CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
421commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 51 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedreadd filters to new ui (#3062)by malik1004x · aa18ea39 · Mar 14, 2026 · 32 filesMessage 68 · AdequateInformational 15Details
Commit message · malik1004x

readd filters to new ui (#3062)

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 15/100

This commit is a routine user-interface feature patch. It re-adds a 'Filters' button to a new wallet design and adds the word 'filters' to translation files. There is no security relevance visible in the code changes.

AI review queued26-03-14_Update Translation_de_DEby BSN ∞/21M · 0601544f · Mar 14, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · BSN ∞/21M

26-03-14_Update Translation_de_DE

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a routine German translation update for the Cake Wallet app. It changes wording, grammar, and formality (for example, switching some phrases from informal 'du' to formal 'Sie'), but does not modify any program logic, security settings, or code behavior.

AI review queuedUpdate RBF nsequence to 0xFFFFFFFD (#3077)by Armin Sabouri · 4d61345f · Mar 13, 2026 · 1 fileMessage 76 · AdequateLow 48Details
Commit message · Armin Sabouri

Update RBF nsequence to 0xFFFFFFFD (#3077)

Technically `0x1` will signal opt-in RBF (since 0x1 ≤ 0xFFFFFFFD); however it also sets a relative timelock of 1 block. This seems like an unintended bug. It also fingerprints cake wallet since `0x1` is an abnormal value. This is especially harmful in collaborative settings e.g payjoin. Most wallets set `nsequence = 0xFFFFFFFD` to opt into RBF or just use full rbf which seems to be gaining more adoption.

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 48/100

Cake Wallet was setting a Bitcoin transaction value (called nSequence) to 1 when enabling Replace-By-Fee (RBF). The value 1 does technically opt into RBF, but it also tells the network the transaction cannot be mined until 1 block has passed, which is a relative timelock. This is likely unintended, makes Cake Wallet transactions stand out as unusual, and can cause problems in collaborative transactions like PayJoin. The fix changes the value to 0xFFFFFFFD, the standard value wallets use for RBF.

AI review queuedFix QR scanner to accept fountain coding for BC-UR codes (#3048)by Hector Chu · 1520ba8e · Mar 13, 2026 · 1 fileMessage 81 · StrongInformational 18Details
Commit message · Hector Chu

Fix QR scanner to accept fountain coding for BC-UR codes (#3048)

* fix: use fountain decoder to determine UR scanning progress

* fix: use fountain encoder for cupcake

* fix build

* fix crash

* revert encoder changes

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
second-pass: broader security terminology
AI analysis · Informational 18/100

This commit updates the QR code scanner in Cake Wallet so it can correctly track progress when scanning multi-part BC-UR QR codes (a format used for things like crypto transaction signing). It replaces a hand-rolled progress check with a dedicated 'fountain decoder' library. There is no direct evidence this fixes a security vulnerability; it appears to be a reliability/UX improvement for scanning animated QR codes.

AI review queuedfix: SPL token balance display for xstocks and non-6-decimal tokens (#3052)by David Adegoke · 4d26b4ee · Mar 13, 2026 · 3 filesMessage 70 · AdequateInformational 19Details
Commit message · David Adegoke

fix: SPL token balance display for xstocks and non-6-decimal tokens (#3052)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit fixes how Cake Wallet displays balances for certain Solana tokens (SPL tokens) that do not use the standard 6 decimal places. Previously, the wallet could show incorrect token balances because it assumed all tokens had 6 decimals. The fix uses the raw balance amount reported by the Solana network and the separately provided user-facing amount, so the displayed balance matches reality. There is no direct evidence this is a security vulnerability, but incorrect balance display could theoretically lead users to make wrong transaction decisions.

AI review queuedmake the block explorer link a more prominent color (#3061)by malik1004x · c5890ef0 · Mar 13, 2026 · 1 fileMessage 58 · ThinInformational 15Details
Commit message · malik1004x

make the block explorer link a more prominent color (#3061)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only changes the color of a block explorer link in the transaction details screen to make it more visible. It is a user-interface styling tweak with no security relevance.

AI review queuedfix: only throw on deserialize if kDebugMode is true (#2976)by cyan · 64ded5a7 · Feb 26, 2026 · 6 filesMessage 93 · StrongLow 38Details
Commit message · cyan

fix: only throw on deserialize if kDebugMode is true (#2976)

This closes #2972, in debug mode we will still catch these issues but if
somehow that happens on production it will fallback to safe default

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: broader security terminologysecond-pass: security-sensitive path
AI analysis · Low 38/100

This commit changes several parts of the Cake Wallet app so that, in normal use, unexpected stored values no longer crash the app. Instead, the app falls back to a safe default (usually 'medium' priority or 'descending' order). In debug builds, it still throws an error so developers can spot problems. The change is a defensive hardening fix: it reduces the chance that a corrupted or mismatched saved setting makes the wallet unusable, but it also means a bad value is silently accepted in production.

AI review queuedfix: Add additional fees validation for native transaction (#2933)by David Adegoke · 7000600c · Feb 20, 2026 · 1 fileMessage 70 · AdequateModerate 58Details
Commit message · David Adegoke

fix: Add additional fees validation for native transaction (#2933)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 58/100

This commit adds a safety check in Cake Wallet's Ethereum-compatible wallet to prevent users from creating native (non-token) transactions when the account does not have enough balance to cover both the amount being sent and the network transaction fee. Previously, the app only checked that the send amount itself was covered by the balance, which could allow a transaction to be created that would later fail or leave the account unexpectedly short. The fix throws a specific fee-related error when the combined amount plus estimated fees exceeds the available balance.

AI review queuedgeneral-fixes (#2912)by David Adegoke · 4838da68 · Feb 17, 2026 · 3 filesMessage 59 · ThinInformational 24Details
Commit message · David Adegoke

general-fixes (#2912)

* Handle tokens bottomsheet triggering on non-evm wallets

* fix:Swith to the right fee currency when sending in bsc wallets

59/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 24/100

This commit fixes three user-facing bugs in a crypto wallet app: it prevents a token-selection bottom sheet from appearing for non-EVM wallets, makes sure BSC (Binance Smart Chain) transactions display fees in BNB instead of ETH, and avoids a crash when a swap currency has no icon image. These are correctness and UI fixes rather than obvious security vulnerabilities, but the fee-currency mix-up could confuse users about transaction costs.

AI review queuedNormalize tokens box in migration edgewise (#2904)by David Adegoke · a02f48a6 · Feb 16, 2026 · 1 fileMessage 58 · ThinInformational 21Details
Commit message · David Adegoke

Normalize tokens box in migration edgewise (#2904)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 21/100

This commit adds a single extra step during a wallet migration path. When an older version of the app's token storage box is missing, the code now initializes the box and then immediately 'normalizes' its keys. The change is small and appears to be a data-consistency fix rather than a security patch, but the commit message gives no details about what problem it solves.

AI review queuedToken delete bug fix (#2889)by David Adegoke · 695829c2 · Feb 13, 2026 · 2 filesMessage 68 · AdequateLow 27Details
Commit message · David Adegoke

Token delete bug fix (#2889)

* Normalize erc20 token addresses and fix duplicate tokens

* fix: Error when deleting token on solana and tron

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 27/100

This commit fixes a bug where deleting a custom token in the Solana or Tron wallet could fail or behave incorrectly. The old code tried to delete the token object directly, which could throw an error if the storage box wasn't open. The new code checks that the storage box is open and deletes the token by its unique address instead. There is also a minor formatting-only change in the Tron wallet's transaction code with no functional effect.

AI review queuedNormalize erc20 token addresses and fix duplicate tokens (#2884)by David Adegoke · 2fc18de9 · Feb 10, 2026 · 6 filesMessage 58 · ThinLow 34Details
Commit message · David Adegoke

Normalize erc20 token addresses and fix duplicate tokens (#2884)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 34/100

This commit fixes a bookkeeping problem in Cake Wallet's handling of Ethereum-compatible tokens. Because Ethereum addresses are case-insensitive but the app was storing them with mixed-case keys, the same token could appear twice or get out of sync. The patch adds a one-time cleanup that converts all stored token addresses to lowercase and merges duplicates. It also updates the built-in token lists to use lowercase addresses. This is a data-consistency bug fix rather than an active remote hack, but if left unfixed it could have led to wrong balances, missing tokens, or in a worst-case scenario sending funds to or trusting the wrong contract address.

AI review queuedAdd BSC chain support to wallet connect key service (#2885)by David Adegoke · 473b82b3 · Feb 10, 2026 · 1 fileMessage 58 · ThinInformational 16Details
Commit message · David Adegoke

Add BSC chain support to wallet connect key service (#2885)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 16/100

This commit adds support for the Binance Smart Chain (BSC) network identifier to the WalletConnect key service. It is a one-line addition listing a new supported blockchain chain. There is no indication of a security fix, vulnerability, or behavior change beyond expanding supported networks.

AI review queuedDisable Jupiter limits for non-solana swaps (#2880)by Omar Hatem · 0b5f1093 · Feb 10, 2026 · 6 filesMessage 81 · StrongLow 25Details
Commit message · Omar Hatem

Disable Jupiter limits for non-solana swaps (#2880)

* Disable Jupiter limits for non-solana swaps
Fix zcash restore from QR
Fix Android build with zkool

* remove print [skip ci]

* update versions [skip ci]

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 25/100

This update makes three small fixes in the Cake Wallet app: it stops using a hidden note field when decoding Zcash payment addresses, removes Jupiter swap limits for non-Solana trades, and adds missing Zcash QR-code restore labels. The Zcash memo change is the most security-relevant because it prevents a payment request from silently carrying an unexpected message, but the commit itself does not describe this as a security fix and no exploit is demonstrated.

AI review queuedfix logix (#2881)by cyan · c13881ff · Feb 10, 2026 · 1 fileMessage 36 · OpaqueLow 42Details
Commit message · cyan

fix logix (#2881)

36/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 42/100

This commit fixes a logic bug in how the Zcash wallet loads cryptographic 'proving' files. Previously, the app would load the files from app assets, then immediately overwrite those loaded bytes by reading from a local cache—even if the asset load had succeeded. After the fix, the app only falls back to the cache when the asset load produced empty data. This prevents silently using stale or corrupted cached parameters and avoids unnecessary network downloads.

AI review queuedfetch params from download.z.cash on demand to reduce app size (#2879)by cyan · 6b458e8a · Feb 9, 2026 · 4 filesMessage 58 · ThinModerate 52Details
Commit message · cyan

fetch params from download.z.cash on demand to reduce app size (#2879)

add restore height to seed screen

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 52/100

This commit changes the Cake Wallet app so that it no longer ships with two large Zcash cryptographic files inside the app bundle. Instead, the app downloads those files from download.z.cash the first time it needs them, and saves them to the app's cache folder. The same commit also adds the wallet's restore height to the seed/keys screen for Zcash wallets. The change is a size optimization, but it introduces a new network download of security-critical parameters and stores them on disk, which could matter if the download or storage is tampered with.

AI review queuedfix: Error while approving transactions via walletconnect for ARB (#2878)by David Adegoke · 143ce845 · Feb 9, 2026 · 2 filesMessage 93 · StrongInformational 24Details
Commit message · David Adegoke

fix: Error while approving transactions via walletconnect for ARB (#2878)

* fix: Error while approving transactions via walletconnect for ARB

* fix: Error while approving transactions via walletconnect for ARB

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 24/100

This commit fixes two bugs in Cake Wallet's WalletConnect integration for Ethereum-compatible chains (including Arbitrum/ARB). First, it corrects how the app picks the right network node when building transactions, so it no longer tries to use a non-EVM wallet's node for EVM chains. Second, it now respects gas values supplied by the connected dApp instead of always overwriting them, and it handles cases where the dApp only provides some gas fields. A third small fix prevents a crash when an auto-closing WalletConnect bottom sheet tries to close after it has already been dismissed. The commit is described by the vendor as a transaction-approval bug fix, not as a security vulnerability.

AI review queuedfix translationby OmarHatem · e450187f · Feb 9, 2026 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · OmarHatem

fix translation

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit fixes a simple Japanese translation typo by adding a missing closing quotation mark in a language file. It has no security relevance.

AI review queuedv5.9.0 Release Candidate (#2871)by Omar Hatem · 174216df · Feb 7, 2026 · 10 filesMessage 76 · AdequateInformational 13Details
Commit message · Omar Hatem

v5.9.0 Release Candidate (#2871)

* v5.9.0 Release Candidate
- Zashi migration
- BSC integration
- Prefetch All evm tokens that the user has
- Bug fixes

* Add new monero nodes
Update app versions

* update zkool fork
update release notes

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 13/100

This is a routine version-bump release candidate for Cake Wallet/Monero.com (5.8.0 → 5.9.0). It adds BNB Smart Chain support, swaps a Zcash library dependency from a personal GitHub fork to a Cake Labs fork, updates the bundled Monero node list, and bumps build numbers across Android, iOS, Linux, macOS, and Windows. The changes are mostly configuration and dependency metadata; there is no direct evidence in the diff of a security vulnerability or a security fix.

AI review queuedDisable ETA by default, use electrs node as a fallback not hardcodedby OmarHatem · 1067157c · Jan 26, 2026 · 4 filesMessage 50 · ThinInformational 24Details
Commit message · OmarHatem

Disable ETA by default, use electrs node as a fallback not hardcoded

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 24/100

This commit makes two user-facing changes in the Cake Wallet app: it turns off a default 'estimated time remaining' display for wallet syncing, and it stops silently forcing a hardcoded Cake-run Bitcoin server when scanning certain private transactions. Instead, the app will use the server the user already picked, only falling back to the hardcoded one if none was chosen. The commit also slightly increases a network keep-alive timer. There is no direct evidence in the commit that this fixes an active security vulnerability, but it reduces privacy and trust risks by giving users more control over which server handles their transaction data.

AI review queuedremove warp from macosby OmarHatem · bbf1ca9d · Jan 23, 2026 · 5 filesMessage 28 · OpaqueInformational 15Details
Commit message · OmarHatem

remove warp from macos

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit removes Zcash 'Warp' wallet-sync components from the macOS build of Cake Wallet, bumps the macOS app build numbers, slightly increases a startup delay, and changes one error case to return false instead of throwing an exception. There is no direct evidence in the commit that this fixes an active security vulnerability; it looks like a build cleanup and minor hardening change.

AI review queuedminor fixesby OmarHatem · d0fc762c · Jan 21, 2026 · 4 filesMessage 0 · OpaqueInformational 24Details
Commit message · OmarHatem

minor fixes

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 24/100

This commit contains three small fixes: a loop bug in Zcash address handling, a reclassification of a Ledger error message, and routine build number bumps. The Zcash fix changes two mistaken index references from 'i' to 'k' inside a loop, which likely caused the wrong wallet account to be checked for hidden/used transparent addresses. This could affect address rotation or privacy behavior for Zcash transparent addresses, but it is a correctness bug rather than an obvious exploit. The Ledger change moves 'transport error' from a list of known Ledger errors to a list of ignored/generic exception strings, which may reduce false crash reports but does not appear security-sensitive. The build number changes are administrative.

AI review queuedv5.8.0 Release Candidate (#2815)by Omar Hatem · 9ca2346a · Jan 20, 2026 · 19 filesMessage 76 · AdequateLow 34Details
Commit message · Omar Hatem

v5.8.0 Release Candidate (#2815)

* v5.8.0 Release Candidate

Add Arbitrum
EVM chains enhancements
Integrate Jupiter swaps for Solana
Bug fixes

* Exclude transparent address from unified address

* fix hiddenAddresses getting discarded [skip ci]

* pump zcash order [skip ci]

* CW-1372: zcash improvements and missing features second iteration (#2818)

* fix: remove hidden addresses from usable address list
fix: getBlockHeightByTime fallback to offline calculation
fix: remove NewWalletTypeViewModel to fix groups working without restart

* fix: rotate T addresses in exchanges

* fix: builds without --zcash config (linux)

* fix: update address after trade

* Add zcash.me

* printv [skip ci]

---------

Co-authored-by: cyan <cyjan@mrcyjanek.net>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 34/100

This is a routine version-bump release candidate (v5.8.0) for the Cake Wallet family of apps. Most changes are feature work: adding Arbitrum, improving EVM chains, integrating Jupiter swaps for Solana, and fixing several Zcash wallet bugs. The Zcash fixes include making sure hidden/used transparent addresses are not reused for exchanges, falling back to an offline formula if the server cannot provide a block height from a date, and removing a stale view-model that was breaking wallet-group functionality. There is no vendor statement that this commit fixes a security vulnerability, and the changes read like ordinary bug fixes rather than a security patch.

AI review queuedfeat: Enhance Solana wallet with token program ID support (#2814)by David Adegoke · 02225fab · Jan 20, 2026 · 2 filesMessage 93 · StrongLow 26Details
Commit message · David Adegoke

feat: Enhance Solana wallet with token program ID support (#2814)

- Handle custom token program IDs, supporting both standard SPL Token and Token-2022.
- Fetch the appropriate token program ID based on mint address.
- Updated associated token account creation logic to use the detected token program ID, ensuring compatibility with different token standards.

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 26/100

This commit updates Cake Wallet's Solana support so it can work with both the older standard SPL token program and the newer Token-2022 program. It fetches the correct token program from the blockchain for each token and uses that program when finding or creating associated token accounts and when building transfer instructions. The change is a feature enhancement, not a stated security fix. There is a small risk that if the code picks the wrong program ID or an attacker-controlled RPC returns bad data, transactions could fail or funds could be sent to incompatible accounts, but the diff itself does not show an obvious vulnerability.

AI review queuedSmoothen Jupiter Swap for Solana Wallets (#2816)by David Adegoke · 696052f5 · Jan 19, 2026 · 5 filesMessage 76 · AdequateInformational 21Details
Commit message · David Adegoke

Smoothen Jupiter Swap for Solana Wallets (#2816)

* feat: Integrate Jupiter DEX

* feat: Enable internal swaps

* feat: implement Jupiter swap execution api and enhance trade handling

- Added executeSwap method to handle signed swap transactions via the execute endpoint.
- Updated signAndPrepareJupiterSwapTransaction to include request ID and handle swap execution response.
- Modified trade details to use txId instead of id for Jupiter trades.
- Enhanced error handling for swap execution with user-friendly messages.
- Updated sendviewmodel to manage trade state updates after transaction commitment.

* fix: null error after successfully swapping

* fix: Finallyyy fixed the annoying tx history issue for solana dex swaps

* fix: update inputAddress to use toAddress in JupiterExchangeProvider

* feat: enhance transaction handling and token balance updates

- Cut down tx fetch/update time for transactions update after swapping
- Added TransactionFetchResult class to hold parsed transactions and token mints.
- Added pollForTransaction method to handle transaction polling with exponential backoff.
- Conditionally hide the external send button based on provider type.

* feat: add fees to trade object and handle null case

* feat: add Jupiter referral fee and account configuration

* fix: Jupiter dex swap fixes
- Fetch and display balance after each completed swap
- Make independent calls parallel, boosting balance display
- Remove incoming or outoging tags from tx history

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 21/100

This commit polishes the new Jupiter DEX swap feature for Solana wallets in Cake Wallet. It makes balance updates faster, fixes a transaction-history display quirk, and tweaks how swap details are copied to the clipboard. There is no clear security bug being fixed; it reads as ordinary feature hardening and UI cleanup.