CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
421commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 50 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidatefeat: initial hive -> SQLite (#2502)by cyan · 76876181 · Oct 31, 2025 · 121 filesMessage 98 · StrongLow 49Details
Commit message · cyan

feat: initial hive -> SQLite (#2502)

* feat: initial hive -> SQLite

Includes migration script and initial work done to
remove dependency on hive generators.

Also contains some refactoring to make sync code
async.

Features new dev screen that lists all SQLite tables

Aspects that need testing:
- backups (from this version, and from previous versions as well)
- wallet loading / wallet list
- almost everything else
- renaming
- deletion
- sorting in wallet list
- wallet groups
- wallet seed/keys
- wallet switching
- wallet creation / restore - all methods
- wallet address page
- hardware wallet connection (and prompts from mall screens)
- contacts
- advanced settings in wallet creation
- derivation paths
- some minor wownero fixes
- base, hardware wallets

* fix: build errors

* fix: Bad state: No element in backup restore

* address comments from review

* fix: HardwareWalletType

98/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathauthentication path
AI analysis · Low 49/100

This is a large internal refactor that replaces the Hive key-value database with SQLite for storing wallet metadata (names, addresses, derivation paths, etc.). It also migrates old Hive data to the new SQLite format. The change touches many wallet types and could affect wallet loading, backups, restores, renaming, deletion, and address book behavior. It is a feature/refactor commit, not a targeted security fix, but any bug in the migration or new SQL layer could lead to data loss or incorrect wallet selection.

Security candidateCW-1175-Implement-swaps.xyz-swap-provider (#2526)by Serhii · ee0996f5 · Oct 20, 2025 · 37 filesMessage 81 · StrongLow 38Details
Commit message · Serhii

CW-1175-Implement-swaps.xyz-swap-provider (#2526)

* Integrate SwapsXYZ

* Remove print

* enhance SwapsXyz EVM token swap handling

* Disable fixed rate support in SwapsXyz provider

* enable fixed rate swap

* fix timestamp parsing

* remove sender and recipient address from fetchRate

* Improve SwapsXYZ trade approval logic

* fix trade ID overflow

* add Base chain support for swaps xyz

* Update lib/view_model/exchange/exchange_trade_view_model.dart

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* add missing support for Base

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

81/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
memory safetysigning or wallet path
AI analysis · Low 38/100

This commit adds a new cryptocurrency swap provider called Swaps.XYZ to the Cake Wallet app. It also adds the ability to send pre-built EVM (Ethereum, Polygon, Base) transactions with custom data, and to approve ERC-20 token spending before those swaps. The changes are broad but appear to be a normal feature integration. There is no direct evidence in the commit of a security vulnerability, but the new code paths handle real money transactions and rely on an external API, which always carries some risk.

Security candidatefix: downgrade and fork reown (#2566)by cyan · 2cf1202f · Oct 17, 2025 · 9 filesMessage 100 · StrongInformational 24Details
Commit message · cyan

fix: downgrade and fork reown (#2566)

Due to reown changing their license in version
1.2.0 we switched to use last open source release
of reown with all fixes for flutter 3.32.0 and
16kb page size requirements.

chore: drop dependency overrides for reown
ci: switch prebuilds to use github releases instead of CDN
fix: reown socket errors in onDone and onError
fix: remove flutter_secure_storage on linux (closes #2577, #2561)

100/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference
Why it was queued
update trust
AI analysis · Informational 24/100

This commit changes how Cake Wallet builds and bundles a third-party library called Reown. The stated reason is a license change in Reown's upstream version 1.2.0, so the project switches to its own forked/prebuilt release. The diff also removes a Linux secure-storage plugin and updates many iOS dependency checksums. There is no direct evidence in the commit of a security vulnerability being fixed or introduced, but any change to how sensitive wallet libraries are fetched, built, and distributed deserves careful review because it touches code that handles cryptographic wallet operations.

Security candidatedcr: Point widget to correct image. (#2586)by JoeGruffins · 32dd69b2 · Oct 16, 2025 · 1 fileMessage 53 · ThinInformational 15Details
Commit message · JoeGruffins

dcr: Point widget to correct image. (#2586)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit simply swaps one image file path for another in a Decred (DCR) information card shown in the wallet's balance screen. It is a visual/UI fix with no security implications.

Security candidatev5.5.0 Release candidate (#2574)by Omar Hatem · b1ee2acd · Oct 15, 2025 · 108 filesMessage 76 · AdequateInformational 18Details
Commit message · Omar Hatem

v5.5.0 Release candidate (#2574)

* v5.5.0 Release candidate

* RC contents:
- Trezor
- Bitbox
- Base
- Hardware/Air-gapped wallets flow enhancements
- New Theme
- UI enhancements
- Bug fixes

fixes:
- Disable LTC for bitbox
- Fix missing coins icons

* RC contents:
- Trezor
- Bitbox
- Base
- Hardware/Air-gapped wallets flow enhancements
- New Theme
- UI enhancements
- Bug fixes

fixes:
- Disable LTC for bitbox
- Add USDE icon
- Fix missing images

* RC contents:
- Trezor
- Bitbox
- Base
- Hardware/Air-gapped wallets flow enhancements
- New Theme
- UI enhancements
- Bug fixes

fixes:
- Disable LTC for bitbox
- Add USDE icon
- Fix missing images
- Refactor code and remove `normalizedIconPath`

* RC contents:
- Trezor
- Bitbox
- Base
- Hardware/Air-gapped wallets flow enhancements
- New Theme
- UI enhancements
- Bug fixes

fixes:
- Disable LTC for bitbox
- Add USDE icon
- Fix missing images
- Refactor code and remove `normalizedIconPath`

* RC contents:
- Trezor
- Bitbox
- Base
- Hardware/Air-gapped wallets flow enhancements
- New Theme
- UI enhancements
- Bug fixes

fixes:
- Disable LTC for bitbox
- Add USDE icon
- Fix missing images
- Refactor code and remove `normalizedIconPath`

* - Add xstocks to existing wallets
- Add xstocks initial icons

* - Add All xStocks icons
- Fix All tokens issues and persistent

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 18/100

This is a routine version-bump release candidate (v5.5.0) for the Cake Wallet/Monero.com apps. It mainly adds support for new hardware wallets (Trezor, BitBox), a Base coin wallet, a new theme, many new token/stock icons, and fixes missing icons. There is no clear security vulnerability in the visible changes. The only notable functional change is that the app now preserves a user's existing token enable/disable preference when updating built-in token lists, instead of resetting it.

Security candidateFix menu action icons (#2582)by tuxsudo · 03c3a362 · Oct 14, 2025 · 3 filesMessage 68 · AdequateInformational 15Details
Commit message · tuxsudo

Fix menu action icons (#2582)

* Fix menu action icons

* Fix a couple picker icons

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit only updates a handful of image/icon file paths used for menu buttons and cryptocurrency listings in the Cake Wallet app. It replaces references to old WebP/PNG icons with newer or more appropriate image assets. There is no security-relevant change here.

Security candidateMinor fixes (#2575)by tuxsudo · 226d8d91 · Oct 14, 2025 · 58 filesMessage 59 · ThinInformational 15Details
Commit message · tuxsudo

Minor fixes (#2575)

* Actually fix settings_theme_choice.dart container this time

* Switch crypto icons to webp

* Fix crypto image extensions

* Fix support images and add Base icon

* Fix image links

* Fix more image links

* Update lib/src/screens/dashboard/desktop_widgets/desktop_wallet_selection_dropdown.dart [skip ci]

* Update cw_core/lib/crypto_currency.dart [skip ci]

* Update cw_core/lib/crypto_currency.dart

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

59/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 15/100

This commit is a routine UI/asset maintenance patch. It converts cryptocurrency and support icons from PNG/SVG formats to WebP, fixes a few image file paths that were still pointing to old filenames, removes a fixed height from a settings theme container, and adds a missing Base network icon. There are no changes to security-sensitive code, cryptography, wallet logic, networking, or permissions.

Security candidateAdd Base Wallet (#2558)by David Adegoke · 2a74317a · Oct 11, 2025 · 139 filesMessage 59 · ThinLow 28Details
Commit message · David Adegoke

Add Base Wallet (#2558)

* chore: Create Base package template

* chore: Update configuration scripts and dependencies to include 'base' coin support

* chore: Update pubspec.yaml, adjust SDK constraints, and add new dependencies

* feat: Add support for base wallet type and cryptocurrency in related configurations

* feat: Implement BaseWallet and DefaultBaseTokens classes for managing base cryptocurrency transactions

* feat: Add BaseTransactionHistory and BaseTransactionInfo classes for handling base cryptocurrency transaction data

* feat: Implement BaseClient, BaseWalletService, and BaseMnemonicIsIncorrectException

* feat: Setup base proxy for main package and adjust token class name

* feat: Setup initial base node configuration

* feat: Integrate support for base wallet type across various functions and services

* feat: Add base support to exchange and outputs

* feat: Add base wallet type integration to wallet creation and node management

* feat: Add base support to transaction details and transaction list item

* feat: Implement BaseURI class and add base support across wallet creation and keys view models

* feat: Add support for BaseScan preference in settings store

* feat: Integrate Base support into various workflows and documentation

* feat: Addingbase config to windows and secret key support

* feat: Add base support to settings and address handling

* chore: Move walletTypeToCurrency to another file and adjust across codebase

* feat: Add 'basescan_history' string localization

* feat: Remove Cryptocurrency.base, it doesn't have a base currency

* feat: Set eth as native currency

* feat: Enhance Base support across various sending, exchange, transaction details, fees, dashboard and balance

* feat: Integrate Base wallet support in advanced privacy settings and home settings view models

* feat: Add Base wallet support with icon and integration across providers, default settings migration, preferences, wallet connect, settings and token utilities

* feat: Update currency handling to use baseEth for Base wallet integration across various components

* fix: Update default token symbol to ETH in Base wallet transaction model

* refactor: Change default currency references from BASE to ETH across client, transaction info, and wallet components

* feat: Introduce normalizedIconPath for CryptoCurrency to standardize icon retrieval across wallet components

* fix: Include baseEth as a native token in EVMChainClient for currency handling

* chore: Update base_icon.png

* feat: Add more nodes to base_node_list.yml

* refactor: Update wallet icon retrieval to use normalizedIconPath

* chore: Remove unused cases and cleanup impl.

* feat: Add base proxy generation to configure

* refactor: Update base proxy and generation code in configure.dart

* feat: Add missing wallet and mono images

* fix: Wrong image path for pr and add missing base qr image

* feat: Enhance EVMTransactionErrorFeesHandler to parse new insufficient funds error format and calculate transaction fees in ETH and USD

* feat: Add gas price safety buffer for Base chain transactions to improve fee estimation accuracy, also fixes send all not calculating correctly

* Update model_generator.sh [skip ci]

* Update assets/base_node_list.yml [skip ci]

* Update cw_base/lib/default_base_erc20_tokens.dart [skip ci]

* Review fixes

* fixes

---------

Co-authored-by: OmarHatem <omarh.ismail1@gmail.com>

59/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
secret or key materialcryptography-sensitive pathseed or entropy pathsigning or wallet pathboot or update path
AI analysis · Low 28/100

This commit adds support for the Base blockchain (an Ethereum Layer 2) to the Cake Wallet app. It introduces a new wallet type, transaction handling, default token list, node list, icons, and settings. The changes are mostly feature additions that mirror existing Ethereum/Polygon support. There are a few code-quality items worth noting, such as a hardcoded API endpoint and a gas-price buffer, but nothing in the diff clearly indicates an exploitable security vulnerability.

Security candidateLCW-1128-Add-support-for-Trezor (#2565)by Konstantin Ullrich · 8b76391a · Oct 10, 2025 · 38 filesMessage 76 · AdequateLow 27Details
Commit message · Konstantin Ullrich

LCW-1128-Add-support-for-Trezor (#2565)

* feat: add support for Trezor hardware wallet integration Restore Wallets

* feat: add Trezor hardware wallet support, implement RLP decoding utility, and update transaction signing logic

* feat: add bitcoin trezor signing

* chore: update Trezor Connect dependency to specific commit hash in pubspec_base.yaml

* feat: add trezor support for litecoin

* feat: add colorFilter for device manufacturer icons to align with theme styles

* refactor: optimize Trezor callback handling

* feat: add BitBox and Trezor support for Bitcoin and Litecoin, update transaction signing logic, and improve modularity in hardware wallet services

* refactor: simplify constructor assertions in `BaseBottomSheetWidget` and cleanup Trezor chainId handling logic

* feat: conditionally render device manufacturers based on platform and hide SeedSigner for now

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarycryptography-sensitive pathsigning or wallet pathparser or protocol path
AI analysis · Low 27/100

This commit adds support for Trezor hardware wallets to the Cake Wallet app, alongside some refactoring of existing Ledger and BitBox hardware wallet code. It introduces new code paths for discovering accounts, signing Bitcoin/Litecoin transactions, and signing Ethereum/Polygon transactions via Trezor. The changes also include a custom RLP decoder for Ethereum transactions and UI updates to show Trezor as an available hardware wallet option on Android. There is no explicit security bug visible in the diff, but the commit is a large feature addition touching sensitive wallet-signing logic, so it warrants careful review.

Security candidateUI updates (#2368)by tuxsudo · c746b85a · Oct 10, 2025 · 329 filesMessage 81 · StrongInformational 15Details
Commit message · tuxsudo

UI updates (#2368)

* Add Black theme

* Fix black theme

* Add WixMadefor Font

* feat: Enhance theme setup

This change:
- Adds support for custom themes
- Updates theme retrieval logic to ensure the right theme is used based on user preferences(especially for custom themes).

* Add black custom colors

* Add custom accent colors

* feat: Restructure custom colors handling for themes

* feat: Integrate new custom colors structure across various components - WIP

* feat: Integrate new custom colors structure across various components, black theme now ready for tests

* feat: Add new accent color themes and update theme selection UI

- Enhanced theme selection UI in display settings to support accent color choices.
- Updated theme handling logic to accommodate new accent color variants.

* Minor updates to display_settings_page.dart

* Update settings_theme_choice.dart

* Revert accidental change in display_settings_page.dart

* Revert WixMadeFor font, fix SVG colors for CakeImageWidget, and test some color changes

* Update Monero Orange

* fix: Remove unused custom colors

* Test outline

* Test spacing and colors

* Add padding

* Remove outline

* Add other accent colors

* Update display_settings_view_model.dart

* Update names and fix switch case

* Add outline and update dark_theme.dart colors

* Add gradient to option_tile.dart

* Update icons

* Update some colors

* Switch option_tile.dart to TextButton

* Add updated icons

* Fix icon resolution

* Cleanup old icons + Update pubspec_base.yaml

* Remove unused fonts

* Update more icons

* Update image paths

* Remove more icons + update some component colors

* Add back DAI icon

* Fix errors

* feat: Implement OLED mode for BlackTheme

* feat: Add OLED mode for BlackTheme and localizations

* feat: Implement OLED mode for Black Theme

* refactor: Remove unused theme parameters and set up easy access to toggleKnob custom colors

* fix: Cleanup UI and overflows

* feat: Persist black theme selection if OS theme mode while app is in system mode

* fix: OS theme change when app is in background restrict pin screen from proceed

* Fix theme picker sizing

* Update lib/src/screens/dashboard/desktop_widgets/desktop_wallet_selection_dropdown.dart

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* refactor: Enhance theme access by introducing ThemeX extension for easier retrieval of current theme and custom colors

* refactor: Remove currentTheme parameter from GradientBackground widget and adjust across affected widgets

* refactor: Remove currentTheme parameter from StandardSwitch and SettingsSwitcherCell, using ThemeX extension for theme access

* refactor: Remove currentTheme parameter from various widgets dependent on SettingsSwitcherCell and StandardxSwitcher, using ThemeX extension for theme access

* refactor: Remove currentTheme in bottomsheets and related widgets, switching to theme extension

* refactor: Remove constructor theme access in OptionTile and related widgets, switching to theme extension

* refactor: Switch bottomsheet related widgets to use theme extension instead of constructor access

* refactor: Migrate currentTheme access from constructor based to extension base

* refactor: Switch theme access from constructor base to extension base [skip ci]

* refactor: Migrate more widgets to use extension based theme access and clean up code

* refactor: Update theme access across multiple widgets to use the new theme extension

* refactor: Clean up theme access in various widgets, moving to extension-based theme usage

* refactor: Make theme picker preview responsive

* fix: Persist saved black theme accent when app is put in background and brought back

* remove unused variables [skip ci]

---------

Co-authored-by: Blazebrain <davidadegoke16@gmail.com>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

81/100 · StrongMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
access controlmemory safetycryptography-sensitive pathseed or entropy pathsigning or wallet pathboot or update pathauthentication path
AI analysis · Informational 15/100

This is a large user-interface refresh for the Cake Wallet app. It adds a new black/OLED theme, lets users pick accent colors, swaps many old PNG icons for new ones, and refactors how widgets access theme colors. There is no indication this change fixes a security bug or introduces a security vulnerability.

Security candidatefeat: integrate `getOnramperSignature` method and add support for retrieving Onramper signature (#2553)by Konstantin Ullrich · 80bba64c · Oct 2, 2025 · 1 fileMessage 98 · StrongLow 28Details
Commit message · Konstantin Ullrich

feat: integrate `getOnramperSignature` method and add support for retrieving Onramper signature (#2553)

* feat: integrate `getOnramperSignature` method and add support for retrieving Onramper signature

* fix: make `getOnramperSignature` call asynchronous

* fix: normalize networkWallets parameter to lowercase [skip ci]

98/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
signing boundary
AI analysis · Low 28/100

This commit adds a new step when a user buys cryptocurrency through the Onramper service. Before opening the Onramper checkout page, the app now sends the user's chosen crypto address to a Cake Wallet server (exchange-helper.cakewallet.com) to request a signature. That signature is then included in the checkout URL. The change also normalizes the blockchain network name to lowercase. There is no direct evidence in the commit of a vulnerability, but it introduces a new network call that handles a real user address and an API key, which is worth reviewing for privacy and trust assumptions.

Security candidateCW-1135-add-support-for-bitbox-hww (#2476)by Konstantin Ullrich · e4672c75 · Oct 1, 2025 · 117 filesMessage 98 · StrongLow 35Details
Commit message · Konstantin Ullrich

CW-1135-add-support-for-bitbox-hww (#2476)

* chore: add ffi and ffigen dependencies to pubspec.yaml

* refactor: replace method channel with FFI implementation for MWeb module

* fix: correct `cd` command in build_mwebd.sh script

* chore: add go.sum file with dependency checksums

* fix: ensure ANDROID_NDK_VERSION is set before building and dynamically update NDK_BIN path

* fix: update NDK_BIN path to dynamically detect platform in build_mwebd.sh script

* refactor: remove unused mwebd dependencies and clean up CwMwebPlugin code

* Update scripts/android/build_mwebd.sh

Co-authored-by: cyan <cyjan@mrcyjanek.net>

* refactor: replace iOS MoneroWallet framework with Mwebd.xcframework and clean up plugin implementation [skip-ci]

* refactor: extract hardware wallet service abstraction

* refactor: extend BitcoinHardwareWalletService from HardwareWalletService and override account retrieval method

* feat: add BitBox hardware wallet support and implement manufacturer selection page with custom UI components

* refactor: update manufacturer selection UI and integrate custom gradient styles for ManufacturerOptionTile widget

* fix: mwebd ffi ios

* feat: add BitBox hardware wallet support, update derivation paths, and refactor hardware wallet credential implementations

* feat: add bitbox support and refactor the old ledger implementation

* feat: add BitBox hardware wallet support and refactor hardware wallet service implementations

* feat: refactor hardware wallet support to introduce abstraction for BitBox and Ledger; update device scanning, initialization, and UI integration

* fix: BitBox hardware wallet ethereum transaction signing

* chore: update BitBox Flutter path references and include build steps in CI workflows

* chore: update CI workflows to include `--dont-install` flag for BitBox Flutter builds

* refactor: replace if-else logic with switch-case for HardwareWalletViewModel factory

* feat: refactor hardware wallet services to introduce shared interface, improve ledger and bitbox implementations, and support additional transaction signing operations

* feat: add SVG assets for hardware wallet manufacturers (Foundation, Keystone, SeedSigner)

* feat: redesign hardware wallet restoration flow with improved routing, UI updates, and manufacturer-specific device selection handling

* fix: validate required BIP353 fields in transaction builder to prevent potential null value errors

* feat: improve BitBox transaction signing logs with detailed PSBT information

* refactor: update MWebFfi class to use non-nullable `lib` and improve address debug logging

* feat: add BitBox coin type constant and improve hardware wallet service extensibility

* chore: remove unused iOS/Android build scripts for mwebd

* feat: add BitBox SVG asset and update localization for hardware wallet connection instructions

* feat: update manufacturer tags and add Toast Easter egg for device selection interactions

* refactor: replace LedgerViewModel with HardwareWalletViewModel across providers and improve hardware wallet handling

* refactor: replace mweb.so with libmweb.so, use sync methods in MWebFfi, and update iOS/Android frameworks/scripts accordingly

* feat: add Ledger Nano X SVG asset to hardware wallet resources

* chore: unify mwebd build process in workflows, remove unused gomobile init command

* refactor: remove redundant print statement and unnecessary whitespace

* chore: add `gomobile init` to Android PR test build workflow

* chore: update Android PR test build workflow and add file existence check in `build_bitbox_flutter.sh`

* chore: override `ledger_usb_plus` dependency in pubspec_base.yaml

* feat: add verbose logging for BitBox connection and initialization process

* Update lib/view_model/hardware_wallet/bitbox_view_model.dart [skip ci]

* CW-1206-refactor-hardware-wallets-code (#2507)

* feat: add support for new hardware wallet types (Cupcake, Coldcard, SeedSigner) and improve QR Code handling

- Introduced new hardware wallet types (Cupcake, Coldcard, SeedSigner) with corresponding assets and localization updates.
- Updated QR Code format selection for hardware wallets with new formats (BCUR, BBQR) specific to devices.
- Improved hardware wallet restoration flow to include airgapped wallet handling via QR Code scanning.
- Refactored routing, view models, and dependency injection to accommodate new hardware wallet types.
- Enhanced UI for device manufacturer selection and QR Code format dialogs.

* feat: update hardware wallet assets and restoration flow

* feat: add changing airgapped wallet type

* feat: add Cupcake Man SVG asset to hardware wallet resources

* refactor: update Litecoin receive options to require wallet parameter and handle hardware wallets

* fix: debugging keystone integration
feat: support for zpub view only restore

* fix: seed signer restore

* fix: disable bitbox restoring (for now) [skip-ci]

* refactor: rename `isCupcake` to `isBitcoinViewOnly` for clarity [skip ci]

---------

Co-authored-by: Czarek Nakamoto <cyjan@mrcyjanek.net>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* refactor: standardize hardware wallet connection handling across wallet types

---------

Co-authored-by: cyan <cyjan@mrcyjanek.net>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

98/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing boundarydefensive validationcredential or privilege statecryptography-sensitive pathseed or entropy pathsigning or wallet pathauthentication pathparser or protocol path
AI analysis · Low 35/100

This is a large feature commit adding support for BitBox hardware wallets to Cake Wallet, alongside a broader refactor of hardware wallet handling. It also includes a small fix to prevent crashes when BIP353 payment-proof fields are missing. There is no clear evidence of a deliberate security vulnerability, but the size and nature of the changes introduce normal implementation risks.