CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
421commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 16 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateMove to precompiled SVGs (#3072)by malik1004x · 89e07fbb · Mar 12, 2026 · 467 filesMessage 76 · AdequateInformational 15Details
Commit message · malik1004x

Move to precompiled SVGs (#3072)

* add compile script

* merge

* move to CakeImageWidget

* add precompiled .vec

* fix double declaration

* move .svg

* add to ci

* add svgs

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive pathseed or entropy pathsigning or wallet path
AI analysis · Informational 15/100

This commit is a routine user-interface refactor: it replaces runtime SVG image files with precompiled binary vector files (.vec) and updates the app's image widget to load them. There is no change to wallet logic, cryptography, networking, permissions, or user data handling. It is not a security patch and does not introduce obvious security risk based on the materials provided.

Security candidateNew design (#2797)by Omar Hatem · 084fd6bb · Mar 11, 2026 · 775 filesMessage 86 · StrongLow 32Details
Commit message · Omar Hatem

New design (#2797)

* refactor node form UI to use new ListItem model

* add new list item row types and widgets

* add style wrapper

* remove print [skip ci]

* Integrate new design mockup with ViewModel (#2653)

* feat: add Lightning Network support for Bitcoin wallets

* refactor: rename `fiatConvertationStore` to `fiatConversionStore` for consistency and update related occurrences across codebase

* feat: enhance address validation with Lightning Network invoice support for BTC & refactor wallet type/token checks in view model

* feat: add support for Lightning invoice detection, refactor MWEB deposit/withdraw actions, and integrate Lightning transaction creation with updated priority handling

* feat: add method to retrieve unused Spark deposit address for Bitcoin wallets

* feat: add Breez API key support and update secrets handling for Bitcoin Lightning wallet integration in workflows

* chore: update Breez SDK dependency to version 0.3.4 in pubspec files

* Add bitcoin secrets config [skip ci]

* feat: extend Lightning wallet functionality with transaction history fetching

* feat: add LNURL-pay address detection and support in address parsing flow for Bitcoin Lightning integration

* refactor: simplify `ReceivePageOption` logic

* refactor: centralize `PaymentURI` generation logic across wallet types

* feat: enhance `PaymentURI` handling with asynchronous support and Lightning-specific functionality

* refactor: streamline `PaymentURI` logic and remove redundant URI implementations across wallet types

* refactor: remove redundant debug print statement from `bitcoin_wallet_addresses.dart`

* refactor: improve consistency in widget styling and centralized label logic, add Bitcoin Lightning deposit/withdraw support

* feat: reload balance and tx history after sending a lightning transaction

* feat: improve address formatting for human-readable addresses and update the default LNURL domain

* fix: merge conflicts

* feat: add error handling for LightningWallet initialization and adjust transaction direction logic

* integrate homepage from new ui mockup

* fix import

* feat: add Lightning Network support for Bitcoin wallets

* refactor: rename `fiatConvertationStore` to `fiatConversionStore` for consistency and update related occurrences across codebase

* feat: enhance address validation with Lightning Network invoice support for BTC & refactor wallet type/token checks in view model

* feat: add support for Lightning invoice detection, refactor MWEB deposit/withdraw actions, and integrate Lightning transaction creation with updated priority handling

* feat: add method to retrieve unused Spark deposit address for Bitcoin wallets

* feat: add Breez API key support and update secrets handling for Bitcoin Lightning wallet integration in workflows

* chore: update Breez SDK dependency to version 0.3.4 in pubspec files

* Add bitcoin secrets config [skip ci]

* feat: extend Lightning wallet functionality with transaction history fetching

* feat: add LNURL-pay address detection and support in address parsing flow for Bitcoin Lightning integration

* refactor: simplify `ReceivePageOption` logic

* refactor: centralize `PaymentURI` generation logic across wallet types

* feat: enhance `PaymentURI` handling with asynchronous support and Lightning-specific functionality

* refactor: streamline `PaymentURI` logic and remove redundant URI implementations across wallet types

* refactor: remove redundant debug print statement from `bitcoin_wallet_addresses.dart`

* refactor: improve consistency in widget styling and centralized label logic, add Bitcoin Lightning deposit/withdraw support

* feat: reload balance and tx history after sending a lightning transaction

* feat: improve address formatting for human-readable addresses and update the default LNURL domain

* fix: merge conflicts

* feat: add error handling for LightningWallet initialization and adjust transaction direction logic

* integrate homepage from new ui mockup

* fix import

* add new-ui dir to pubspec_base

* minor layout fixes

* cleanup navbar logic

* Modify navbar behaviour

* smooth color change when selecting navbar options

* open old ui pages with new ui action buttons

* feat: working navbar in new ui

* fix: minor sizing tweaks

* CW-1266-integrate-bitcoin-lightning-through-spark-sdk (#2623)

* feat: add Lightning Network support for Bitcoin wallets

* refactor: rename `fiatConvertationStore` to `fiatConversionStore` for consistency and update related occurrences across codebase

* feat: enhance address validation with Lightning Network invoice support for BTC & refactor wallet type/token checks in view model

* feat: add support for Lightning invoice detection, refactor MWEB deposit/withdraw actions, and integrate Lightning transaction creation with updated priority handling

* feat: add method to retrieve unused Spark deposit address for Bitcoin wallets

* feat: add Breez API key support and update secrets handling for Bitcoin Lightning wallet integration in workflows

* chore: update Breez SDK dependency to version 0.3.4 in pubspec files

* Add bitcoin secrets config [skip ci]

* feat: extend Lightning wallet functionality with transaction history fetching

* feat: add LNURL-pay address detection and support in address parsing flow for Bitcoin Lightning integration

* refactor: simplify `ReceivePageOption` logic

* refactor: centralize `PaymentURI` generation logic across wallet types

* feat: enhance `PaymentURI` handling with asynchronous support and Lightning-specific functionality

* refactor: streamline `PaymentURI` logic and remove redundant URI implementations across wallet types

* refactor: remove redundant debug print statement from `bitcoin_wallet_addresses.dart`

* refactor: improve consistency in widget styling and centralized label logic, add Bitcoin Lightning deposit/withdraw support

* feat: reload balance and tx history after sending a lightning transaction

* feat: improve address formatting for human-readable addresses and update the default LNURL domain

* fix: merge conflicts

* feat: add error handling for LightningWallet initialization and adjust transaction direction logic

* feat: enable private transactions by default in LightningWallet and update Breez SDK version to 0.4.2

* minor fixes [skip ci]

* chore: fix some minor issues in comments (#2654)

Signed-off-by: black5box <black5box@outlook.com>

* fix: handle send-all functionality for LightningWallet transactions and adjust amount calculation logic

* fix-german (#2659)

* chore: update German localization strings for consistency and accuracy

* chore: update German localization strings for consistency and accuracy [skip-ci]

* feat: add LNURL support for address validation and LightningWallet compatibility, enhance error handling for OpenCryptoPay

* fix: adjust LightningWallet amount parsing from 9 to 8 decimal places

* feat: add LNURL support in LightningPaymentRequest and LightningWallet

* Fix navigation gradient (#2657)

* Fix navigation gradient

* Fix CONFIG_ARGS formatting in app_config.sh (#2660)

* fix: block wrongly parsed addresses (#2656)

* fix: block wrongly parsed addresses

* fix: move parsed address check into handlePaymentFlow method

* fix: Handle QR URLs separately for pay anything flow

* feat: add electrum seed support for Lightning

* refactor: improve `parseFixed` logic and add comprehensive unit tests for edge cases (#2661)

* Update cw_bitcoin/lib/bitcoin_wallet.dart [skip ci]

* resolve conflict issue

---------

Signed-off-by: black5box <black5box@outlook.com>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>
Co-authored-by: black5box <black5box@outlook.com>
Co-authored-by: tuxsudo <tuxsudo@tux.pizza>
Co-authored-by: cyan <cyjan@mrcyjanek.net>
Co-authored-by: David Adegoke <64401859+Blazebrain@users.noreply.github.com>

* remove old code [skip ci]

* fix: page widgets rebuilt every time

* chore: formatting

* remove unused navbar

* fix: lightning balance on balance card in lightning mode

* fix: return if uri == null

* feat: trade history in new ui

* feat: enhance balance model with secondary asset handling

* feat: unique card colors and icons for coins

* wip: card customization

* fix: merge conflict

* feat: customizable balance card

* Fix some spacings and test sizing

* Fix formatting

* feat: add Lightning Network support for send flow and fee handling adjustments

* refactor: remove unnecessary debug print statement in send flow for Lightning Network balance

* feat: integrate OpenCryptoPay QR handling in send flow and improve scan action handling logic

* feat: add maxDepositClaimFee parameter for Lightning wallet configuration

* Switch balance card to RoundedSuperellipse and set color list to Wrap

* Fix

* Switch to scroll view

* refactor: update navigation route from `receive` to `addressPage` in coin action row

* feat: bloc-based viewmodel for card customizer

* feat: mobx-independent balance card customizer vm

* minor fixes

* copyWith constructor for cleaner state changes

* refactor: wrap `HistorySection` with `Observer` for reactive state updates, update navigation for "Buy" action, and fix incorrect balance property

* feat: enhance Bitcoin receive flow with Lightning and SegWit options, update address page registration, and localize coin action labels

* feat: add helper methods for Lightning and SegWit receive page options in Bitcoin configuration

* feat: add Lightning transaction type handling and enable navigation to transaction details from history

* Add more special card types

* feat: new ui settings page

* feat: add Lightning actions to balance cards, refactor card rendering logic

* refactor: update settings page localization, hide unused settings items

* feat: add secrets generation for cw_bitcoin, including breezApiKey

* Lightning switcher animation (#2725)

* Properly animate bitcoin/lightning switcher

* Cleanup and fix sizing

* Final cleanup

* Fix action button colors (#2732)

* feat: add hardware wallet type handling and improve parsed address reset flow

* Refactor settings page to use generic row items (#2745)

* fix android back button in settings on android, force iphone-style transitions on all platforms

* move settings page to generic row impl

* fix imports

* Balance card fixes (#2729)

* Update balance card sizing

* Fix spacing

* Initial font changes (#2731)

* Initial font changes

* More font changes

* feat: integrate Lightning transaction support and improve transaction history UX

- Enhanced dashboard to compute confirmations using the first and last transactions.
- Updated `BitcoinWallet` to subscribe for and manage Lightning transactions.
- Improved `HistoryTile` layout and introduced new leading icons for Lightning transactions.

* feat: add unclaimed deposit actions and enhance Lightning event handling

* release changes [skip ci]

* Enhanced card customizer (#2744)

* enhanced card customizer

* Fix conflicts

* Add missing icons + adjust spacing

---------

Co-authored-by: tuxsudo <tuxsudo@tux.pizza>

* feat: enhance Lightning invoice handling and address validation

- Added support for identifying non-zero amount Lightning invoices.
- Refined invoice matching with updated regex patterns.
- Improved UI to conditionally display addresses in sending confirmations.
- Adjusted logic to handle zero-value Lightning invoices.

* feat: add `isPayjoinAvailable` computed property and update Payjoin visibility logic

* feat: improve Lightning wallet handling and block explorer logic

* update patch version [skip ci]

---------

Signed-off-by: black5box <black5box@outlook.com>
Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>
Co-authored-by: OmarHatem <omarh.ismail1@gmail.com>
Co-authored-by: tuxsudo <tuxsudo@tux.pizza>
Co-authored-by: black5box <black5box@outlook.com>
Co-authored-by: cyan <cyjan@mrcyjanek.net>
Co-authored-by: David Adegoke <64401859+Blazebrain@users.noreply.github.com>

* minor new ui fixes

* padding for new row separators

* remove debug prints

* New design improve nav bar (#2763)

* tweak navigation bar touch targets and sizing

* feat: add tests for identifying zero and non-zero amount Lightning invoices (#2772)

* feat: add tests for identifying zero and non-zero amount Lightning invoices

- Added unit tests to validate recognition of Bolt11 zero-amount and non-zero-amount invoices.
- Enhanced `isBolt11ZeroInvoice` function to handle `lightning:` prefixed invoices.

* fix: correct currency selection logic for Lightning wallets in Send ViewModel

* feat: improve Lightning wallet initialization and address generation

- Updated `init` method in `LightningWallet` to return a boolean for initialization success, adding error handling for failed setups.
- Integrated dynamic name generation using `generateName` for Lightning wallet addresses.

* refactor: relocate `generate_name` to `cw_core` and update imports

* chore: update breez sdk (#2789)

* Wire tokens and NFTs to new Home page (#2804)

* wiring for assets on home page

* fix imports

* wire nft page in new ui

* fix nft display in new ui

* fix totalWidth calc

* add tokens button + bugfixes

* add tokens button + bugfixes

* fix late initialization

* fix history section exception

* fixes

* Add haptic feedback (#2813)

* Add haptic feedback

* Add haptic feedback to correct ActionButton

* Return bottom gradient (#2808)

* Add IgnorePointer to bottom nav gradient (#2822)

* New design send page (#2791)

* new ui send page (wip)

* coin control page improvements

* fee settings, new send confirmation modal

* minor aesthetic fixes

* load network name without cw_bitcoin import

* recipient dot cleanup

* minor logic fixes

* ui polish

* - add aliaspay support
- fix wording for max button
- fix back button action in modals

* Sizing changes

* dismiss transaction on modal close

* sizing fix

* - fix remove recipient icon
- properly round amounts
- fix coin control page spacing

* - fix remove recipient icon
- properly round amounts
- fix coin control page spacing

* - fix button sizing
- add description for fees page

* Update lib/view_model/unspent_coins/unspent_coins_list_view_model.dart [skip ci]

* Update lib/view_model/send/send_view_model.dart [skip ci]

---------

Co-authored-by: tuxsudo <tuxsudo@tux.pizza>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* Fix conflicts with dev

* Fix conflicts with dev

* Add zcash receive options to new design flow

* wire in missing settings in new ui

* up migration version

* formatting

* translations

* lint.sh

* New design receive page (#2834)

* feat: viewmodel on new receive page (wip)

* feat: address type selector for new ui receive page

* fix: minor fixes to touch targets and tap anims

* minor ui fix

* wip receive page changes

* receive page + address selection page

* receive page + address selection page

* add font

* add svg

* minor ui fixes

* receive page fixes/improvements

* change receive page modal design

* further ui polish

* icons for infobox

* fix restricted import

* fix closing label modal

* - fix balance card appearance on address page
- fix search bar position
- fix mweb position in address type selector

* receive page fixes

* fix anonpay

* remove restricted import

* fixes

* fix receive on zec

* simplify chain id

* lint fix

* fix migration numbering

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* fix migration version

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* fix settings

* readability

* fix formatting

* move dismiss infobox to vm

* disable addr rotation on zcash

* remove _setEffects

* translations

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* New UI Sync bar (#2831)

* syncbar

* small styling fixes

* modify duration

* lint.sh

* syncHeavy wallet types

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* update translations, add pull-down refresh, separate top bar components to files

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* alphabetize

* New design balance card icons (#2824)

* Add the other crypto card icons

* Update Zano, add Zcash and Arbitrum

* Update default card style and available gradients

* Fix broken preview

* Fix animation

* Color combinations fix

* Minor updates

* Add decred icon

* if(!mounted) return;

* New design minor fixes (#2842)

* More minor fixes

* Update modal sheet behaviour

* Update missing currency image links

* List row and navigation bar tweaks

* Minor navbar fix

* New UI Swap page (#2829)

* new ui send page (wip)

* coin control page improvements

* fee settings, new send confirmation modal

* minor aesthetic fixes

* load network name without cw_bitcoin import

* recipient dot cleanup

* minor logic fixes

* ui polish

* - add aliaspay support
- fix wording for max button
- fix back button action in modals

* Sizing changes

* dismiss transaction on modal close

* sizing fix

* - fix remove recipient icon
- properly round amounts
- fix coin control page spacing

* - fix remove recipient icon
- properly round amounts
- fix coin control page spacing

* - fix button sizing
- add description for fees page

* swap page

* fixes

* further fixes

* merge

* png -> svg

* minor condition changes

* lint.sh

* fix swapsxyz isCentralized

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* translations, readability improvements, remove debug rows

* cleanup

* alphabetize strings

* small bugfixes

---------

Co-authored-by: tuxsudo <tuxsudo@tux.pizza>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* fix new ui coin control page layout (#2843)

* New design lightning flows (#2821)

* new ui send page (wip)

* coin control page improvements

* fee settings, new send confirmation modal

* minor aesthetic fixes

* load network name without cw_bitcoin import

* recipient dot cleanup

* minor logic fixes

* ui polish

* - add aliaspay support
- fix wording for max button
- fix back button action in modals

* Sizing changes

* dismiss transaction on modal close

* sizing fix

* - fix remove recipient icon
- properly round amounts
- fix coin control page spacing

* - fix remove recipient icon
- properly round amounts
- fix coin control page spacing

* - fix button sizing
- add description for fees page

* lightning flow wip

* lightning flow wip #2

* lightning withdraw flow

* lightning deposit flow (wip, currently works but really janky)

* send from external + bugfixes

* merge fixes

* merge fixes

* fixes

* Update lib/new-ui/widgets/send_page/l2_action_wallet_selector.dart

---------

Co-authored-by: tuxsudo <tuxsudo@tux.pizza>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* fix covered create wallet button

* fix: close modal after transaction commitment in Send ViewModel (#2858)

* New design tweaks (#2847)

* Add more haptic feedback

* Fix background gradients and modify SafeArea in home_page.dart

* Fix history padding, fix divider color, disable Charts, update base_page.dart appbar style, fix nav bar border + height on iOS

* Lightning Username setup flow for new UI (#2845)

* lightning username edit/create flow

* fix button color

* fix layout

* fixes

* remove character limitation for internal builds

* remove dependency on cw_bitcoin

* fix username requirements

* fixes

* condition fix

* Update lib/new-ui/pages/lightning_username_page.dart

---------

Co-authored-by: OmarHatem <omarh.ismail1@gmail.com>

* keyboard hide overlay for iphone

* New design UI tweaks (#2870)

* Fix nav height on Android

* Fix blue gradient

* Update transactions view and minor UI tweaks

* CW1011-Allow-users-to-view-bitcoin-amounts-in-sats (#2678)

* feat: introduce `formatFixed` integration and sats display preference

* feat: enable display of Bitcoin amounts in satoshis and refactor amount formatting logic

* refactor: consolidate fee formatting logic and add support for MWEB availability check

* feat: add support for satoshi-based amount display and enhance fiat conversion logic

* feat: add support for satoshi-based amount parsing, formatting, and display preferences across buy/sell flow and UI adjustments

* feat: implement `AmountParsingProxy` with unit tests for parsing and formatting crypto amounts in various display modes

* feat: replace `preferBalanceInSats` with `displayAmountsInSatoshi` and introduce `AmountParsingProxy` for unified crypto amount handling across the app

* refactor: streamline amount formatting logic and enhance unspent coins handling with `AmountParsingProxy` integration for unified crypto processing

* refactor: replace direct bitcoin amount formatting with `AmountParsingProxy` and remove debug print in `exchange_view_model`

* refactor: replace `getIt<AmountParsingProxy>` with `_appStore.amountParsingProxy`, remove redundant dependencies across view models and adjust related imports

* refactor: remove redundant `AmountParsingProxy` registration in DI setup to simplify dependency management [skip ci]

* feat: add getCryptoSymbol to simplify the Symbol selection between Sats and Bitcoin

* fix: merge conflict

* Revert "fix: merge conflict"

This reverts commit 6debdaa0466747d6fcc85d6bd0be115e6fb4d856.

* fix import [skip ci]

* feat: remove number formatter from exchangeVM

* refactor: replace `SettingsStore` with `AppStore` across view models, integrate `AmountParsingProxy` for amount formatting, and clean up redundant imports

* refactor: remove debug print statements from `getCryptoOutputAmount` in `AmountParsingProxy`

* feat: enhance fee and deposit amount formatting with crypto symbols and improved parsing

* feat: integrate `AmountParsingProxy` for improved Bitcoin amount parsing in `PaymentURI` and fiat-to-crypto conversion

* feat: append crypto symbols to Bitcoin transaction amounts in dashboard view

* feat: improve crypto amount parsing in SendCard widget and Output view model using `AmountParsingProxy`

* feat: conditionally show Bitcoin amount display setting for Bitcoin wallets and refactor `DisplaySettingsViewModel` to use `AppStore`

* refactor: clean up redundant imports in `bitcoin_wallet.dart` and `electrum_wallet.dart`

* feat: append crypto symbols to fee values in send and cake pay card widgets for improved clarity

* refactor: replace `currencyTitle` with `currency` across widgets and integrate `AmountParsingProxy` for improved crypto amount formatting and parsing

* refactor: improve validation logic and amount parsing in SendCard and Output widgets

* refactor: standardize amount parsing and formatting logic with `AmountParsingProxy` across ViewModels and widgets

* refactor: `AppStore` remove debug prints

* refactor: rename amount parsing/formatting methods for better clarity in tests [skip ci]

* fix: AmountParsingProxy and optimize `cryptoAmount` handling in BuySellViewModel

* fix: adjust balance calculation for Monero and Wownero to exclude unlocked amount from full balance

* fix: correct `_appStore` usage and format adjustments in `SendViewModel`

* feat: enhance satoshi on new-ui

* feat: add computed property for `amountParsingProxy` in AppStore

* feat: localize Bitcoin amount display option and update asset history UI

* feat: improve exchange amount processing and refactor fiat conversion values

---------

Co-authored-by: OmarHatem <omarh.ismail1@gmail.com>

* New design unconfirmed balance widget (#2861)

* unconfirmed balance display widget for new ui

* unconfirmed balance display widget for new ui

* merge

* alphabetize translations

* New UI fixes (#2860)

* fix asset top bar

* improve wordmark in large qr mode on receive

* receive option fixes

* exchange -> swap

* send page fixes

* update pubspec base

* go to home on wallet change

* nicer card customizer

* don't show account name for single-account wallets

* special card design for lightning

* fiat amount bar improvement

* update translations

* add sending indicator

* fix non-number input to receive amount

* de-jank fiat input

* nicer balance card animation when switching btc-ln

* nicer balance card animation when switching btc-ln

* fix backup password input

* display time+date in history

* fix error on buy

* fix incorrect wallet showing in wallets tab

* fix wallet list layout

* only show coin control option on hasCoinControl

* better error on send page

* fiat value in coin control

* add zano to isSyncHeeavy

* fix keys in settings

* fix assets condition

* fix import

* remove BasePage dependency in RescanPage

* add missing settings

* show send/receive in swap confirm sheet

* fix receive background on ios

* fix assets spacing

* fix trade tile sizing

* fix padding

* fix icon in wallet select modal

* change text on swap initial modal

* spacing

* l2 send external modal styling

* fix null on swap confirm sheet

* change infobox text

* add chain icon to asset widgets

* add chain icon to asset widgets

* disable swap page reset

* fix wallet list page layout

* revert merge conflict issue [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* Account Customizer for new UI Monero (#2859)

* new ui monero account management (wip)

* account reordering wip

* account reordering wip

* account reordering (works)

* cards view compact mode

* format

* translation

* name generation

* fix for non-xmr wallets

* }

* allow reset order, fallback on improperly saved order

* translation

* fix for pre-reorder wallet loading

* fix loading

* - save cards on modal slide-down
- always load active account as first

* fix card customizer close anim

* fixes

* fix condition

* merge

* fix migration versions

* use updated flutter rust bridge in lightning and payjoin

* mvp fixes

* new ui mweb mask/unmask

* fallback for balance card amount format

* New UI tweaks (#2872)

* Update lightning transaction history view

* Add BNB card design

* Color, padding, and radius fixes

* Fix wallet list bottom section & gradient

* Update Apps page

* reformat

* nicer sat picker

* fix keyboard

* chain badges

* enhance styling for card customizer

* mweb settings icon

* mweb chain badge

* update wording in settings

* bnb chain icon

* always round send amount

* always round all amount

* token placeholder

* Fix ModernButton colors (#2888)

* Fix ModernButton colors

* Minor

* guard for unconfirmed balance widget

* fix error on wallet switch

* New design mvp fixes (#2890)

* mvp fixes

* fallback for balance card amount format

* reformat

* nicer sat picker

* fix keyboard

* chain badges

* enhance styling for card customizer

* bnb chain icon

* always round send amount

* always round all amount

* guard for unconfirmed balance widget

* fix error on wallet switch

* Update lib/new-ui/pages/account_customizer.dart

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* fixes

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* Install Protoc in reusable build workflow

Added step to install Protoc before building.

* Fix protobuf-compiler installation step

Update package list before installing protobuf-compiler.

* Modify Protoc installation command to handle update errors

Change the install command for Protoc to avoid failure on update.

* Streamline Lightning wallet balance management and crypto handling (#2893)

* refactor: streamline crypto amount handling and improve Lightning balance management

- Removed redundancy in balance calculations for Lightning wallets.
- Centralized crypto symbol creation with `selectedCryptoCurrencySymbol`.
- Enhanced crypto amount handling and formatting with `AmountParsingProxy`.
- Simplified logic for displaying Lightning balances across UI components.

* refactor: remove sats display logic and unused formatting from BalanceCard widget

* chore: update breez-sdk-spark-flutter to latest commit

* feat: enhance crypto amount formatting with localized separators and max decimals

* fixes

* fix: handle null balance records in Lightning wallet cards

* New design add validators (#2894)

* add validation, fix node form

* Add validator to send amount input field

Added a validator to the amount input field.

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* Disable 'addresses' button on receive screen for BTC LN (#2896)

* feat: Disable addresses button on receive screen for BTC LN

* chore: remove debug print in uri computation

* feat: introduce swap action toggle and UI updates

* feat: conditionally display Zcash card setting for Zcash wallets in Display Settings

* Fix leading button color (#2898)

* fix amount format

* fix loadCards

* pre-beta fixes

* cyjan: fix: order being null for certain index

* pre-beta fixes v2 (#2905)

* minor context check [skip ci]

* persist fee priority for zcash (#2907)

* Add support for Zcash address detection and amount logic refactor (#2906)

* refactor: consolidate crypto amount handling with `displayAmount` and `cryptoCurrencySymbol`, improve fiat conversion logic, and optimize token currency management

* refactor: simplify `displayAmount` logic and remove unused `_rawAmount` property

* feat: add support for Zcash transparent address detection and simplify amount conversion logic

* Improve Lightning invoice handling and crypto formatting (#2908)

* fix: update Lightning address regex to support additional formats and prefixes

* fix: conditionally render advanced settings dropdown based on fees or coin control availability

* feat: enhance address detection, Lightning invoice handling, and crypto formatting

* feat: improve Lightning invoice parsing and crypto amount formatting on send page

* chore: remove unnecessary exception printing in `getBolt11Amount` function

* Fix lightning swap

* import fix (hide Mac;)

* parse -> tryParse

* Transaction Commited -> Transaction Sent!

* feat: enable clipboard paste for deposit and receive addresses in swap page (#2909)

* fix: resolving LNURLS (#2911)

* new UI pre-beta fixes (#2910)

* fixes

* parse -> tryParse

* change sat display settings style

* minor fix until hive is removed [skip ci]

* Remove redundant logic and improve send page features (#2913)

* fix: update crypto amount parsing logic in send confirmation sheet

* feat: Added checkbox to toggle Litecoin MWEB coins on the send page.
fix: LNUrlPayRecord

* fix: remove redundant `.withLocalSeperator()` from fiat balance formatting logic

* fix: update Bitcoin amount display titles to align with consistent formatting standards

* force boolean to update (#2916)

* force boolean to update

* fix bnb balance

* fixes #4 (#2917)

* only display sats for btc wallets in card customizer

* fix: resolve async handling of Lightning transaction history in `fetchTransactions` method (#2919)

* New design pre beta fixes 5 (#2918)

* improve l2 deposit/withdraw flow layouts

* add copied indicator

* SafeArea

* fix addr rotation

* fix styling of lightning switcher

* no raster graphics in new ui please

* optimization for assets/history section

* remove unused bloc provider

* optimize dashboard + fix duplicated name

* disable lightning mode on wallet change

* remove broken animation

* safearea around nodes page

* fix rescan page layout

* fix exception on really fast switching

* remove broken blur

* card customizer autosave

* remove debug print

* add better fallbacks for currency titles

* revert due to broken animation

* fix send page crash

* fix chain title for arb

* fix cupertino date picker

* Update lib/new-ui/widgets/receive_page/receive_bottom_buttons.dart [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* feat: add focus management and external address validation to send page forms

- Introduced `focusNode` to `NewSendAddressInput` for better input handling.
- Enhanced address validation by synchronizing with parsed external addresses.
- Updated logic for non-MWEB unspent coin type in send actions.
- Suppressed unnecessary exception logs in Bitcoin wallet transactions.

* New design swap page fixes (#2923)

* swap page fixes

* add scroll controller

* comment

* tweak refresh pulldown (#2924)

* add copy button to l2 send external modal (#2925)

* account customizer padding

* feat: lightning transaction fetching and Lightning wallet integration (#2927)

- Allow nullable `height` in `ElectrumTransactionInfo`.
- Add `fromDate` support for filtered Lightning transaction history retrieval.
- Simplify Lightning address handling logic in wallet addresses.
- Optimize Lightning wallet transaction syncing based on the last Lightning transaction date.
- Clean up imports in `electrum_transaction_history.dart`.

* New balance handeling (#2931)

* feat: lightning transaction fetching and Lightning wallet integration

- Allow nullable `height` in `ElectrumTransactionInfo`.
- Add `fromDate` support for filtered Lightning transaction history retrieval.
- Simplify Lightning address handling logic in wallet addresses.
- Optimize Lightning wallet transaction syncing based on the last Lightning transaction date.
- Clean up imports in `electrum_transaction_history.dart`.

* feat: add support for Lightning balance in wallet snapshot and initialization

* Disable Lightning switcher for hardware wallets (#2932)

* fix: disable Lightning switcher for hardware wallets

* fix: update wallet type check to use `isSoftwareWallet` for Lightning support

* New design pre beta fixes 6 (#2929)

* fix swaps from ln

* prevent crash if ln balance isn't loaded yet

* fix currency icons disappearing on swap confirm sheet

* fix swap fiat validation

* display ln at top on swap currency selector in btc wallets

* update icon for card options

* display default fiat and crypto at top of currency picker

* fix fiat amount bar formatting

* add modal scroll controller to provider logs

* revert premature optimization (sizing issue)

* New design pre beta fixes 7 (#2935)

* fix swaps from ln

* prevent crash if ln balance isn't loaded yet

* fix currency icons disappearing on swap confirm sheet

* fix swap fiat validation

* display ln at top on swap currency selector in btc wallets

* update icon for card options

* display default fiat and crypto at top of currency picker

* fix fiat amount bar formatting

* add modal scroll controller to provider logs

* revert premature optimization (sizing issue)

* copyable trade id

* disable swaptrade on ln

* set isFixedRate properly

* update color

* display trocador provider on swap confirmation sheet

* add "exchange rate is fixed" text

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* updated l2 modal (#2934)

* display names for send addr input (#2936)

* fix: MWEB toggle logic on send page (#2938)

* feat: add retry logic to `getAddress` in Lightning wallet (#2939)

* Enhance crypto address handling and add Lightning invoice support (#2937)

* feat: enhance crypto address handling and add Lightning invoice support

- Added `_overrideFromCryptoCurrency` and `_overrideToCryptoCurrency` for Zcash unified and shielded addresses.
- Improved Lightning invoice generation with `getLightningInvoice` for Bitcoin wallets.
- Updated error handling in exchange provider to accommodate API changes.
- Introduced Lightning invoice fallback for deposit and receive addresses in ExchangeViewModel.

* feat: Added `_overrideFromCryptoCurrency` and `_overrideToCryptoCurrency` for Zcash unified and shielded addresses.

* fix pay anything on paste button (#2940)

* Prevent multiple paste triggering any pay flow

* fixup fiat input (#2941)

* New design small fixes (#2920)

* Fix optical symmetry for swipe to send text

* Update nav bar icons

* Top bar and card tweaks

* Update paddings

---------

Co-authored-by: malik1004x <malikowskirobert@gmail.com>

* fix erc20 balance display (#2944)

* fix erc20 balance display

* route through cw_evm

* New design beta fixes (#2943)

* fix asset tile layout

* fix card customizer keyboard jumping

* fix cardsview exception

* fix swap modal height

* remove syncbar percentage

* add copy icon to trade id

* fix trade confirmation appearing twice

* remove useless mweb setting

* add tag to contact currency selector text

* prettify picker for ln

* fix receive crash

* always route to NewSendPage

* handle ln amount on paste

* handle ln amount on payment request creation

* prettify ln errors

* readd "blocks" word

* register deeplinks

* Enhance bitcoin error message [skip ci]

* fix support chat page (#2946)

* new-design-fix-confirm-sheet-parsing-error (#2950)

* feat: use bigint instead of doubles

* feat: use bigint instead of doubles

* feat: use bigint instead of doubles

* fix: also show sats in confirm sheet

* fix: also show sats in confirm sheet

* feat: localize amounts and cap amount in tx history (#2951)

* fix: linux CI

* feat: localize token balances (#2954)

* fix: send amount hww (#2955)

* chore: use latest breez sdk (#2953)

* fix addAddressWord

* fixes (#2957)

* receive fixes (#2959)

* fix: stabilize android build by increasing jvm heap size (#2958)

* fix: lighting by having the new SDK Save into a new location (#2961)

* New design rc fixes (#2960)

* additional safeguards for isSyncHeavy check

* fix account name getting reset

* update base icon

* fix units in swap

* readd memos to zec

* New design minor UI (#2956)

* Wrap text for list item widgets

* Update lightning address and QR icons

* Update near intents icon

* Fix share issue

* Fix (#2963)

* fix tx amount formatting

* rename currency

* change wording for zec memo

* fix base icon

* fix app icon script [skip ci]

* New design rc fixes 2 (#2965)

* fix account name changes

* fix spacing on addresses page

* add payjoin copy modal

* improve memo ui

* potential fix for ci

* Set default address for zcash and bitcoin for buy flow (#2979)

* new monero.com icons (#2980)

* parse and validate deposit amount from api (#2967)

* generic fixes

* minor context fix [skip ci]

* Generic fixes (#2982)

- solana send all bug
- pasting SOL address triggering payanything flow
- add more address types for payanything detection

* rescan fix

* about page (#2974)

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* update settings icons/wording (#2973)

* Changelog modal (New UI) (#2971)

* add new changelog modal

* typo

* print -> printV

* Update lib/new-ui/widgets/changelog_modal.dart [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* fix node form (#2970)

* new-design-add-breez-logging (#2984)

* feat: add Lightning log export functionality for Bitcoin wallets

* feat: add multilingual support for Lightning log export strings

* feat: add Lightning support toggle in settings and translations for multiple languages

* refactor: simplify `setUseLightning` by removing redundant store update

* Update cw_bitcoin/lib/electrum_wallet.dart [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* minor fixes [skip ci]

* minor context fixe [skip ci]

* fix: make walletinfoid unique to prevent duplicates (#2969)

* fix: walletconnect not working in new design builds (#2993)

* new-design-fix-mweb-coin-enabling (#2995)

* feat: add unspent coin type handling to asset details modal send button

* fix: improve German translations for wallet, seed, and Lightning-related strings

* fix: update Dutch translations to correct terminology and formatting #2992 (#2997)

* fix: drop gn (#3000)

* vulnerable seeds popup on new ui (#3004)

* update mac os monero.com icons (#3003)

* Add Payjoin log export and improve logging behavior (#2999)

* fix: suppress exception logging in `getAddress` method of Lightning wallet

- Added a try-catch block to avoid unnecessary exception logs during Lightning address retries.

* fix: update fallback message for missing Lightning address detection

* feat: add Payjoin log export and logging enhancements

* fix: localize "Export Payjoin Logs" string in settings page

* fix: litecoin mweb balance being included in the second asset (#2998)

* Minor fixes (#2994)

* Minor fixes

* Update lib/new-ui/new_dashboard.dart [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* New design post release fixes (#3002)

* fix: only throw on deserialize if kDebugMode is true (#2976)

This closes #2972, in debug mode we will still catch these issues but if
somehow that happens on production it will fallback to safe default

* fix: update docs and dockerfile (#2975)

* fix: missing steps for linux build [skip ci] (#2985)

* move balance to bigint

* move balance to bigint

* fix electrum issue

* fix unconfirmed balance

* fixes

* Fix minor issue in Spanish translation (#2991)

* Fix minor issue in French translation (#2987)

* Fix minor issues in German translation (#2986)

* update constructor calls in configure.dart

* fixes

* remove expnded

* V6.0.1 Early Release Candidate

---------

Co-authored-by: cyan <cyjan@mrcyjanek.net>
Co-authored-by: Edwin den Boer <woordenboer@planet.nl>
Co-authored-by: OmarHatem <omarh.ismail1@gmail.com>

* Swaps xyz swap enhancements (#2615)

* refactor token cache and limit handling

* Improve SwapsXYZ external send logic

* Improve SwapsXYZ fixed-rate handling

* disable fixedRate for SwapsXyz

* SwapsXYZ contract call

* Add track url for swaps xyz

* add arbitrum support

* add check for unsupported source tokens

* enable SwapsXyzExchangeProvider in provider list

* refactor SwapsXYZ provider and trade flow handling

* Update exchange_trade_view_model.dart

* validate evm call-data

* Revert "validate evm call-data"

* fix msg value for ERC-20 transfers

* fix flag for swapsXYZ send check

* Update send_view_model.dart

* handle Swaps.xyz method selectors & approvals

* fix evm approvals

* Improve EVM token approval & receipt handling

* merge split token transfers in evm tx

* fix token allowance check for approvals

* add sourceToken validation to EVM tx creation

* prioritizing incoming transactions over fetched outgoing ones

* compute net flow when merging transactions

* add truncateTrailingText to list items and widgets

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>
Co-authored-by: Serhii-Borodenko <17529954+Serhii-Borodenko@users.noreply.github.com>

* fix wownero balance (#3007)

* fix keyboard (#3006)

* fix android build

* check if stream is closed [skip ci]

* [skip ci] lint

* fix: populate amount field (#3009)

* fix address rotation exception (#3011)

* copy uri with amount from recieve page (#3010)

* add "transaction sent!" to swap confirmation sheet (#3012)

* fix wallet change on token swaps (#3013)

* Fix fee estimation and recipient logic in Lightning Network (#3014)

* fix: update `hasMultiRecipient` logic to include non-Lightning coin type check

* fix: Lightning Network fee estimation and parsing logic

* fix: adjust `sumByBigInt` logic to handle `sendAll` flag in send page

* fix: move sqlite migrations to sqlite.dart (#3008)

* fix: move sqlite migrations to sqlite.dart
fix: backup restore not initializing SQL properly

* Update cw_core/lib/db/sqlite.dart

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* feat: update currency symbol handling and extend Electrum transaction details (#3016)

* Use isCentralized for truncation trade id [skip ci]

* fix: Incorrect token amount for tokens and filter out new spam transactions after swaps (#3015)

* New design release swap fixes (#3018)

* fix deserialize ln

* fix get wallet type for bnb tokens

* show extraId for swaps

* chore: translate using gpt-5.2 (#3021)

* add NEAR send-all validation

* tiny ui fixes (#3023)

* use double parsing for amount comparison[skip ci]

* adjust lightning address error message

* feat: add BTC LN support to available methods and payment data handling

* feat: add cached Lightning address handling for improved performance (#3025)

- Introduced `cachedAddress` field to store and reuse the last fetched Lightning address.
- Updated `getLightningAddress` method to fallback on `cachedAddress` if no new address is fetched.
- Extended wallet constructors and snapshots to include `cachedLightningAddress` for persistence.

* Revert transaction history color

* Minor

* Apply suggestion from @malik1004x

* new-design-post-release-fixes-3 (#3028)

* fix unnecessary account switching

* fix exception on bad payment amount

* fallback for currencies on external swap modal

* increase balance card touch target

* don't use lightning addresses for exchange

* increase max length for ln encoding

* don't show infobox on ln receive

* fix showing old tx details (null tx on createTransaction)

* remove unused import

* refactor: relocate `_logStream` declaration in `LightningWallet` for better code organization (#3029)

* monero build fix
update build numbers
fix best rate null [skip ci]

* hide swap on mweb asset

* minor context fix [skip ci]

* Fix Silent payment case

* new-ui: fix changelog typo (#3036)

Fix typo in changelog for account management.

* Modify date format to Month DD YYYY

* feat: docker based ci

* Fix 2FA continue button location (#3043)

* fix: Desktop wallet bugs (#2968)

* fix: Desktop wallet bugs
- repeated wallets post migration
- newly created wallets not showing up
- extra large components on desktop, needed maxwidth

* chore: Remove duplicate logic

* chore: remove formatting

* refactor: streamline updateList method and handle multiple calls with a future based mutex

* refactor: enhance swipe to confirm with dynamic width handling and improved drag threshold logic

* Improve error handling and duplicate invoice handling in Lightning wallet (#3047)

* fix: handle duplicate Lightning invoice payments gracefully

* fix: improved error handling in Lightning wallet

* General improvements (#3030)

* General Improvements
- Make borderRadius for CTAs uniform 18px
- Identify hardware wallets in title of Seeds/Keys page
- Make entire wallet tile clickable in wallet list

* chore: Simplify check

* Update lib/view_model/wallet_keys_view_model.dart [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* homescreen improvements (#3034)

* Homescreen improvements
- Increase touch area for card editing icon
- Tapping any card in the background should move it ino the foreground without closing the account tab
- make top left chain icon primary color with full opacity when syncing and 20% when done
- add tor indicator to top bar when enabled

* fix: remove unneeded color filter

* refactor: Adjust structure for tor and sync indicators

* minor fixes (#3045)

* Enhance LNURL payment integration (#3041)

* feat: enhance LNURL support and Lightning payment handling

- Improve LNURL decoding and encoding with expanded prefix handling.
- Add support for parsing and validating LNURL payment invoices.
- Introduce logic for fetching LNURL payment request amounts.
- Update payment flow to integrate LNURL and Lightning-specific conditions.
- Refactor BOLT11 prefix validation and amount extraction logic.

* fix: simplify LNURL invoice validation by removing redundant BOLT11 check

---------

Signed-off-by: black5box <black5box@outlook.com>
Co-authored-by: Serhii <borodenko.sv@gmail.com>
Co-authored-by: malik1004x <malikowskirobert@gmail.com>
Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>
Co-authored-by: tuxsudo <tuxsudo@tux.pizza>
Co-authored-by: black5box <black5box@outlook.com>
Co-authored-by: cyan <cyjan@mrcyjanek.net>
Co-authored-by: David Adegoke <64401859+Blazebrain@users.noreply.github.com>
Co-authored-by: Konstantin Ullrich <konstantin@cakewallet.com>
Co-authored-by: Edwin den Boer <woordenboer@planet.nl>
Co-authored-by: Serhii <17529954+serhii-bor@users.noreply.github.com>
Co-authored-by: Serhii-Borodenko <17529954+Serhii-Borodenko@users.noreply.github.com>
Co-authored-by: rottenwheel <92872541+rottenwheel@users.noreply.github.com>

86/100 · StrongMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
access controldefensive validationcryptography-sensitive pathseed or entropy pathsigning or wallet pathauthentication pathparser or protocol path
AI analysis · Low 32/100

This is a very large feature commit for Cake Wallet titled 'New design'. It primarily introduces a redesigned user interface and adds Bitcoin Lightning Network support via the Breez SDK. The commit also includes many smaller fixes for swaps, address parsing, amount formatting, and wallet handling. There is no explicit vendor statement that this commit fixes a security vulnerability, and the changes are mostly feature work. Some areas—such as Lightning wallet initialization, address validation, and swap/exchange flow changes—touch security-sensitive code, but the diff provided is too high-level to confirm any specific vulnerability or its fix.

Security candidateGeneric Token Fixes (#2874)by David Adegoke · 326ef316 · Feb 8, 2026 · 8 filesMessage 83 · StrongModerate 64Details
Commit message · David Adegoke

Generic Token Fixes (#2874)

* feat: Automatically detect wallet tokens for EVM chains

* feat: Disable potential tg scam tokens by default

* feat: Add homoglyph normalization to detect spoofing attacks in token symbols

* refactor: Improve scam token detection and apply to automatically fetched EVM tokens

* refactor: Enhance scam detection for automatically detected tokens in evm wallets

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Enable whitelisted tokens with balance when importing wallet tokens

* feat: Disable imported tokens with balance less than 0.1 usd

* feat: Disable imported tokens with balance less than 0.1 usd
- Update configure file

* fixes:
- default tokens marked as potential scam
- ui overflow for token name on balance page
- add more filters for spam tokens

* - detect and flag default token impersonators
- add homoglyph normalization to prevent spoofing attacks on new token symbols
- fix bnb not coming up in receive currency list for swap page

* - detect and flag default token impersonators
- add homoglyph normalization to prevent spoofing attacks on new token symbols
- fix bnb not coming up in receive currency list for swap page

* Revert Exclude BNB from receive currencies list [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

83/100 · StrongMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
explicit security languagememory safetysigning or wallet path
AI analysis · Moderate 64/100

This update improves protections in the Cake Wallet app against fake or scam tokens. It adds checks that automatically flag tokens pretending to be well-known coins (like fake USDC or fake ETH) using look-alike characters, and it disables low-value or suspicious tokens when wallets are imported. The changes are defensive and reduce the chance that users are tricked into trusting scam tokens.

Security candidateGeneric Token Fixes (#2873)by David Adegoke · fa5149af · Feb 7, 2026 · 3 filesMessage 71 · AdequateModerate 63Details
Commit message · David Adegoke

Generic Token Fixes (#2873)

* feat: Automatically detect wallet tokens for EVM chains

* feat: Disable potential tg scam tokens by default

* feat: Add homoglyph normalization to detect spoofing attacks in token symbols

* refactor: Improve scam token detection and apply to automatically fetched EVM tokens

* refactor: Enhance scam detection for automatically detected tokens in evm wallets

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Enable whitelisted tokens with balance when importing wallet tokens

* feat: Disable imported tokens with balance less than 0.1 usd

* feat: Disable imported tokens with balance less than 0.1 usd
- Update configure file

* fixes:
- default tokens marked as potential scam
- ui overflow for token name on balance page
- add more filters for spam tokens

71/100 · AdequateMessage clarity
✓ Descriptive subject✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
explicit security languagememory safetysigning or wallet path
AI analysis · Moderate 63/100

This commit improves protections in Cake Wallet against scam or fake tokens on EVM blockchains. It tightens how the app decides a token looks suspicious, adds more spam keywords (like 'reward', 'claim', 'airdrop'), checks whether a token is pretending to be the chain's native coin (e.g., a fake 'ETH' on Ethereum), and disables low-value or suspicious tokens when wallets are imported. It also fixes a minor screen layout issue where long token names could overflow.

Security candidatefeat: zashi zkool sweep, and minor fixes (#2838)by cyan · d8a67660 · Feb 6, 2026 · 59 filesMessage 80 · StrongLow 32Details
Commit message · cyan

feat: zashi zkool sweep, and minor fixes (#2838)

feat: restore from keys zcash
fix: don't display empty keys

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Low 32/100

This commit adds a feature to Cake Wallet that helps Zcash users recover funds that may be hidden on internal change addresses (a known issue with some wallets like Zashi). It also adds the ability to restore a Zcash wallet from a private key instead of only from a seed phrase, and makes several small UI and error-message improvements. There is no clear security vulnerability in the diff itself; the changes appear to be defensive/recovery functionality.

Security candidateCW-1228: Automatically Fetch All Tokens (#2869)by David Adegoke · 4ae94db3 · Feb 5, 2026 · 4 filesMessage 76 · AdequateModerate 53Details
Commit message · David Adegoke

CW-1228: Automatically Fetch All Tokens (#2869)

* feat: Automatically detect wallet tokens for EVM chains

* feat: Disable potential tg scam tokens by default

* feat: Add homoglyph normalization to detect spoofing attacks in token symbols

* refactor: Improve scam token detection and apply to automatically fetched EVM tokens

* refactor: Enhance scam detection for automatically detected tokens in evm wallets

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Enable whitelisted tokens with balance when importing wallet tokens

* feat: Disable imported tokens with balance less than 0.1 usd

* feat: Disable imported tokens with balance less than 0.1 usd
- Update configure file

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
explicit security languagesigning or wallet path
AI analysis · Moderate 53/100

This commit changes how Cake Wallet automatically finds and displays Ethereum-compatible tokens in a user's wallet. Previously, the app likely added discovered tokens more readily. Now it applies several safety filters: tokens flagged as possible spam by the data provider, tokens with suspicious properties, tokens without a valid USD price, and tokens worth less than about 10 cents are disabled by default. The change also fixes a chain-name label for BNB Smart Chain and adds a helper that carries token balances through the discovery process so the app can check the dollar value. Overall this is a defensive, anti-scam improvement rather than a vulnerability fix.

Security candidateCW-1228: Automatically detect wallet tokens for EVM chains (#2827)by David Adegoke · 4f8cccce · Feb 5, 2026 · 8 filesMessage 81 · StrongModerate 50Details
Commit message · David Adegoke

CW-1228: Automatically detect wallet tokens for EVM chains (#2827)

* feat: Automatically detect wallet tokens for EVM chains

* feat: Disable potential tg scam tokens by default

* feat: Add homoglyph normalization to detect spoofing attacks in token symbols

* refactor: Improve scam token detection and apply to automatically fetched EVM tokens

* refactor: Enhance scam detection for automatically detected tokens in evm wallets

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Enable whitelisted tokens with balance when importing wallet tokens

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
explicit security languagesigning or wallet path
AI analysis · Moderate 50/100

This commit adds a feature that automatically finds and lists Ethereum-compatible tokens a user owns, then tries to protect them from scam tokens. It fetches token data from an external service (Moralis), marks tokens as suspicious if their names/symbols contain scammy keywords or mimic well-known coins using look-alike letters (like Cyrillic or Greek characters), and disables tokens that fail a fiat price check. The change is primarily a defensive security improvement, but it also introduces new code paths that handle external data and user balances, which carry some risk if the checks can be bypassed or the external service is untrusted.

Security candidateCW-1368: Add Binance Smart Chain (#2836)by David Adegoke · 308de038 · Feb 5, 2026 · 103 filesMessage 76 · AdequateInformational 20Details
Commit message · David Adegoke

CW-1368: Add Binance Smart Chain (#2836)

* feat: Add Binance Smart Chain support to wallet types and EVM chain registry

* feat: Add BSC node list and support in wallet type and chain ID mappings

* feat: Add BSC default tokens and update evm utility functions

* feat: Integrate BSC support in node settings and management

* feat: Add BSC support to config scripts and wallet type generation

* feat: Add BSC support to EVM chain ID and switcher

* feat: Extend BSC support in wallet utilities and chain type checks

* feat: Add BSC support to different wallet functions

* feat: Add BSCURI class and implement for uri handling

* feat: Update Android and iOS configurations to support BSC URL schemes

* feat: Add BSC support to different functionalities and settings

* refactor: Update wallet type name from'Binance Smart Chain' to BNB Smart Chain

* feat: Add switcher icon and updates token utils

* Review fixes

* More changes to BSC name, wallet listing and images

* Add more default tokens

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive pathseed or entropy pathsigning or wallet path
AI analysis · Informational 20/100

This commit adds support for the BNB Smart Chain (BSC) to the Cake Wallet app. It is a feature addition that introduces a new EVM-compatible blockchain alongside existing Ethereum, Polygon, Base, and Arbitrum support. There is no indication in the commit that this is a security fix or that it addresses any vulnerability. The changes are broad but routine: new wallet type, chain ID mappings, default nodes, default tokens, transaction handling, UI icons, URL schemes, and localization strings.

Security candidatefix: update icon for Arbitrum currency (#2817)by David Adegoke · ad50fb04 · Jan 19, 2026 · 1 fileMessage 65 · AdequateInformational 15Details
Commit message · David Adegoke

fix: update icon for Arbitrum currency (#2817)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit simply swaps the image file used for the Arbitrum cryptocurrency icon from an old PNG to a new WebP file. It is a cosmetic user-interface change with no security relevance.

Security candidateYwallet zcash (#2810)by Omar Hatem · ef9b0fba · Jan 16, 2026 · 141 filesMessage 71 · AdequateLow 32Details
Commit message · Omar Hatem

Ywallet zcash (#2810)

* feat(zcash): initial commit
- initial work on cw_zcash
- use single .db for everything zcash to speed up sync and scanning
- implement silent autoshielding of non-orchard funds
- use FFI for everything to fetch the data
- add support for passphrase by adding extra word to seed phrase
- enforce lints on CI for cw_zcash directory
- use correct zcash name, and call transparent zcash tZEC
- minor cleanups outsite of cw_zcash
- gitmodules, gitignore
- db debug
- fix broken addressPageType in WalletInfo
- enable debug options in kDebugMode and kProfileMode

* feat: T address rotation (and cache) wip: minor fixes

* wip: shield tx list

* fix fiat amounts fix derrivation of rotation account addresses screen
for zcash block height fix T address shields improvements Amount in
disposable T shields UI improvements
show pending outgoing tx in tx history

* fix null check on passphrase page fix tx showing as pending rename auto
shield txs fixed send all to include fee use rotating address in
addressForExchange wrap all calls of WarpApi.getLatestHeight in try
catch to prevent leaking errors

other minor fixes from notion

* wallet group debug cache sent tx address wallet T address rotation fixes
automatically pick the fee for auto-shield

* fix T address cache deserialization fix autoshield icon fix autoshield
text getCachedDestinationAddress fix send address cache

* address comments from review

* wip: iOS fix

* fix swap

* Allow cakepay payment from zcash wallet

* fix: ios (I'm stupid) fix: reorder addresses to make orchard default
fix: send all balance

* 5.6.6 bump fix: ios apple review add transport error to ignored
exceptions

* fix: leaving dust behind when sweeping all

* Change wallets order

* fix: reflect balance of pending out txs fix: restore height support

* linux support (disabled)

* fix: date picker for zcash on restore screen fix: build script for linux
match WarpApi.warpSync args with upstream

* fix: linter script

* ensure all exchange providers support ZEC (#2802)

* ensure all exchange providers support ZEC

* remove zaddr and tzec currencies and refactor providers

* Update lib/exchange/provider/near_Intents_exchange_provider.dart

* add back old zcash currencies for backward compatibility, thanks Czarek

* minor fix [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* Update android/app/src/main/AndroidManifestBase.xml [skip ci]

* Update ios/Runner/InfoBase.plist [skip ci]

* fix: remove unused code fix: macos fix: disable on linux and macos

* update build numbers [skip ci]

* Add zcash to birdpay

---------

Co-authored-by: Czarek Nakamoto <cyjan@mrcyjanek.net>
Co-authored-by: Serhii <borodenko.sv@gmail.com>

71/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference
Why it was queued
secret or key materialaccess controlcryptography-sensitive pathseed or entropy pathsigning or wallet path
AI analysis · Low 32/100

This is a large feature commit that adds Zcash wallet support to Cake Wallet. It introduces a new cw_zcash package, integrates the Warp FFI library, adds transparent address rotation, auto-shielding, and exchange/CakePay support. The commit itself is a feature addition, not a disclosed security fix. There are some code-quality and potential operational-security concerns (hardcoded fee values, debug code left in release paths, unhandled exceptions swallowed, and a custom CRC32-based seed derivation for disposable addresses), but no direct vulnerability is demonstrated in the diff.

Security candidateCW-1250: Refactor L2 Chains Code (#2677)by David Adegoke · 2a77d359 · Jan 16, 2026 · 251 filesMessage 98 · StrongLow 44Details
Commit message · David Adegoke

CW-1250: Refactor L2 Chains Code (#2677)

* feat(evm): add ChainConfig model and related classes

- Add ChainConfig class for immutable EVM chain configuration
- Add ChainCapabilities class for chain feature flags
- Add FeeType enum and FeeModel class for fee configuration

* feat(evm): add EvmChainRegistry for centralized chain management

- Add singleton EvmChainRegistry class with chain configuration storage
- Initialize with Ethereum, Polygon, Base, and Arbitrum chains
- Add mappings for WalletType, tag, and CAIP-2 to chainId lookups
- Provide lookup methods for chain configurations by various identifiers
- Support for querying available chains and registered chain IDs

* feat(evm): add EVMChainClientFactory and consolidate chain clients

- Create EVMChainClientFactory for creating chain-specific clients based on chainId
- Move all chain clients (EthereumClient, PolygonClient, BaseClient, ArbitrumClient) into cw_evm/lib/clients/ folder
- Refactor EVMChainClient from abstract to concrete class with default implementations
- Add default implementations for fetchTransactions, fetchInternalTransactions, and prepareSignedTransactionForSending
- Update all client classes to use super(chainId: X) constructor pattern
- Factory returns EVMChainClient directly for unregistered chains instead of throwing
- Remove dependencies on cw_ethereum, cw_polygon, cw_base, cw_arbitrum packages from pubspec.yaml
- Consolidate all EVM chain client implementations in one location for easier maintenance

* add ui for evm switcher on eth

* add inputs for evm network list edit switches

* refactor(evm): Make EVMChainWallet concrete and unify transaction classes
- Make EVMChainWallet and EVMChainWalletBase concrete classes (removed abstract)
- Implement all previously abstract methods in EVMChainWallet
- Make EVMChainTransactionInfo and EVMChainTransactionHistory concrete
- Reorganize default tokens into tokens/ folder:
- Refactor EVMChainDefaultTokens to import and use token classes from tokens/ folder
- Move clients to clients/ folder:
- Move evm_chain_formatter.dart to utils
- Update chain-specific transaction history classes to pass walletType to fromJson
- Update old wallet classes (EthereumWallet, PolygonWallet, etc.) to pass walletType
- Maintain compatibility with existing per-chain wallet classes

This refactoring enables the unified EVMChainWallet architecture while maintaining
full backward compatibility with existing per-chain wallet implementations.

* feat(evm): Add chain selection capability to EVMChainWallet
- Add selectedChainId observable field to track currently selected chain
- Add selectChain(chainId) action method to switch between EVM chains
- Add selectedChainConfig computed getter for accessing chain configuration
- Initialize selectedChainId from client.chainId in constructor
- Add _getClientForCurrentChain() helper method for future use

This enables chain switching functionality while maintaining full backward compatibility. The selectedChainId is initialized from the existing client, and all existing methods continue to work unchanged. Future increments will update methods to use selectedChainId internally.

* refactor(evm): Update client immediately on chain selection

- Update selectChain() to immediately create new client for selected chain
- Remove _getClientForCurrentChain() helper method
- Simplify all methods to use _client directly instead of helper calls
- Client is now always in sync with selectedChainId

This improves code simplicity and performance by eliminating repeated
client checks. The client is updated synchronously when selectChain()
is called, ensuring state consistency.

* featr(evm): Add unified evm proxy setup and fix chain initialization

- Add unified Evm proxy
- Add evm.dart to .gitignore for generated proxy
- Add generateEVM() to configure.dart for proxy generation
- Fix selectedChainId to initialize from registry based on walletInfo.type

Ensures selectedChainId always matches wallet type on initialization
and adds unified proxy infrastructure.

* refactor(evm): Update backward compat helpers to use registry via proxy

- Add registry helper methods to unified EVM proxy
- Update all lib/ files to use proxy instead of direct cw_evm imports
- Enforce proxy pattern: no direct imports from cw_evm in main app
- Update configure.dart to include registry methods in generated proxy

Maintains backward compatibility while centralizing chain data access
through the unified proxy pattern.

* feat(evm): Add chain selection UI to dashboard

- Add chain selection methods to DashboardViewModel (isEVMWallet,
availableChains, currentChain, selectChain)
- Add chain dropdown widget to balance page for EVM wallets
- Dropdown shows current chain and allows switching between all
registered EVM chains
- Only visible for EVM-compatible wallets
- Add chain selection methods to EVM proxy (getAllChains,
getCurrentChain, selectChain)

Users can now switch between EVM chains (Ethereum, Polygon, Base,
Arbitrum) directly from the dashboard without creating separate wallets. All chain-related code follows the established proxy pattern.

* feat(evm): Add persistence for selected chain ID

- Add initialChainId parameter to EVMChainWallet constructor
- Save selectedChainId to wallet JSON in toJSON() method
- Load selectedChainId from JSON in open() method
- Handle backward compatibility: wallets without saved chain ID use
wallet type's default chain ID
- Client is created with saved chain ID when opening wallet

Selected chain preference is now persisted across app sessions. Users will see their previously selected chain when reopening wallets.

* chore: Minor cleanup

* refactor(evm): Remove old per-chain packages, consolidate to unified cw_evm

- Delete cw_ethereum, cw_polygon, cw_base, cw_arbitrum packages
- Remove old proxy files (lib/ethereum/, lib/polygon/, lib/base/, lib/arbitrum/)
- Update all view models to use unified evm! proxy
- Move DEuro functionality to cw_evm/lib/deuro/
- Remove dependencies from pubspec.yaml and configure.dart
- Remove walletType parameter from EVM proxy methods

All EVM chains now use unified cw_evm package through single proxy interface. lib/ only depends on cw_evm, simplifying architecture and enabling easy addition of new L2 chains.

BREAKING CHANGE: Old per-chain packages removed

* refactor(evm): Update wallet handling to use unified EVM proxy

- Replace individual chain imports (Ethereum, Polygon, Base, Arbitrum) with a single EVM proxy import.
- Refactor wallet-related methods across various view models to utilize the new evm proxy for various usecases.

This change enhances code maintainability and prepares the codebase for the addition of new EVM chains.

* refactor(evm): Update model generator and enhance EVM classes

- Modify model_generator.sh to remove previous chain folders from the loop.
- Change EVMChainTransactionHistoryBase and EVMChainWalletBase classes to be abstract.
- Update import paths in configure.dart to reflect the new structure of the cw_evm package.

* add evm switcher icons to pubspec_base

* change evm switcher to sliding animation

* formatting fix

* dpi agnostic width

* feat(evm): Enhance chain handling and transaction history management

- Introduce getCurrentChainId function to EVMChainTransactionHistoryBase for dynamic transaction history file naming based on the current chain ID.
- Update EVMChainTransactionInfo to include chainId, ensuring accurate transaction data representation.
- Refactor EVMChainWalletBase to support automatic node connection and transaction history loading upon chain selection.
- Implement saveBackup and restoreWalletFilesFromBackup methods in EVMChainWalletService to manage wallet backups based on wallet type.
- Update various methods across the codebase to accommodate the new chain handling logic, improving overall functionality and user experience.

* chore: Cleanups and updates

* feat: add WalletType.evm and deprecate individual EVM chain types

Add unified WalletType.evm enum value for all EVM-compatible chains.
Deprecate old individual EVM types (ethereum, polygon, base, arbitrum)
with guidance to use WalletType.evm for new code.

Update serialization/deserialization functions to support WalletType.evm:
- serializeToInt() returns 18 for WalletType.evm
- deserializeFromInt() handles case 18
- walletTypeToString() and walletTypeToDisplayName() return 'EVM'
- cryptoCurrencyToWalletType() maps all EVM currencies to WalletType.evm

Old EVM types remain functional for backward compatibility with existing
wallets. This is the foundation for unifying EVM chain management.

* feat: update EVM detection functions to support WalletType.evm

Update all EVM detection and chain helper functions to support the unified WalletType.evm while maintaining backward compatibility with old EVM types.

All functions require chainId parameter when used with WalletType.evm, ensuring proper chain-specific behavior. Old EVM types continue to work without changes for backward compatibility.

* feat: add currency mapping support for unified EVM wallet type

- Update currency mapping to support WalletType.evm with chainId-based currency resolution.
- Override EVMChainWallet.currency getter to use selectedChainId from registry.
- Replace walletTypeToCryptoCurrency calls with wallet.currency in view models.
- Add WalletType.evm cases to switch statements and consolidate EVM transaction list item methods.
- Add explorer URL method to EVM interface

* feat: Update wallet operations with unified WalletType.evm

- Update wallet service to always create new wallets and restores with WalletType.evm, defaulting to Ethereum.
- Preserve old wallet types when opening existing wallets. Update wallet instance creation and opening logic to handle unified EVM type with chainId-based config lookup.

* Add WalletType.evm support across all switch statements
- Update all switch statements and conditionals to include WalletType.evm alongside existing EVM types.
- Add chainId-based node selection support for unified EVM wallets. - Fix redundant code in exchange view model.
- Ensure backward compatibility with old EVM wallet types.

* feat(evm): Implement chainId-based node management for WalletType.evm

- Add chainId-based node storage for unified EVM wallets, enabling separate node preferences per chain.
- Replace unsafe dynamic casts with type-safe getSelectedChainId method. Update all node retrieval and switching logic to support chainId-based selection.

* feat: Update UI components to show unified EVM wallet option

- Filter out old EVM wallet types (ethereum, polygon, base, arbitrum) from wallet creation and restore UI, showing only unified WalletType.evm option.
- Update wallet type generation to include WalletType.evm instead of individual
chain types.
- Update configure.dart to generate WalletType.evm in availableWalletTypes
- Add filtering checks to prevent old EVM types from appearing

* fix: Fix WalletType.evm support and complete remaining edge cases

Add missing WalletType.evm cases to switch statements to resolve compilation
errors. Complete remaining unification items:

- Add WalletType.evm support to node, wallet utils, and view models
- Update EVMChainDefaultTokens and EVMChainUtils to support chainId
- Fix token initialization and priority fee calculations for WalletType.evm
- Update payment view model to handle WalletType.evm with chainId

All identified edge cases from the unification plan are now complete.

* fix: Fix network switching issues for EVM wallets
- Fix null check errors when creating and restoring an EVM wallet
- Fix null check errors for balance getter when switching networks
- Fix fiat amount display for native currencies in transaction history

* refactor: Simplify EVM wallet chain selection in CryptoBalanceWidget

- Removed the old dropdown for chain selection and replaced it with a more integrated EvmSwitcher dialog.
- Updated EvmSwitcher to accept a list of available chains and handle chain selection more efficiently.
- Enhanced EvmSwitcherDataItem to include chainId for better identification of chains.
- Improved the overall UI flow for EVM wallet interactions.

* refactor: Enhance EVM wallet handling and chainId integration

- Simplified chainId checks across various components to ensure consistent handling for WalletType.evm.
- Updated EVMChainDefaultTokens and EVMChainUtils checks to allow all EVM wallets for chainId operations
- Handled backward compatibility for older wallet types in transaction info

* refactor: More enhancement and backward compatibility fixes for EVM Wallet

- Introduced a new method to retrieve cryptocurrency by chainId, improving the handling of WalletType.evm.
- Updated transaction history management to filter transactions based on the current chainId
- Refactored EVMChainTransactionInfo to accept chainId directly
- Modified utility functions in EVMChainUtils and TokenUtilities for better chainId handling

* refactor: Streamline EVM token retrieval and enhance chainId handling

* feat: Introduce comprehensive guide for adding new EVM L2 networks

- Added a detailed documentation file outlining the steps to integrate new EVM-compatible L2 networks into Cake Wallet.
- Included prerequisites, architecture overview, and a step-by-step guide covering chain configuration, native currency addition, default tokens, and node setup.
- Emphasized the unified architecture for EVM chains and backward compatibility considerations.
- Removed the outdated guide on adding new L2 networks to streamline documentation.

* feat: Reposition EVM switcher button on dashboard page

* just adding reminders for the refactoring [skip ci]

* more todos [skip ci]

* feat: enhance wallet functionality with chainId support

- Added chainId to `WalletBase` and updated currency method to use it.
- Modified EvmChainRegistry to initialize registry on call.
- Updated various components to pass chainId where necessary for currency conversions.
- Improved handling of chain IDs in wallet-related view models and UI components for better compatibility with EVM networks.

* fix: remove default chainId fallback in payment confirmation widget

* feat: Adapt anypay to new unified flow WIP

* fix: Issues with handling non evm swaps for anypay

* fixes to flow structure

* Add persistence to hidden chains on switcher

* refactor: simplify equality operator in Erc20Token class

* feat: add excluded arbutrum tokens for chainflip

* chore: Remove print statement [skip ci]

* refactor: dispaly QR image display for evm based on selected chain ID

* feat: enhance EVM wallet compatibility check for raw address input

* chore: Update doc to reflect changes [skip ci]

* feat: Integrate Blink for EVM wallets for anti-sandwich attacks.

- Add toggle in privacy settings to enable/disable
- When enabled, route all evm broadcast rpc calls via Blink

* feat: Integrate Blink for EVM wallets for anti-sandwich attacks.

- Add toggle in privacy settings to enable/disable
- When enabled, route all evm broadcast rpc calls via Blink

* feat: Integrate Blink for EVM wallets for anti-sandwich attacks.

- Add toggle in privacy settings to enable/disable
- When enabled, route all evm broadcast rpc calls via Blink

* feat: Handle same chainId scenario for pasted evm addresses

* feat: Add Blink Setting to Advanced Settings Page

* fix: Handle Blink supported chains

* fix: Fixes to evm swap

* fix: Add fallback for currency fetch

* fix: Add evm to supported list

* fix: Better handle balance errors

* fix: Update token check to use contract address comparison, resolves the usdt/usdt0 issue

* refactor: Simplify checks by cearing all tokens on chain switch, removing unnecessary currency checks

* fix: Simplify checks based from feedback on review

* fix: Exclude arbitrum from tx priority using chainId

* refactor: Handle chains not having transaction priority within refactor

* fix: Unified evm wallet fixes
- Handle switching networks while on tx history page
- Update NFTs when network is switching on listing page
- Fix arbitrum tx priority error on swap screen
- Switch check to display deuro from wallet type to chainId
- Add fallback check for getting token info for evm
- Better error message for max fee per gas less than block base fee error

* refactor: Update wallet checks from type to chainId for EVM compatibility checks

* refactor: Update eth chain utils and remove verified contract criteria in scam detection checks

* refactor: Enhance validation for deuro calls

* fix : Remove unneeded validation check for savings edit

* feat: Hide EVM chain switcher behind feature flag

* refactor: Remove EVM wallet type references and update related logic

* chore: Clean up wallet type references and remove repeated imports

* feat: Add fallback for derivation path and add arbitrum support to app scripts

* fix: NFT popup error

* fix: Transaction details fee regression

* fix: Fixes and improvements
- Add nonce parameter to transaction methods in EVM clients
- Remove brackets for create swaps
- Display contacts for selected wallettype alone
- Remove tx priorty switching for arb

* feat: Enhance Arbitrum support across swap providers

* fix: Add missing secret keys

* fix: display sending currency icon in send from external page

* refactor: Handle arbitrum edgecase for wallet list display image

* fix: Handle more cases of arbitrum image display for contact book

* exploring possible issues with tx history

* chore: switch to printV

* fix: Add an extra check for keys

* fix: Filter out eth spam transaction and modify parsing format

* fix: Handle contract decimals for sending tokens

* fix: Display proper balance error

* Update cw_evm/lib/utils/evm_chain_formatter.dart [skip ci]

---------

Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

98/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
explicit security languagesecret or key materialcryptography-sensitive pathseed or entropy pathsigning or wallet pathboot or update path
AI analysis · Low 44/100

This is a large code-refactoring commit that consolidates Ethereum and L2 chain support (Ethereum, Polygon, Base, Arbitrum) into a single unified EVM package. It also adds a new optional privacy feature called Blink that routes EVM transaction broadcasts through a third-party service. The commit is primarily an architectural refactor with many file moves and deletions, plus new UI for switching EVM chains. There is no explicit vendor statement that this fixes a security vulnerability, and the diff alone does not show a clear exploitable bug, but the scope and new RPC routing warrant careful review.

Security candidatefix seed page on desktop (#2752)by malik1004x · c7e9a4e6 · Dec 19, 2025 · 1 fileMessage 53 · ThinInformational 18Details
Commit message · malik1004x

fix seed page on desktop (#2752)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
seed or entropy path
AI analysis · Informational 18/100

This commit adjusts how many seed-phrase word tiles are shown per row on desktop screens. It adds an upper limit of four tiles per row so the seed-phrase display does not stretch too wide on large monitors. There is no security change here; it is purely a user-interface layout fix.

Security candidateadd save as dialog for seed on desktop (#2753)by malik1004x · fb6054cb · Dec 19, 2025 · 1 fileMessage 53 · ThinLow 26Details
Commit message · malik1004x

add save as dialog for seed on desktop (#2753)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Low 26/100

This commit changes how users save their wallet recovery seed on desktop computers. Previously, the app used a generic share feature. Now it opens a 'Save As' dialog and writes the seed to a plain text file named after the wallet. The seed is still shown on screen and handled by the app, so this is mainly a usability change, not a fix for a known security flaw. However, saving a seed as a plain text file on a desktop can increase the risk that the seed is accidentally left in an easy-to-find location.

Security candidatefix: handle unexpected ViewModel in ledger connection process (#2716)by Konstantin Ullrich · f122ce0c · Dec 12, 2025 · 3 filesMessage 93 · StrongLow 29Details
Commit message · Konstantin Ullrich

fix: handle unexpected ViewModel in ledger connection process (#2716)

* fix: handle unexpected ViewModel in ledger connection process

* fix: add missing exception handler for `_QueuedFuture.execute` in `exception_handler.dart`

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathauthentication path
AI analysis · Low 29/100

This commit fixes a bug in the Cake Wallet app's process for connecting Ledger hardware wallets. Previously, if the app received an unexpected type of screen data (not a LedgerViewModel), it would silently skip a safety check and still try to proceed, which could lead to a crash or undefined behavior. The fix shows an error message and stops instead. It also adds a missing Bluetooth queue error to a list of known harmless exceptions so the app doesn't wrongly report it as a bug.

Security candidatefeat: implement silent payment derivation paths and master HD wallet integration (#2708)by Konstantin Ullrich · 89863e3b · Dec 11, 2025 · 4 filesMessage 93 · StrongLow 29Details
Commit message · Konstantin Ullrich

feat: implement silent payment derivation paths and master HD wallet integration (#2708)

* feat: implement silent payment derivation paths and master HD wallet integration

- Added default derivation paths for silent payments (mainnet and testnet).
- Introduced `_masterHD` for handling seed-based key derivations.
- Updated silent payment address record to include spend derivation path.
- Refactored UTXO handling and scanning logic to support multiple receivers with unique derivation paths.
- Improved logging for better debugging of silent payment workflows.

* refactor: remove debug prints

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
secret or key materialsigning or wallet path
AI analysis · Low 29/100

This commit adds support for Bitcoin "silent payments" in Cake Wallet. It introduces new derivation paths for scanning and spending, stores a spend derivation path on each silent payment address record, and changes how private keys are derived when spending silent-payment UTXOs. The change is a feature implementation/refactor rather than a clearly labeled security fix. There is no direct evidence in the commit that it fixes an active vulnerability, but it touches sensitive key-derivation and UTXO-handling code, so correctness matters for funds safety.

Security candidatefix race condition in deep link loading (#2709)by malik1004x · f0dd95ff · Dec 8, 2025 · 2 filesMessage 53 · ThinLow 45Details
Commit message · malik1004x

fix race condition in deep link loading (#2709)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 45/100

This commit fixes a race condition in how the app handles deep links (special URLs that open the app from outside, like payment requests or WalletConnect connections). Before the fix, the app might try to act on a deep link before the wallet dashboard was fully loaded, which could cause the link to be ignored or processed in the wrong state. The fix adds a flag that delays deep-link handling until after the main wallet page is ready. There is no direct evidence in the commit that this was exploitable as a security vulnerability, but race conditions in deep-link handling can sometimes be abused to redirect users or trigger unintended actions.

Security candidatequick fixes for swap logic across providers (#2702)by Serhii · bad88e9c · Dec 3, 2025 · 6 filesMessage 81 · StrongLow 35Details
Commit message · Serhii

quick fixes for swap logic across providers (#2702)

* fix currency matching and network mapping

* add support for Arbitrum

* Update lib/exchange/provider/exolix_exchange_provider.dart [skip ci]

* Update lib/exchange/provider/exolix_exchange_provider.dart [skip ci]

---------

Co-authored-by: Serhii-Borodenko <17529954+Serhii-Borodenko@users.noreply.github.com>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive path
AI analysis · Low 35/100

This commit fixes how Cake Wallet matches currencies and blockchain networks when displaying swap/exchange transactions from several third-party exchange providers. Before the fix, mismatched capitalization or inconsistent network names (for example 'Arbitrum' vs 'ARB') could cause the app to fail to identify the correct currency or network. This is a bug-fix patch that reduces the chance of user confusion or incorrect transaction details, but it does not appear to be a direct exploit fix. The commit also adds support for the Arbitrum network.

Security candidateImprove seed grid sizing (#2687)by tuxsudo · 1d715d39 · Dec 1, 2025 · 1 fileMessage 68 · AdequateInformational 15Details
Commit message · tuxsudo

Improve seed grid sizing (#2687)

* Attempt to improve seed grid layout and sizing

* Cleanup

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
seed or entropy path
AI analysis · Informational 15/100

This commit adjusts how a wallet's recovery seed phrase is displayed on screen. It makes the grid of seed words resize automatically based on screen width and tweaks text wrapping and line spacing so the words fit better. There is no security-relevant change here.

Security candidatefix: crypto amount calculation logic with max decimals (#2697)by Konstantin Ullrich · 86f30a21 · Dec 1, 2025 · 2 filesMessage 93 · StrongLow 33Details
Commit message · Konstantin Ullrich

fix: crypto amount calculation logic with max decimals (#2697)

* fix: crypto amount calculation logic with max decimals

* refactor: remove `_setCryptoNumMaximumFractionDigits` and `_cryptoNumberFormat` to simplify `OutputBase` logic

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive path
AI analysis · Low 33/100

This commit changes how Cake Wallet converts a fiat amount into a crypto amount when a user is sending funds. Previously, the app used a shared number formatter whose decimal precision was set per wallet type. Now it uses the currency's own configured decimal count. The change also adds helper methods for converting between whole-coin and smallest-unit amounts elsewhere in the code. The main risk is that a wrong number of decimal places could cause displayed or calculated amounts to be rounded, potentially leading users to send slightly more or less than they intended, or to misread the value.

Security candidateLCW-1144 cupcake litecoin (#2557)by cyan · 77812016 · Nov 24, 2025 · 26 filesMessage 76 · AdequateLow 37Details
Commit message · cyan

LCW-1144 cupcake litecoin (#2557)

* Add psbt rpcs

* Only build arm64

* Rebuild protos

* Update proto

* Add psbt create rpc

* Restore wallet stuff

* more stuff

* more stuff

* more stuff

* Fix open wallet

* Fix mweb enabled

* Start of buildPsbt

* Update proto

* Psbt add recipients

* fixes

* slightly better

* more fixes

* decode ur

* add more commit code

* Update proto

* use new proto

* Don't eat psbt rpc errors

* Use unix domain socket for mwebd

* add gitignore

* Undo build only arm64

* fix pure mweb txns

* fix mweb txids

* fix ci

* fix blank pegin address

* chore: update cw_mweb dependencies
chore: remove cw_core as dependency from cw_mweb

* fix: Ltub restore

* fix: address review crashes, fix non-mweb view only wallets

* minor fixes

---------

Co-authored-by: Hector Chu <hectorchu@gmail.com>
Co-authored-by: OmarHatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarysigning or wallet path
AI analysis · Low 37/100

This commit adds new Litecoin MWEB (privacy feature) wallet capabilities to Cake Wallet, including restoring wallets from extended public keys and handling special PSBT (partially signed Bitcoin-like) transactions. It also upgrades several Go dependencies and switches the local MWEB service from a network port to a Unix domain socket. There is no clear security bug, but the changes touch sensitive wallet code and key handling, so they deserve careful review.

Security candidateShow fiat amount for tokens on swipe confirmation sheet (#2670)by malik1004x · 66a8e895 · Nov 22, 2025 · 2 filesMessage 81 · StrongInformational 17Details
Commit message · malik1004x

Show fiat amount for tokens on swipe confirmation sheet (#2670)

* fix: fiat amount not showing for tokens on the swipe to send confirmation sheet

* fix: fiat amount not showing for tokens on the swipe to send confirmation sheet

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive path
AI analysis · Informational 17/100

This commit fixes a UI bug where the estimated fiat (e.g., USD) value of token payments was not shown on the 'swipe to confirm' send screen. It adds a helper to match currencies by both name and network tag, then uses that match to look up the correct exchange price. There is no direct evidence this is a security vulnerability; it appears to be a user-experience fix that could indirectly prevent user confusion or transaction mistakes.

Security candidateCW-1290-Add-Duress-pin-feature (#2664)by Serhii · 1b354c70 · Nov 22, 2025 · 41 filesMessage 76 · AdequateLow 37Details
Commit message · Serhii

CW-1290-Add-Duress-pin-feature (#2664)

* add duress PIN feature

* add localization

* Update configure.dart

* Update configure.dart

* add duress PIN validation logic

* - fix error popup
- put behind a feature flag

---------

Co-authored-by: OmarHatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access controlauthentication path
AI analysis · Low 37/100

This commit adds a 'duress PIN' feature to Cake Wallet. It lets users set a second PIN that, if entered instead of the normal PIN, silently wipes all local wallet data, resets the app, and sends the user back to the welcome screen. The feature is meant to protect users who are forced to unlock their wallet under threat. The code includes checks to stop the duress PIN from being the same as the regular PIN, shows warnings before setup, and is hidden behind a feature flag that is currently turned on.

Security candidateCw 1294 fix xo swaps bug (#2645)by Serhii · c552ab86 · Nov 21, 2025 · 10 filesMessage 76 · AdequateModerate 58Details
Commit message · Serhii

Cw 1294 fix xo swaps bug (#2645)

* Improve currency parsing with tag support

* changenow currency parsing fix

* exolix currency parsing fix

* letsExchange currency parsing fix

* stealth currency parsing fix

* trocador currency parsing fix

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Moderate 58/100

This commit fixes how the Cake Wallet app figures out which cryptocurrency a user is sending or receiving during swaps. Before the fix, the app could confuse coins that share the same name but live on different blockchains (for example, USD Coin on Ethereum versus USD Coin on Polygon). That confusion could lead to the app picking the wrong wallet balance, building an incorrect transaction, or showing the user the wrong asset. The fix adds 'tag' support so the app can tell these similar coins apart, and it also improves error handling when a coin isn't enabled in the wallet.

Security candidateCW-1208: Pay Anything EVM enahancements (#2600)by David Adegoke · 238022c4 · Nov 11, 2025 · 43 filesMessage 76 · AdequateLow 34Details
Commit message · David Adegoke

CW-1208: Pay Anything EVM enahancements (#2600)

* feat: Pay Anything EVM enahancements

* ifx: Add baseEth to address validator switch case

* fix: Error detecting other wallet types

* feat: Preserve QR amount and other data through evm chain selection flow

* Update container color to surfaceContainer

* feat: Add support for Bitcoin Lightning Network detection

- Identify Base QR codes when scanned
- Display all available currencies for network
- Enhance detector to recognize lightning addresses

* fix: Update token selection for currently selected wallet

* fix: Improve token matching logic for EVM networks

* feat: Update selected currency when wallet is switched

* ui: Add chain badge to the swap confirmation bottomsheet

* fix: Asks to switch wallets even if the current wallet type is the same as the QR. Fix merge conflicts too

* fix: Handle matching logic internally and general cleanups

* fix: Terminate flow if address is not a valid parsed address

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>
Co-authored-by: tuxsudo <tuxsudo@tux.pizza>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Low 34/100

This commit adds user-facing features to Cake Wallet for handling EVM (Ethereum-like) addresses and Bitcoin Lightning payments. It lets users pick which EVM network and token to use when scanning a generic 0x address, improves token matching, and adds detection for Lightning invoices, Lightning email-style addresses, and LNURL codes. There is no clear security bug in the diff, but the new address-detection logic is broad and could misclassify ordinary email addresses as Lightning payment addresses, which might confuse users or lead to incorrect payment flows.

Security candidateCW-1194-Add-Arbitrum-Wallet (#2587)by David Adegoke · 2da3ba57 · Nov 5, 2025 · 129 filesMessage 98 · StrongLow 34Details
Commit message · David Adegoke

CW-1194-Add-Arbitrum-Wallet (#2587)

* feat: initialize cw_arbitrum package with essential files

- Implement ArbitrumClient for transaction handling
- Add ArbitrumWallet and related classes for wallet management
- Establish transaction history and info classes for Arbitrum transactions
- Add ArbitrumWalletService for wallet operations and management

* feat: Add arbitrum related secrets to workflow

* feat: Add nodes for arbitrum

* feat: Add Arbitrum support to cryptocurrency handling

* refactor: Update Arbitrum currency references from 'ARB' to 'ETH'

* feat: Add Arbitrum support to wallet type and transaction handling

* feat: Add Arbitrum URL schemes to Android and iOS configurations

* feat: Add Arbitrum SVG icons and a WebP image

* feat: Setup Arbitrum proxy

* fix: Add localization

* feat: Integrate Arbitrum support across various configurations and files

- Updated cakewallet.bat to include Arbitrum in app configuration.
- Added Arbitrum node list to pubspec_base.yaml.
- Modified Android, iOS, Linux, and macOS app configuration scripts to support Arbitrum.
- Introduced Arbitrum output path and generation logic in configure.dart.
- Enhanced wallet type and pubspec generation to include Arbitrum.
- Added Arbitrum-related secrets in secret_key.dart.

* feat: Enhance Arbitrum integration with new URI class and updates across various components

- Introduced ArbitrumURI class for handling Arbitrum payment URIs.
- Updated seed validator, wallet creation service, and other components to support Arbitrum.
- Added Arbitrum node handling in default settings migration and node list management.
- Enhanced preferences and settings store to include Arbitrum-specific configurations.
- Updated QR utility and token utilities to accommodate Arbitrum functionalities.

* feat: Add Arbitrum support to various buy providers

- Updated DFXBuyProvider, KryptonimBuyProvider, OnRamperBuyProvider, and RobinhoodBuyProvider to include Arbitrum wallet type and blockchain references.
- Enhanced integration for Arbitrum across multiple components to ensure consistent support.

* feat: Implement Arbitrum support in wallet selection and settings

- Added Arbitrum wallet type handling in common test flows and wallet services.
- Integrated Arbitrum icons in desktop wallet selection and menu widgets.
- Updated privacy settings to include ArbiScan options.
- Enhanced key service to support Arbitrum private and public key retrieval.

* feat: Expand Arbitrum support across various view models and components

- Integrated Arbitrum wallet type handling in advanced privacy settings, transaction details, and wallet management.
- Added Arbitrum-specific methods for transaction and wallet creation, restoration, and fee management.
- Updated dashboard and home settings to accommodate Arbitrum functionalities, including token management and transaction display.
- Enhanced exchange and send view models to support Arbitrum transactions and currency handling.
- Included Arbitrum in wallet address list and privacy settings for improved user experience.

* refactor: Simplify token initialization in Arbitrum wallet service

- Removed the migration flag from the addInitialTokens method in ArbitrumWalletService.
- Updated addInitialTokens method in ArbitrumWallet to handle existing tokens more efficiently.
- Enhanced initial token retrieval logic in DefaultArbitrumErc20Tokens to prioritize iconPath assignment.
- Improved token update logic in BaseWallet for consistency across wallet services.

* chore: Update Dart SDK constraints in pubspec.yaml

* fix: Update file paths for arbitrum assets

* fix: Correct box name formatting in Arbitrum wallet initialization

* Update .github/workflows/pr_test_build_android.yml [skip ci

* Update .github/workflows/pr_test_build_android.yml

* fix: Add missing evm params

* fix: Remove duplicate method declaration

* refactor: simplify isSwapsXyzSendingEVMTokenSwap check

* fix: Update arbitrum configs with sql storage update

* feat: Add estimated fee retrieval for Arbitrum and revamp priority fee handling for EVMChainWallet

* refactor: Update transaction priority handling and estimated fee calculations across EVMChain chains, also remove priority fee levels for Arbitrum

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

98/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive pathseed or entropy pathsigning or wallet pathboot or update path
AI analysis · Low 34/100

This is a large feature commit that adds support for the Arbitrum (ARB) blockchain to the Cake Wallet app. It introduces a new Arbitrum wallet package, transaction handling, default token lists, node lists, UI icons, and integration with buy/sell providers and settings. There is no explicit security fix or vulnerability disclosure in the commit message or diff. The changes mostly mirror how existing EVM chains (Ethereum, Polygon, Base) are already handled. A few code-quality observations exist, such as a hard-coded Etherscan API key dependency and a minor syntax issue in a domain list, but nothing that clearly creates a new exploitable security flaw based on the supplied materials.