CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
421commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 22 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedUpdate README.md (#2820)by Seth For Privacy · cd2f87a7 · Jan 19, 2026 · 1 fileMessage 36 · OpaqueInformational 15Details
Commit message · Seth For Privacy

Update README.md (#2820)

36/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply updates a single URL in the README file, changing the user guides link from guides.cakewallet.com to docs.cakewallet.com. There is no code change and no security issue visible in the diff.

AI review queuedminor fixesby OmarHatem · 6cb28d46 · Jan 17, 2026 · 18 filesMessage 0 · OpaqueInformational 23Details
Commit message · OmarHatem

minor fixes

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 23/100

This commit is titled 'minor fixes' and mostly contains routine maintenance: pinning a shared library (on_chain) to a specific commit hash, a small UI spacing tweak, a test update, and a few app-logic hardening changes. The most notable security-relevant change is in the Jupiter exchange provider, where the code now explicitly checks that both the 'from' and 'to' currencies are Solana-based tokens before fetching prices or creating trades. Previously, the provider relied on a pre-generated list of supported pairs, which could be bypassed or become stale. Another change hides the recipient address after exchanges involving Zcash, matching the privacy behavior already used for Monero and Wownero. A Solana client cleanup removes an unused HTTP client field, and a send-sheet popup check adds a guard to avoid calling Navigator.pop when the dialog cannot be popped. None of these changes are described by the vendor as security fixes, and no external references or CVEs are supplied.

AI review queuedfix zcash not getting passed the group seedby OmarHatem · 5c166f0e · Jan 17, 2026 · 1 fileMessage 45 · ThinLow 44Details
Commit message · OmarHatem

fix zcash not getting passed the group seed

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 44/100

This commit fixes a bug where new Zcash wallets in Cake Wallet were created without receiving the user's recovery phrase (mnemonic seed). Instead of using the intended seed, the wallet likely fell back to generating or using a different seed internally. This could mean a user who wrote down their recovery phrase would later be unable to restore their Zcash wallet with that phrase, potentially locking them out of funds. It is a reliability/functional bug with possible loss-of-access consequences, not an obvious remote attack vector.

AI review queuedfeat: Integrate Jupiter DEX (#2761)by David Adegoke · cf795bcc · Jan 16, 2026 · 16 filesMessage 88 · StrongLow 35Details
Commit message · David Adegoke

feat: Integrate Jupiter DEX (#2761)

* feat: Integrate Jupiter DEX

* feat: Enable internal swaps

* feat: implement Jupiter swap execution api and enhance trade handling

- Added executeSwap method to handle signed swap transactions via the execute endpoint.
- Updated signAndPrepareJupiterSwapTransaction to include request ID and handle swap execution response.
- Modified trade details to use txId instead of id for Jupiter trades.
- Enhanced error handling for swap execution with user-friendly messages.
- Updated sendviewmodel to manage trade state updates after transaction commitment.

* fix: null error after successfully swapping

* fix: Finallyyy fixed the annoying tx history issue for solana dex swaps

* fix: update inputAddress to use toAddress in JupiterExchangeProvider

* feat: enhance transaction handling and token balance updates

- Cut down tx fetch/update time for transactions update after swapping
- Added TransactionFetchResult class to hold parsed transactions and token mints.
- Added pollForTransaction method to handle transaction polling with exponential backoff.
- Conditionally hide the external send button based on provider type.

* feat: add fees to trade object and handle null case

* feat: add Jupiter referral fee and account configuration

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 35/100

This commit adds a new Jupiter DEX (decentralized exchange) integration to Cake Wallet, allowing users to swap Solana-based tokens directly inside the app. It also changes how Solana transactions are parsed and how balances are updated after swaps. The changes are mostly feature additions and UI tweaks, not a security patch. There are some code-quality concerns—such as trusting external API responses, deriving counterparty addresses from the first account in an instruction, and adding referral fee configuration—but no direct evidence in the diff of an exploitable vulnerability.

AI review queuedfix conflict resolve issue (#2812)by Omar Hatem · 36877751 · Jan 16, 2026 · 2 filesMessage 53 · ThinInformational 16Details
Commit message · Omar Hatem

fix conflict resolve issue (#2812)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 16/100

This commit fixes two minor problems introduced when earlier code changes were merged together. One file had an unused import removed, and another file corrected a typo where a function was being called with square brackets instead of parentheses. The typo only affected the Zcash wallet fee-priority setting and would have caused a compile-time or runtime error rather than a silent security issue.

AI review queuedminor fix [skip ci]by OmarHatem · 0e485513 · Jan 15, 2026 · 2 filesMessage 28 · OpaqueInformational 17Details
Commit message · OmarHatem

minor fix [skip ci]

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 17/100

This is a tiny two-part patch. One change fixes a Flutter widget lifecycle check so a modal bottom sheet is shown only when the widget is still mounted. The other adds a harmless GPU-related error message to a list of exceptions that are ignored for crash-reporting purposes. There is no obvious security issue here.

AI review queuedminor fallback [skip ci]by OmarHatem · de33666b · Jan 15, 2026 · 1 fileMessage 28 · OpaqueLow 32Details
Commit message · OmarHatem

minor fallback [skip ci]

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 32/100

This is a small defensive fix in Cake Wallet's Litecoin address handling. When the wallet tries to create a private 'change' address using the optional MimbleWimble (MWEB) feature, it now checks that an MWEB address actually exists before using it. Previously, if MWEB was enabled but no MWEB address had been generated, the code could try to use a non-existent address, likely causing a crash or returning an invalid change address. The change makes the wallet fall back to the normal change-address path instead.

AI review queuedminor [skip ci]by OmarHatem · 400e6f90 · Jan 13, 2026 · 1 fileMessage 28 · OpaqueLow 25Details
Commit message · OmarHatem

minor [skip ci]

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 25/100

This is a tiny one-line UI fix in a mobile wallet app. It adds an extra check before closing a bottom sheet during a cryptocurrency trade, likely to prevent a crash or visual glitch when the screen has already been dismissed. There is no clear security relevance in the commit itself.

AI review queuedfix: custom Bitcoin Ledger derivation paths and update ledger-bitcoin dependency (#2798)by Konstantin Ullrich · 98aa1fd6 · Jan 9, 2026 · 3 filesMessage 93 · StrongLow 32Details
Commit message · Konstantin Ullrich

fix: custom Bitcoin Ledger derivation paths and update ledger-bitcoin dependency (#2798)

* fix: custom Bitcoin Ledger derivation paths and update ledger-bitcoin dependency

* fix: remove unused `derivationPath` in `signTransaction` method

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: broader security terminologysecond-pass: security-sensitive path
AI analysis · Low 32/100

This commit fixes how Cake Wallet handles custom Bitcoin account paths on Ledger hardware wallets. Previously, the app may have ignored a user's chosen derivation path when signing Bitcoin transactions with a Ledger, which could lead to signing from the wrong account or failing to find funds. The update also bumps the ledger-bitcoin plugin to a newer version. There is no direct evidence in the commit of a security vulnerability being exploited; it reads as a bug fix for correctness.

AI review queueddetect hogex inputs and only require 6 confs if so (#2786)by Hector Chu · ff88fa8d · Jan 9, 2026 · 4 filesMessage 58 · ThinLow 34Details
Commit message · Hector Chu

detect hogex inputs and only require 6 confs if so (#2786)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 34/100

This commit changes how Cake Wallet handles Litecoin MWEB (privacy feature) peg-out transactions. Previously, the wallet treated all non-MWEB inputs as if they were 'hog-ex' peg-outs and required 6 confirmations before spending them. The new code actually detects real hog-ex transactions by looking at transaction script patterns and only applies the 6-confirmation rule to genuine peg-outs. This is a correctness and usability fix, not a vulnerability patch, though the old behavior could have caused unnecessary transaction blocking.

AI review queuedsanity checks [skip ci]by OmarHatem · b2c379fc · Jan 8, 2026 · 3 filesMessage 28 · OpaqueLow 42Details
Commit message · OmarHatem

sanity checks [skip ci]

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 42/100

This commit adds fallback logic so that if a backup password is missing from secure storage, a new one is automatically generated. It also bumps app version numbers. The change looks like a defensive hardening fix: previously, code assumed the backup password was always present (using a force-unwrap `!`), which could crash or behave unpredictably if the value was absent. The patch replaces that assumption with a safe default and automatic regeneration.

AI review queuedawait wallet name check [skip ci]by OmarHatem · 934b50da · Dec 30, 2025 · 2 filesMessage 45 · ThinLow 49Details
Commit message · OmarHatem

await wallet name check [skip ci]

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 49/100

This commit fixes a bug where the app did not wait for a check that a wallet name already exists before continuing to create or restore a wallet. Because the check was not awaited, the app could proceed before knowing the result, potentially allowing a duplicate wallet to be created or overwriting an existing one. The fix simply adds 'await' so the check completes first.

AI review queuedfix: Minor fixes - Solana (#2737)by David Adegoke · f5754ed2 · Dec 24, 2025 · 6 filesMessage 88 · StrongInformational 20Details
Commit message · David Adegoke

fix: Minor fixes - Solana (#2737)

* fix: Minor fixes

* refactor: handle updates to connectivity status for swipe to send button

* fix: Remove Future.wait

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100

This commit makes small Solana-related fixes in the Cake Wallet app. It shortens a network-request delay, removes an unnecessary Observer wrapper from a QR-code address page, wraps a send-confirmation sheet in an Observer so the slide-to-send button reacts to connectivity changes, dims the slide icon when disabled, and adds a user-friendly error message for expired Solana block hashes. None of these changes appear to be security fixes; they are usability and reliability tweaks.

AI review queuedfix: prevent RBF for Silent Payment addresses in Bitcoin transactions (#2760)by Konstantin Ullrich · 6e9d76e4 · Dec 23, 2025 · 1 fileMessage 70 · AdequateLow 43Details
Commit message · Konstantin Ullrich

fix: prevent RBF for Silent Payment addresses in Bitcoin transactions (#2760)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 43/100

This commit stops users from using Replace-By-Fee (RBF) on Bitcoin transactions that were sent to Silent Payment addresses. RBF lets someone bump a low-fee Bitcoin transaction to speed it up, but doing it with Silent Payments could break privacy or cause the recipient's address to be reused or revealed in a harmful way. The fix checks the saved recipient address and disables the RBF option when it matches a Silent Payment address pattern.

AI review queuedRemove print (#2764)by David Adegoke · efcd38e6 · Dec 23, 2025 · 1 fileMessage 36 · OpaqueInformational 15Details
Commit message · David Adegoke

Remove print (#2764)

36/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit removes a single debug print statement that logged a wallet object to the console. It is a cleanup change with no security relevance. There is no vulnerability, no exploit path, and no user-facing behavior change beyond preventing a wallet object from appearing in logs.

AI review queuedfix: date on silent payments transactions (#2740)by Konstantin Ullrich · c208e8b5 · Dec 19, 2025 · 2 filesMessage 88 · StrongInformational 23Details
Commit message · Konstantin Ullrich

fix: date on silent payments transactions (#2740)

* fix: date on silent payments transactions

* fix: clear outdated Silent Payment Addresses during initialization

* fix: streamline Silent Payments address handling by using the first record only

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 23/100

This commit fixes two practical bugs in Cake Wallet's Bitcoin 'silent payments' feature. First, it corrects the source URL used to look up the date of a silent-payment transaction, switching from an old/invalid Cake mempool endpoint to the current one. Second, it clears stale silent-payment address records during wallet startup and only uses the first generated silent address when building the address list. There is no direct evidence in the commit of a security vulnerability being exploited; the changes are bug fixes and cleanup.

AI review queuedCw 1291 ledger fixes (#2741)by Omar Hatem · 6c12ed15 · Dec 19, 2025 · 5 filesMessage 76 · AdequateInformational 23Details
Commit message · Omar Hatem

Cw 1291 ledger fixes (#2741)

* fix: handle unexpected ViewModel in ledger connection process

* fix: add missing exception handler for `_QueuedFuture.execute` in `exception_handler.dart`

* fix: handle hardware wallet connection flow in exchange trade page

* refactor: replace hardware wallet conditional logic with switch statement for improved readability and future extensibility

* feat: add hardware wallet support for dEURO savings actions and approval flow

---------

Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 23/100

This commit fixes several bugs in Cake Wallet's handling of hardware wallets (Ledger, Trezor, BitBox, etc.). It makes sure hardware wallet users are prompted to connect their device before sending funds, using a savings feature, or approving transactions. It also adds a missing error handler and prevents the app from crashing when an unexpected wallet type appears during Ledger setup. There is no direct evidence this is a security patch, but the changes reduce the chance of failed or misrouted transactions for hardware wallet users.

AI review queuedRemove replaced electrum transactions (#2738)by malik1004x · d3ba9661 · Dec 17, 2025 · 1 fileMessage 68 · AdequateLow 35Details
Commit message · malik1004x

Remove replaced electrum transactions (#2738)

* fix: remove replaced btc transactions

* fix: remove replaced btc transactions

* remove debug print

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 35/100

This commit changes how Cake Wallet's Bitcoin wallet handles transaction history from Electrum servers. When refreshing balances, it now deletes any stored Bitcoin transactions that send to the wallet's address but are no longer returned by the Electrum server. The stated goal is to remove transactions that were replaced or invalidated, such as RBF (Replace-By-Fee) replacements. This is a data-cleanup fix, but it could affect what transactions the user sees and what the wallet believes is spendable.

AI review queuedFix db getting deleted on iOS (#2736)by Omar Hatem · aea855d0 · Dec 15, 2025 · 11 filesMessage 76 · AdequateModerate 54Details
Commit message · Omar Hatem

Fix db getting deleted on iOS (#2736)

* Fix db getting deleted on iOS

* Fix db getting deleted on iOS and add a patch for users who updated

* remove prints [skip ci]

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 54/100

This update fixes a bug where iPhones could accidentally delete or fail to find the app's wallet database, which could make users think their wallets were lost. It also patches related problems where restored wallets might pick the wrong address type (derivation path) after the database move. The release notes only say 'Bug fixes' and do not describe the security relevance.

AI review queuedminor fix [skip ci]by OmarHatem · 9458f604 · Dec 12, 2025 · 1 fileMessage 28 · OpaqueInformational 21Details
Commit message · OmarHatem

minor fix [skip ci]

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 21/100

This is a small defensive UI fix in the cryptocurrency wallet's send/swap flow. Before popping a screen, the code now checks that the widget is still active and that there is actually a screen to go back to. This prevents a potential app crash if a user triggers the swap flow when there is no previous screen to return to, or after the screen has been closed.

AI review queuedRemove SecretStore class for Backup viewmodels (fix for backup password not restoring) (#2723)by malik1004x · 7464ead4 · Dec 11, 2025 · 6 filesMessage 73 · AdequateLow 30Details
Commit message · malik1004x

Remove SecretStore class for Backup viewmodels (fix for backup password not restoring) (#2723)

* backup page viewmodels without secretstore class

* minor reaction optimization

* minor reaction optimization

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
second-pass: broader security terminology
AI analysis · Low 30/100

This commit fixes a bug where the backup password was not being restored or applied correctly in Cake Wallet. It removes a separate in-memory 'SecretStore' class and instead has the backup screen and backup-password editing screen share one view-model directly. The change also adds a guard so you cannot export a backup when no password is set. There is no direct evidence in the commit of a security vulnerability being exploited; it reads as a reliability/bug-fix, though a missing backup password could weaken backup security.

AI review queuedfix restoring from QRby OmarHatem · 13a56574 · Dec 11, 2025 · 1 fileMessage 28 · OpaqueInformational 24Details
Commit message · OmarHatem

fix restoring from QR

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 24/100

This commit fixes a crash when restoring a cryptocurrency wallet from a QR code. The old code tried to convert an 'xpub' value even when it didn't exist, which would cause an error. The fix only runs the conversion if the value is actually present. There is no direct evidence this is a security vulnerability, but a crash during wallet restore could disrupt user access to funds.

AI review queuedminor fix (#2717)by Omar Hatem · 625a050e · Dec 11, 2025 · 1 fileMessage 36 · OpaqueInformational 15Details
Commit message · Omar Hatem

minor fix (#2717)

36/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This is a tiny one-line change that adds an empty catch block so an error during a Monero wallet blockchain-height refresh does not crash the code path. It is a defensive stability fix, not a security patch, and there is no indication it addresses a vulnerability.

AI review queueddebugging workflowby OmarHatem · 701b167a · Dec 11, 2025 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · OmarHatem

debugging workflow

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply removes a temporary debugging job from an Android build workflow. It deletes steps that printed GitHub context and pull request details during CI runs. There is no change to application code, secrets, permissions, or security behavior.

AI review queueddebugging workflowby OmarHatem · 05bffff1 · Dec 11, 2025 · 1 fileMessage 18 · OpaqueInformational 17Details
Commit message · OmarHatem

debugging workflow

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 17/100

This commit changes a GitHub Actions workflow file for Android test builds. It removes automatic triggers for regular pushes and for pull_request_target events, leaving only standard pull_request triggers. It also adds a large commented-out block showing an alternative workflow path for external fork pull requests. The change appears to be a debugging or hardening adjustment to how CI runs, not a code change in the app itself. There is no direct evidence this fixes a security vulnerability, but narrowing CI triggers can reduce attack surface for supply-chain-style abuse.