commit does not appear to be a disclosed security fix, and no CVE or vendor security statement is present.

Security candidatePrivacy: randomized coin selection (BnB changeless + single random draw) (#3408)by Cindy · 3b098e35 · Aug 19, 2026 · 5 filesMessage 100 · StrongLow 38Details
Commit message · Cindy

Privacy: randomized coin selection (BnB changeless + single random draw) (#3408)

* Randomize coin selection with single random draw

The greedy selection walked the unspent pool in a predictable order (address generation order, then per-address server order), a fingerprint an analyst can exploit. Shuffle the pool before the accumulate-until-covered loop so the input set is chosen non-deterministically (single random draw). MWEB coins are still kept last.

Branch-and-bound (changeless exact match) is a larger follow-up.

* Add BnB + SRD coin selection primitives

Pure, wallet-independent coin selector: branch-and-bound for an exact
changeless match within the cost-of-change window, single-random-draw
fallback (shuffled, injectable RNG) when no exact match exists, and
selectCoins tying them together over effective values.

This is the basis for replacing the greedy accumulation in _createUTXOS
so sends produce no change when possible and a non-deterministic
selection otherwise. Validated with dart test (9 cases); wiring into
_createUTXOS is a separate step.

* Use BnB changeless matching in coin selection

Before the shuffled greedy walk, run branch-and-bound over effective
values (value minus per-input fee cost) looking for an input set whose
excess over amount plus fee stays below dust. When found, order those
inputs first and cap the walk at their count: the caller then computes
a change below dust, drops the change output, and absorbs the residue
into the fee, producing a changeless transaction with no residual
change fingerprint.

When no match exists, selection falls back to the shuffled pool, which
the greedy walk turns into a single random draw. BnB is skipped for
sendAll, forced input counts and pools holding MWEB coins.

changelessMatch filters non-positive effective values and maps indices
back to the original pool.

* Cover changeless fee bounds and BnB termination

Assert the end-to-end arithmetic the wallet performs around a
branch-and-bound match: with the 68/34/10 vBytes model, the leftover
the caller absorbs into the fee is never negative (no re-selection
loop) and never exceeds the dust limit (bounded fee overpay).

Also pin termination: a large pool with no possible match returns null
through the maxTries cap instead of exploring the full search tree.

* Use a secure RNG for coin selection randomness

The selection shuffle and the single-random-draw fallback exist to be
unpredictable, so seed them from Random.secure() instead of the default
PRNG, matching what Core and bdk use for coin selection. Pool sizes are
small, so the cost is negligible. Tests keep injecting a seeded Random
for determinism.

* Randomize RBF and payjoin input candidate order

Two secondary paths still consumed unspentCoins in wallet scan order
(address generation order, then per-address age), the same predictable
order removed from the main selection path:

- replaceByFee walked the unused-UTXO list in scan order when the fee
bump needed extra inputs
- the payjoin receiver handed input candidates to the payjoin library
in scan order, letting ties inside its selection mirror that order

Shuffle both with a secure RNG so no input-selection path exposes the
wallet's address or coin age ordering.

* ci: skip Linux PR build on forks (no secrets access)

* Account for script-type sizes in changeless matching

* Keep coin selection order stable within a transaction build

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
explicit security languageentropy or randomnesssigning boundaryaccess controldefensive validationsigning or wallet path
AI analysis · Low 38/100

This commit improves Bitcoin/Litecoin privacy in Cake Wallet by making coin selection less predictable. Previously, the wallet chose coins in a fixed order (based on address creation and age), which outside observers could use to fingerprint the wallet or trace its funds. The patch shuffles candidate coins using a secure random source, tries to build changeless transactions when possible, and also randomizes coin order in RBF fee-bump and PayJoin flows. It also adds a CI guard to skip Linux builds on fork pull requests because secrets are unavailable there.

Security candidateSet anti-fee-sniping locktime (exact-tip) on bitcoin sends (#3385)by Cindy · ca00370c · Aug 19, 2026 · 5 filesMessage 81 · StrongLow 30Details
Commit message · Cindy

Set anti-fee-sniping locktime (exact-tip) on bitcoin sends (#3385)

* Set anti-fee-sniping locktime on bitcoin sends

Current tip (exact-tip) via shared helper, wired into normal sends (path A) and payjoin/PSBT (path B). 0 when unsynced. Converges with the exact-tip cluster (payjoin-cli, ldk-node, Bull Bitcoin) and skips the ~10% backdate.

* Update cw_bitcoin/lib/locktime.dart

Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>

* Update cw_bitcoin/lib/locktime.dart

Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>

* Update cw_bitcoin/lib/locktime.dart [skip ci]

---------

Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 30/100

This commit changes how Cake Wallet sets the 'locktime' field on outgoing Bitcoin transactions. Previously, Cake Wallet apparently left this value at zero, which made its transactions stand out and easier to track. Now it sets the locktime to the current blockchain height when the wallet is synced, matching common behavior used by other Bitcoin wallets. This is a privacy improvement, not a fix for a vulnerability that lets someone steal funds directly.

Security candidatefeat: pin all dependencies to git sources (#3381)by cyan · be694edc · Aug 18, 2026 · 64 filesMessage 65 · AdequateLow 27Details
Commit message · cyan

feat: pin all dependencies to git sources (#3381)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
access controlsigning or wallet path
AI analysis · Low 27/100

This commit changes how the Cake Wallet app manages its software building blocks (Dart/Flutter dependencies). It removes many per-package lock files, pins more dependencies to specific Git commit hashes instead of branch names, adds shared override files, and updates CI build scripts. The main security angle is supply-chain hardening: pinning to exact Git commits makes it harder for an attacker to silently swap in a malicious version of a library. However, the commit is a broad refactor, and the diff does not show a specific vulnerability being fixed or any malicious code being introduced. It is best treated as a defensive hygiene improvement.

Security candidatev6.4.1 Release Candidate (#3506)by Omar Hatem · 8f38ba6b · Aug 12, 2026 · 39 filesMessage 81 · StrongInformational 15Details
Commit message · Omar Hatem

v6.4.1 Release Candidate (#3506)

* v6.4.1 Release Candidate

* fix changelog overflow (#3510)

* update ios min version

---------

Co-authored-by: malik1004x <malikowskirobert@gmail.com>

81/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
memory safety
AI analysis · Informational 15/100

This commit is a routine version bump to 6.4.1 plus a small user-interface fix for a changelog text overflow and an iOS minimum version update. It also refreshes translated release notes and updates a dependency reference for the Trezor hardware wallet integration. There is no indication of a security fix or vulnerability being addressed.

Security candidatefeat: show Bitcoin master fingerprint in wallet keys (#3489)by Seth For Privacy · b60b5a59 · Aug 7, 2026 · 4 filesMessage 98 · StrongInformational 15Details
Commit message · Seth For Privacy

feat: show Bitcoin master fingerprint in wallet keys (#3489)

* feat: show Bitcoin master fingerprint in wallet keys

Add the BIP-32 master fingerprint (XFP) to the Bitcoin wallet keys shown
under Settings > Seed & Keys > Keys, labeled "Master fingerprint".

* fix: keep xPub in Keys tab by splitting silent payment keys into a dedicated list

The Keys tab / Silent Payments tab split relied on a hardcoded item index
(`items.sublist(0, 4)` / `sublist(4)`) that assumed the first four items
were always WIF/private key/public key/xPub. Adding the master fingerprint
as the first item pushed xPub into the Silent Payments tab.

Route Bitcoin silent payment keys into their own `silentPaymentItems` list
instead, and render each tab from its list.

98/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
secret or key materialsigning or wallet path
AI analysis · Informational 15/100

This commit is a user-facing feature, not a security fix. It adds a new 'Master fingerprint' value to the Bitcoin wallet keys screen and fixes a small UI bug where adding that new item accidentally moved another key (xPub) into the wrong tab. There is no indication of a vulnerability being patched.

Security candidateCW-1581-trezor-fixes-enhancements (#3462)by Konstantin Ullrich · feeec2e4 · Aug 6, 2026 · 46 filesMessage 76 · AdequateLow 27Details
Commit message · Konstantin Ullrich

CW-1581-trezor-fixes-enhancements (#3462)

* feat: add Trezor auto connect

* chore: update `trezor_flutter`

* fix: correct method name for retrieving Trezor auto-pairing credentials

* fix: update device connection prompt text across all languages [skip ci]

* feat: add Trezor key image synchronization ui and improve hardware wallet UX

* feat: add sync-balance icon asset for settings row visuals [skip ci]

* feat: add sync-balance icon asset for settings row visuals [skip ci]

* fix: remove unused Monero and sync key images settings actions from menus [skip ci]

* fix: re-enable routing for UR QR Animated Page [skip ci]

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
credential or privilege stateprivacy or spend-authorization protocolsigning or wallet path
AI analysis · Low 27/100

This commit improves how Cake Wallet connects to Trezor hardware wallets and synchronizes Monero 'key images' (data that proves coins haven't already been spent). It adds automatic reconnection, a new user interface for syncing key images, and stores an encrypted Trezor pairing state on the device. The changes are mostly user-experience and reliability fixes rather than a clear security patch, though they touch on sensitive areas such as encrypted storage, hardware wallet pairing, and transaction signing flow.

Security candidatefix:quick actions cold start (#3476)by Serhii · 061f36a6 · Aug 5, 2026 · 4 filesMessage 68 · AdequateInformational 17Details
Commit message · Serhii

fix:quick actions cold start (#3476)

* fix:quick actions cold start

* route receive links to new receive page

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
authentication path
AI analysis · Informational 17/100

This commit fixes a bug where app shortcuts (quick actions) didn't work correctly when the wallet app was started from a cold state. It also updates the 'receive' shortcut to open the newer receive page instead of the older address page. There is no clear security issue here; it is a routine UI/UX bug fix.

Security candidateWrap long passphrase value on the wallet seed/keys screen (#3480)by claude[bot] · 0e42f162 · Aug 5, 2026 · 1 fileMessage 58 · ThinInformational 15Details
Commit message · claude[bot]

Wrap long passphrase value on the wallet seed/keys screen (#3480)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
access controlsigning or wallet path
AI analysis · Informational 15/100

This commit is a minor user-interface fix that makes very long wallet passphrases wrap to multiple lines instead of overflowing the screen. It does not change security behavior, cryptography, or how secrets are stored or protected.

Security candidatesecurity: require app-level vulnerability proofsby sethforprivacy · 42019d86 · Aug 3, 2026 · 1 fileMessage 62 · AdequateInformational 15Details
Commit message · sethforprivacy

security: require app-level vulnerability proofs

62/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Names security-relevant behavior explicitly! No meaningful explanatory body
Why it was queued
explicit security languagedocumentation-only discount
AI analysis · Informational 15/100

This commit only updates the project's security policy document (SECURITY.md). It tightens the rules for vulnerability reports by requiring proof-of-concept code that actually runs against the Cake Wallet app, and it asks contributors not to use AI-generated comments. There are no code changes, no bug fixes, and no direct security impact on the app itself.

Security candidatea11y: expose ModernButton, CoinActionButton and ModalTopBar as single labeled button nodes (#3463)by Seth For Privacy · 26a16a4e · Aug 2, 2026 · 75 filesMessage 91 · StrongInformational 21Details
Commit message · Seth For Privacy

a11y: expose ModernButton, CoinActionButton and ModalTopBar as single labeled button nodes (#3463)

* Give ModernButton and CoinActionButton one labeled a11y node

ModernButton, CoinActionButton and the ModalTopBar chrome buttons were
icon-only IconButtons with no tooltip and a detached caption sibling, so
screen readers announced an unnamed "button" plus unrelated static text.

- Add optional semanticLabel to ModernButton; wrap the control in
MergeSemantics + Semantics(button: true, label: semanticLabel ?? label)
and exclude both the icon and the visible caption so exactly one node
is exposed. No visual or pointer change.
- Give CoinActionButton the same treatment, reusing the label callers
already pass (dashboard Send / Receive / Swap / Scan).
- Add leadingSemanticLabel / trailingSemanticLabel to ModalTopBar,
defaulting the leading button to "Close", and mark a non-empty title
as a semantics header.
- Migrate every ModernButton / ModalTopBar call site to pass a localized
label, and drop the now-redundant external Semantics wrapper in
base_page.dart so the back button is not labeled twice.
- Localize the hard-coded "Settings" modal title in settings_page.dart.

New English keys: rotate_address, swap_reverse_direction, switch_camera,
switch_input_currency, test_node_speeds, turn_flash_off, turn_flash_on.

* Require explicit accessible names on ModalTopBar and ModernButton icons

ModalTopBar defaulted every leading icon's accessible name to "Close", so
the ~40 callers that pass a back arrow announced the wrong action, and
trailingSemanticLabel was optional, leaving the trailing icon controls
unnamed.

- Drop the "?? close" fallback in ModalTopBar: the leading ModernButton
now gets exactly leadingSemanticLabel, and constructor asserts require a
non-empty label whenever leadingIcon / trailingIcon is supplied. Callers
that pass leadingWidget / trailingWidget instead are unaffected, and a
null icon still builds no button at all.
- Assert in both ModernButton constructors that the control has a name:
either semanticLabel or a non-empty visible label.
- Pass the matching localized label at every ModalTopBar call site: "Go
back" for back arrows, "Close" for close icons, and the action name for
trailing icons (History, Configure, Export CSV, Save, Scan, Close).
- Label the last unnamed ModernButton (wallet accounts, wallet_info.dart).

No new localization keys; all labels reuse existing strings_en.arb keys.

* fix(a11y): put ModalTopBar header flag on the title Text node

On-device audit (CW-1574, defect D2) found zero [heading] nodes in the
Android accessibility tree on the Receive page: Semantics(header:) wrapped
the AnimatedSwitcher rather than the Text inside it, so the flag never
landed on the node that carries the title label.

Move the header semantics inside the AnimatedSwitcher, directly around the
Text. The ValueKey(title) moves with it onto the Semantics wrapper, since
AnimatedSwitcher switches on its direct child's key -- keying the Semantics
by title preserves the existing switch/animation behavior exactly.

No test or robot resolves the title ValueKey through a Text-typed finder,
so the key relocation is not observable from the test suites on this branch.

* Set headingLevel so Android surfaces modal titles as headings

The Flutter 3.41 engine drives AccessibilityNodeInfo.setHeading from
headingLevel, not the IS_HEADER flag (which 3.35 used). Proven by an
on-device probe: header:-only headings print on a 3.35-engine build and
vanish on the 3.41-engine CI build.

91/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathauthentication path
AI analysis · Informational 21/100

This commit is an accessibility (a11y) improvement, not a security fix. It makes icon-only buttons and modal titles readable by screen readers by attaching proper labels to them. There is no vulnerability being patched and no way for an attacker to exploit these changes.

Security candidateEnforce passphrase confirmation match on the restore and create wallet flows (#3474)by claude[bot] · f6566e3b · Aug 2, 2026 · 2 filesMessage 81 · StrongModerate 52Details
Commit message · claude[bot]

Enforce passphrase confirmation match on the restore and create wallet flows (#3474)

* fix: enforce passphrase confirmation in restore passphrase bottom sheet

The confirm-passphrase field in AddPassphraseBottomSheet already had a
validator comparing it to the first field, but the fields were not inside
a Form and nothing ever called validate(), so the validator never ran.
Tapping "Restore" restored the wallet with the first field's value even
when the confirmation did not match, defeating the typo check.

Wrap both fields in a Form and validate it before completing the restore,
matching the existing pattern in advanced_privacy_settings_page.dart.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019DtLNfYw1H81p7zZrkNDXM

* Validate passphrase confirmation when the passphrase field is empty

---------

Co-authored-by: Claude <noreply@anthropic.com>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access controldefensive validationsigning or wallet pathauthentication path
AI analysis · Moderate 52/100

This commit fixes a bug in the wallet restore and creation screens where the 'confirm passphrase' field was not actually being checked. A user could type one passphrase and a different confirmation, yet still proceed. The wallet would then be created or restored using only the first passphrase, which could lock users out of their funds if they made a typo. The fix wraps the fields in a proper form and validates the confirmation before continuing.

Security candidatezec ironwood (#3425)by cyan · 92c2c5e0 · Jul 27, 2026 · 38 filesMessage 59 · ThinLow 35Details
Commit message · cyan

zec ironwood (#3425)

* initial

* wip

* ironwood detection, migration

* dev: zec address validation on rt

* fix: ironwood spend

* ironwood regressions

* fix: tx history

* bump: zkool2

* fix: tx amounts on pending
fix: ironwood pending balance
fix: orchard->ironwood migration
fix: orchard->any pre ironwood txs
fix: ironwood -> any txs
fix: WrongSpendAuthorizingKey
fix: tx history
fix: autoshield to ironwood
fix: zkool to latest version
break: my sleep schedule :sweating: :worksonmymachine:

* thx fable

* downgrade frb to 2.11.1

* fix: tx amounts in history

* Migating... / migration label for O->I txs

59/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
update trustsigning or wallet path
AI analysis · Low 35/100

This commit adds support for Zcash's Ironwood network upgrade to Cake Wallet. It changes how wallet balances, transactions, and addresses are handled when Ironwood activates, and it lets advanced users pick mainnet, testnet, or regtest for Zcash. The changes are mostly functional upgrades and bug fixes rather than a clear security patch, but they touch sensitive areas like balance calculation, transaction construction, and address validation. Because the commit is large and partially hardcodes dev-network settings (for example, a regtest node at 10.0.2.2), there is some risk of misconfiguration or incorrect balance reporting, though no direct exploit is visible in the diff.

Security candidateShuffle change output on hardware wallet and Bitcoin Cash sends (#3432)by Cindy · b73c46ac · Jul 26, 2026 · 5 filesMessage 81 · StrongLow 49Details
Commit message · Cindy

Shuffle change output on hardware wallet and Bitcoin Cash sends (#3432)

* Shuffle change output on hardware wallet sends

Hardware wallet BTC/LTC sends passed outputs to the PSBT/device in the
given order (change last), a position fingerprint. The outputOrdering
param was plumbed but ignored. Add orderOutputs() and apply it in both
buildHardwareWalletTransaction paths; set the send call site to shuffle.

Refs #3376 (the software send + RBF paths were covered by #3420).

* Shuffle change output on Bitcoin Cash sends

The BCH send path built via ForkedTransactionBuilder with
outputOrdering: none, leaving change deterministically last. The builder
shuffles natively and change is found by isChange, not position, so flip
it to shuffle (matches the BTC software path from #3420).

Refs #3376.

* Update cw_bitcoin/lib/electrum_wallet.dart

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 49/100

This commit fixes a privacy weakness in Cake Wallet's Bitcoin, Litecoin, and Bitcoin Cash sending flows. Previously, when using a hardware wallet or sending Bitcoin Cash, the app's own 'change' output was always placed last in the transaction. That predictable ordering acts like a fingerprint, making it easier for outside observers to identify which output belongs to the sender and trace the user's funds. The patch shuffles output order so the change output no longer sits in a fixed, telltale position.

Security candidatev6.3.0 Release Candidate (#3414)by Omar Hatem · 544cbec0 · Jul 21, 2026 · 15 filesMessage 76 · AdequateLow 45Details
Commit message · Omar Hatem

v6.3.0 Release Candidate (#3414)

* v6.3.0 Release Candidate
- the new transaction history
- Radar in Apps screen
- Zcash update
- Flutter update
- Parts of the Refactor
should improve how amounts are handled in the app and fix any issue with amounts
improve handling sending to aliases

- Improvements for Cake Pay mobile
- Bug fixes

* don't use memo for note/message values

* save message in QR locally in the notes field

* Make stealth addresses generated from silent payment, not reliant on output index (#3420)

* - fix swaps showing only on primary account
- switch tron default node
- privacy fixes

* - enlarge destination tag and make it copiable
- migrate users on hashvault
- minor fix

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
privacy or spend-authorization protocolsigning or wallet pathauthentication path
AI analysis · Low 45/100

This is a routine version-bump release candidate for Cake Wallet/Monero.com v6.3.0. The visible code changes include several privacy-related tweaks: Bitcoin transaction output ordering is now shuffled instead of fixed, a Tor/onion exchange provider now uses HTTPS instead of HTTP, default Tron and Monero nodes are switched/migrated away from TronGrid and HashVault, and a hardware-wallet passphrase field disables autocorrect. There are also UI fixes for destination tags and QR-code payment notes. The commit message itself mentions 'privacy fixes' but does not describe a specific vulnerability or disclose a security incident.

Security candidatesecurity: harden vulnerability disclosure policy (#3419)by Seth For Privacy · 41e2cba3 · Jul 20, 2026 · 1 fileMessage 98 · StrongInformational 15Details
Commit message · Seth For Privacy

security: harden vulnerability disclosure policy (#3419)

* security: harden vulnerability disclosure policy + Slack routing

* security: add discretionary reward policy and marketing-site out-of-scope

98/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
explicit security languagedefensive validationdocumentation-only discount
AI analysis · Informational 15/100

This commit only updates the project's written security policy (docs/SECURITY.md). It does not change any application code, fix a bug, or patch a vulnerability. It clarifies how researchers should report security issues, adds safe-harbor language, defines scope, and introduces a discretionary reward policy. There is no direct security risk or security improvement to the software itself.

Security candidatetrezor-monero-passphrase-modal (#3337)by Konstantin Ullrich · 9d685d46 · Jul 17, 2026 · 17 filesMessage 76 · AdequateLow 25Details
Commit message · Konstantin Ullrich

trezor-monero-passphrase-modal (#3337)

* trezor monero passphrase modal

* feat: add Trezor passphrase support for wallet restoration process

* revert: send page changes

* chore: format code

* chore: format code

* chore: reorganize imports and improve code formatting in send_page.dart [skip ci]

* auto-reformat

* fix: trezor usb device refresh race condition

* fix: ui bugs in relation to trezor

* fix: only show passphrase option for trezor devices

---------

Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access controlsigning or wallet pathauthentication path
AI analysis · Low 25/100

This commit adds support for using a passphrase with Trezor hardware wallets when restoring a Monero wallet in Cake Wallet. It also fixes a small race condition when refreshing the list of connected USB devices. There is no clear security vulnerability in the diff itself; it is a feature addition with some minor hardening.

Security candidatefeat: zkool2 (#3165)by cyan · 28c2cc15 · Jul 17, 2026 · 33 filesMessage 71 · AdequateLow 44Details
Commit message · cyan

feat: zkool2 (#3165)

* feat: zkool2

* feat: rescan on zkool
fix: sending to extracted addresses
fix: labeling shielding txs
fix: autoshield endless loop
fix: autoshield t addr not firing
fix: autoshield destinations
chore: remove old routes for rescan with zkool
other minor fixes/cleanups

* fix: zcash hardfork

* fix: update sync progress more reliably

* fix: pending transaction loading
fix: autoshield txs
fix: taddress
fix: fee estimation
fix: tx send errors

* chore: bump zkool2 to latest version
fix: reduce amount of taddrs generated
fix: derivation path for internal wallets
fix: display address in correct hidden/usable spots
fix: get wallet db height before it syncs for the first time
fix: taddr rotation with passphrase
fix: sync progress ui refresh
fix: taddress generation not getting capped
fix: hidden addresses not being hidden
fix: pending transactions not being shown
fix: t address cache misses
fix: t address rotation not getting refreshed
fix: t address high index not being used

* fix: refresh t addresses

* fix: patch rust side to make t addr rotation work

* fix: ui issue in recipient address
fix: zcash multiaddress send to show in the ui
fix: potential race condition

* minor fixes

* format

* fix: flashing on receive screen

* remove unused 'autoShield'

* review

71/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access controlcryptography-sensitive pathsigning or wallet path
AI analysis · Low 44/100

This is a large feature commit that replaces Cake Wallet's older Zcash wallet backend (warp_api) with a new library called zkool2. It touches address generation, transaction creation, balance scanning, transparent-address rotation, auto-shielding, and migration of old wallets. The commit message lists many bug fixes, but the code change is broad and partially complete (for example, the rescan method is mostly commented out). There is no direct evidence in the commit of a deliberate security vulnerability, but the size and incomplete state create a higher-than-normal risk of bugs that could lose funds, leak privacy, or produce incorrect balances.

Security candidateCW-1291-ledger-fixes (#3390)by Konstantin Ullrich · ed540bae · Jul 16, 2026 · 12 filesMessage 76 · AdequateInformational 23Details
Commit message · Konstantin Ullrich

CW-1291-ledger-fixes (#3390)

* feat: add connecting indicator in hardware wallet connect screen

* chore: bump ledger related dependencies

* chore: bump ledger related dependencies

* feat: add additional guard against gLedger being null

* auto-reformat

* feat: improve ledger connection and state management

* fix: connect_device_page padding on iOS

* chore: update universal_ble dependency reference

---------

Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathauthentication path
AI analysis · Informational 23/100

This commit fixes bugs in how Cake Wallet connects to Ledger hardware wallets. It adds guards so the app doesn't crash or behave oddly when no Ledger connection exists, prevents duplicate connection attempts, improves cleanup when switching wallets, and updates the underlying Ledger Bluetooth/USB library versions. There is no obvious new security vulnerability here; the changes look like stability and reliability improvements for hardware wallet users.

Security candidatecontinue formattingby Omar · b1922fc6 · Jul 15, 2026 · 29 filesMessage 18 · OpaqueInformational 15Details
Commit message · Omar

continue formatting

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet pathboot or update path
AI analysis · Informational 15/100

This commit is purely a code-formatting cleanup. It adjusts line breaks, indentation, and whitespace across many Dart files but does not change any program logic, add new features, or alter security behavior.

Security candidateReformat the whole codebase with 100 line width (#3403)by Omar Hatem · 16ddc083 · Jul 14, 2026 · 801 filesMessage 58 · ThinInformational 15Details
Commit message · Omar Hatem

Reformat the whole codebase with 100 line width (#3403)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathseed or entropy pathsigning or wallet pathboot or update pathauthentication pathparser or protocol path
AI analysis · Informational 15/100

This commit is a purely cosmetic reformatting of the entire codebase to use a 100-character line width. It adjusts whitespace, line breaks, and indentation across hundreds of files but does not change any program logic, security behavior, or functionality. The only non-formatting change is that the GitHub Actions lint workflow was disabled by commenting it out, which is a CI/process change rather than a product security issue.

Security candidateauto-reformatby Robert Malikowski · 4427a05f · Jul 14, 2026 · 779 filesMessage 18 · OpaqueInformational 15Details
Commit message · Robert Malikowski

auto-reformat

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
cryptography-sensitive pathseed or entropy pathsigning or wallet pathboot or update pathauthentication pathparser or protocol path
AI analysis · Informational 15/100

This is a large automated code reformatting commit. It only changes whitespace, line breaks, indentation, and trailing newlines across hundreds of files. There is no change to program logic, no bug fixes, and no security-related behavior change.