CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
420commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 29 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedFix restoring duplicate hardware wallet (#2673)by Omar Hatem · a4a6e2e3 · Nov 24, 2025 · 1 fileMessage 53 · ThinLow 30Details
Commit message · Omar Hatem

Fix restoring duplicate hardware wallet (#2673)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 30/100

This commit fixes a bug where restoring the same hardware wallet twice could create duplicate wallet entries. The change makes the wallet creation code reuse a single WalletInfo object instead of creating a separate copy, ensuring that saving updates the existing record rather than potentially writing a new one. There is no direct evidence of a security vulnerability such as theft of funds; the issue appears to be a data-integrity/duplicate-record bug.

AI review queuedminor fixes [skip ci]by OmarHatem · f0524bce · Nov 24, 2025 · 3 filesMessage 28 · OpaqueInformational 15Details
Commit message · OmarHatem

minor fixes [skip ci]

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit makes three small, unrelated changes: it updates iOS dependency lock files to include SQLite-related libraries, removes a 'throw e' after an error dialog in a Nano representative-change screen, and adds 'context.mounted' checks before showing bottom sheets during payment flows. The UI fixes prevent harmless Flutter exceptions when a widget is no longer on screen, while the Podfile.lock change is a routine dependency bookkeeping update.

AI review queuedDark and tinted icons for iOS (#2671)by malik1004x · 908c8de2 · Nov 24, 2025 · 95 filesMessage 68 · AdequateInformational 15Details
Commit message · malik1004x

Dark and tinted icons for iOS (#2671)

* feat: new ios icon format with dark/tinted icons

* feat: switch monero.com icons to new format

* update gitignore

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a cosmetic update for iOS app icons. It adds new dark-mode and tinted icon variants for Cake Wallet and refreshes the icon set for Monero.com. There are no code changes that affect security, privacy, or how the app handles money or data.

AI review queuedHide available balance in send card (#2662)by malik1004x · 7172928e · Nov 21, 2025 · 30 filesMessage 76 · AdequateInformational 20Details
Commit message · malik1004x

Hide available balance in send card (#2662)

* hide available balance on send page when balance is hidden

* hide available balance on send page when balance is hidden

* allow show/hide of balance from send card

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 20/100

This commit is a small privacy/usability fix for the send screen. It makes the wallet's available balance respect the user's 'hide balance' setting, and lets them tap to temporarily reveal it. There is no security vulnerability being fixed here.

AI review queuedUpdate monero_wallet_service.dart (#2666)by Serhii · f05d6ef1 · Nov 21, 2025 · 1 fileMessage 43 · ThinLow 25Details
Commit message · Serhii

Update monero_wallet_service.dart (#2666)

43/100 · ThinMessage clarity
✓ Descriptive subject✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 25/100

This commit removes a single line that saved wallet metadata to persistent storage after creating a Monero wallet from a BIP39 seed phrase. The change could mean wallet details are not written to disk at this point, which might affect recovery, wallet listing, or data consistency. There is no clear evidence in the commit itself that this is a security fix, exploit, or intentional vulnerability patch.

AI review queuedCW1272 tails, linux generic fixes (#2630)by cyan · a7734c5c · Nov 20, 2025 · 16 filesMessage 76 · AdequateLow 27Details
Commit message · cyan

CW1272 tails, linux generic fixes (#2630)

* fix: linux/tails fixes, sqlite fix on linux

* add sqlite deps

* fix: old/new dir migration from .local

* fix: tails path, local/share old names for compatibility

* Update cw_core/lib/db/sqlite.dart

Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>

* fix: close icon on desktop [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>
Co-authored-by: Konstantin Ullrich <konstantinullrich12@gmail.com>
Co-authored-by: Konstiantin Ullrich <konstantin@cakewallet.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 27/100

This commit fixes Linux and Tails-specific app-data handling, switches SQLite to a desktop-compatible implementation, and corrects a broken icon asset. It is primarily a compatibility and bug-fix patch. There is no direct evidence in the commit that it addresses a security vulnerability, but the changes touch sensitive areas: where wallet data is stored, how old data directories are migrated, and how Tor/SOCKS proxy settings are parsed on a privacy-focused OS (Tails).

AI review queuedminor fixes [skip ci]by OmarHatem · 954ac34c · Nov 17, 2025 · 2 filesMessage 28 · OpaqueInformational 20Details
Commit message · OmarHatem

minor fixes [skip ci]

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 20/100

This small patch fixes two minor issues in a cryptocurrency wallet app. One change makes sure a settings toggle waits for its background task to finish before continuing, which could prevent a race condition or incomplete state. The other change makes the app correctly recognize when its Tor privacy feature is disabled, so it doesn't try to stop a service that was never running. These are defensive bug fixes rather than obvious security holes, but they touch privacy and notification settings.

AI review queuedCw 1247 improve tabs navigation (#2634)by Serhii · cbf8e7d0 · Nov 14, 2025 · 44 filesMessage 76 · AdequateInformational 15Details
Commit message · Serhii

Cw 1247 improve tabs navigation (#2634)

* add dashboard page indicator

* refactor dashboard page indicator and UI

* refactor fade animation

* smoother UI transitions

* Improve accessibility for page indicator

* localize action names

* Update page indicator colors and blur effect

* fix page indicator layout

* Update Spanish translations for 'apps', 'history', and 'home'

* update dashboard labels

* changed settings page label

* Modify page_indicator.dart

* refactor page indicator animation

* review fixes

---------

Co-authored-by: Jaim3 <github@jaim3.com>
Co-authored-by: tuxsudo <tuxsudo@tux.pizza>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a routine user-interface redesign for the Cake Wallet app's dashboard. It replaces the old dot-style page indicator with a new labeled pill-style indicator, adds new icons, shortens the bottom navigation dock, and updates translations for labels like 'Apps', 'History', and 'Home'. There is no security-relevant change visible in the code.

AI review queuedfix: Sync bar ETA (#2515)by David Adegoke · 9775f7a6 · Nov 12, 2025 · 6 filesMessage 88 · StrongInformational 20Details
Commit message · David Adegoke

fix: Sync bar ETA (#2515)

* fix: Sync bar ETA

* fix: Smooth ETA - WIP

* fix: Show disconnected status when sync disconnects

* feat: Display blocks remaining for the first five seconds and then switch to percentage

* Update

* fix: Extend duration for showing blocks remaining during sync from 5 to 15 seconds; update connectivity check to handle multiple connectivity results, and handle disconnected state while syncing

* feat: Initially display block if the a reconnection is triggered while syncing

* fix: More improvements to syncing

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100

This commit fixes how the wallet's sync progress bar estimates and displays remaining time. It changes when the app shows 'blocks remaining' versus a percentage, smooths the ETA calculation, and makes the connection-status check correctly show 'disconnected' if the network drops while syncing. There is no direct security vulnerability being patched; it is a user-experience and reliability improvement for sync feedback.

AI review queuedCW-1238-Solana-Fixes (#2620)by David Adegoke · edcf6ffe · Nov 11, 2025 · 37 filesMessage 76 · AdequateInformational 24Details
Commit message · David Adegoke

CW-1238-Solana-Fixes (#2620)

* refactor: optimize SPL token transaction and balance fetching with batch processing

* fix: SPL tokens not populating all fields

* fix:Solana Fixes

- Optimize SPL token transactions and balance fetching
- Auto Populate all fields when fetching SPL tokens
- Gracefully handle errors when sending Solana tokens

* fix: update wallet compatibility check in LinkViewModel

* feat: add Moralis API key to secrets

* Update

* feat: Add error handling for invalid associated token accounts in Solana transactions

* fix: Add cleaning for reown to linux ci

* refactor: Update transactions after eveey batch fetch

* fix: make error messages more readable

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 24/100

This commit is a routine bug-fix and performance-improvement patch for Solana (SPL token) handling in Cake Wallet. It batches token balance and transaction fetching, fills in missing token metadata via a new Moralis API, improves error messages, and fixes a wallet-connect compatibility check. There is no direct evidence in the commit of a security vulnerability being fixed; it reads as a stability/usability improvement.

AI review queuedCW-1190: Minor Fixes (#2614)by David Adegoke · 9fa4584d · Nov 8, 2025 · 9 filesMessage 76 · AdequateLow 48Details
Commit message · David Adegoke

CW-1190: Minor Fixes (#2614)

* fix: Enhance WalletConnect URI handling and validation, better handle errors

* fix: Disable swipe to send if wallet is not synchronized

* fix: Handle session expiry gracefully

* fix: Disable swipe to send if wallet is not synced

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 48/100

This commit is a routine bug-fix patch titled 'Minor Fixes'. It mainly does two things: it prevents users from accidentally sending cryptocurrency while their wallet is still synchronizing, and it makes WalletConnect URI handling more robust by trimming whitespace, stripping stray '@' prefixes, and handling session expiry errors more gracefully. There is no direct evidence in the commit that these fixes address an active security exploit; they appear to be defensive hardening and usability improvements.

AI review queuedFix untappable area of wallets page (#2636)by tuxsudo · 19362df2 · Nov 8, 2025 · 1 fileMessage 68 · AdequateInformational 15Details
Commit message · tuxsudo

Fix untappable area of wallets page (#2636)

* Fix untappable area of wallets page

* Cleanup

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit fixes a user-interface bug where a decorative gradient overlay on the wallets page was accidentally blocking taps on buttons underneath it. The fix wraps the gradient in an IgnorePointer widget so it no longer intercepts touches, while keeping the actual buttons tappable. There is no security relevance in this change.

AI review queuedcleaning reown previous folderby OmarHatem · 78e6660a · Nov 7, 2025 · 1 fileMessage 35 · OpaqueInformational 17Details
Commit message · OmarHatem

cleaning reown previous folder

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 17/100

This commit changes an Android build script to delete leftover files from a previous download before downloading a fresh copy of a software package called reown_flutter. On its own, this is a routine cleanup step in a CI/CD build pipeline. There is no direct evidence in the commit that it fixes a security vulnerability, but it removes a potential source of stale or tampered files being reused accidentally during builds.

AI review queuedrefactor: Optimize gas fee calculations for Base chain transactions (#2613)by David Adegoke · 68dd3f28 · Nov 6, 2025 · 6 filesMessage 93 · StrongLow 28Details
Commit message · David Adegoke

refactor: Optimize gas fee calculations for Base chain transactions (#2613)

* refactor: Optimize gas fee calculations for Base chain transactions

* feat: Added an abstract method for priority fee calculations in EVMChainWallet class, and implemented it across the evm wallets.

* fix: Estimated fee on send screen for base wallet different from fee on swipe to send bottomsheet

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 28/100

This commit refactors how gas fees are calculated for Base, Polygon, Ethereum, and Arbitrum wallets in Cake Wallet. It moves chain-specific priority fee logic out of shared code into each chain's wallet class, fixes a mismatch between the fee shown on the send screen and the fee shown on the final confirmation screen, and increases the safety buffer used when sending the entire balance on Base. There is no direct evidence this fixes an active exploit or security vulnerability, but it does reduce the risk of users accidentally overpaying or underpaying fees and improves consistency in fee display.

AI review queuedCode cleanupby OmarHatem · 507be140 · Nov 6, 2025 · 3 filesMessage 18 · OpaqueInformational 15Details
Commit message · OmarHatem

Code cleanup

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit removes an unused 'change your asset' button and its related code from the send-money screen. It only affects the Haven wallet type, which no longer shows a currency picker during sending. There is no security issue here—it's purely cleanup of dead UI code.

AI review queued- disable Arbitrum - Minor fixes - Code cleanupby OmarHatem · df11f87e · Nov 6, 2025 · 10 filesMessage 60 · AdequateInformational 23Details
Commit message · OmarHatem

- disable Arbitrum
- Minor fixes
- Code cleanup

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 23/100

This commit mostly disables the Arbitrum cryptocurrency across build scripts and rewrites fee-estimation code. It also adds two small safety checks: one to prevent a crash when a Wownero wallet pointer is null, and another to wrap a Nano network call in a try/catch so an unexpected node response doesn't crash the app. There is no clear security vulnerability being fixed; it looks like routine cleanup and hardening.

AI review queuedUpdate issue templatesby Omar Hatem · 569ee044 · Nov 5, 2025 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Omar Hatem

Update issue templates

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit adds a standard GitHub feature-request template. It is purely a project-management/documentation change and does not touch any code, configuration, or security controls.

AI review queuedtolerate nullable payment methodsby OmarHatem · dd772d84 · Nov 2, 2025 · 3 filesMessage 35 · OpaqueInformational 24Details
Commit message · OmarHatem

tolerate nullable payment methods

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 24/100

This commit makes the Cake Pay gift-card/order feature more forgiving when a vendor response does not include payment details for every supported cryptocurrency. Previously the app would crash if a field such as BTC or XMR was missing; now it accepts null values and removes a couple of fallback empty-string defaults when building the order record. The change is primarily a robustness/crash-fix, not a clear security patch.

AI review queuedfixate grpc versionby OmarHatem · 71852592 · Oct 31, 2025 · 3 filesMessage 28 · OpaqueLow 26Details
Commit message · OmarHatem

fixate grpc version

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 26/100

This commit pins the 'grpc' networking library to a specific older version (4.0.1) instead of allowing newer compatible versions. It also downgrades a related Google authentication package from 2.0.0 to 1.6.0. The change appears to be a build-stability or compatibility fix rather than a response to a known security vulnerability, but pinning dependencies can affect which security patches are received in future builds.

AI review queuedfix: better handle exchange url launchingby OmarHatem · f5119d26 · Oct 31, 2025 · 4 filesMessage 57 · ThinInformational 23Details
Commit message · OmarHatem

fix: better handle exchange url launching

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 23/100

This commit improves how the Cake Wallet app handles failures when opening a third-party cryptocurrency exchange website. It adds error messages so users see clearer warnings (for example, if the exchange blocks Tor connections), fixes a typo in variable names, and prevents a possible app crash when dismissing a wallet-loading warning. There is no direct evidence this fixes an active security vulnerability, but it makes the buy/sell flow more robust and user-friendly.

AI review queuedchore: update `trezor_connect` dependency to latest commit hash across pubspec files (#2618)by Konstantin Ullrich · 55bae6c5 · Oct 30, 2025 · 3 filesMessage 70 · AdequateInformational 15Details
Commit message · Konstantin Ullrich

chore: update `trezor_connect` dependency to latest commit hash across pubspec files (#2618)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
second-pass: broader security terminology
AI analysis · Informational 15/100

This commit simply updates the version (commit hash) of an internal dependency called trezor_connect in three package configuration files. There is no code change in the Cake Wallet repository itself, and no security-related explanation is provided in the commit.

AI review queuedEnable SSL for some nodes [skip ci]by OmarHatem · f47509eb · Oct 28, 2025 · 2 filesMessage 45 · ThinLow 42Details
Commit message · OmarHatem

Enable SSL for some nodes [skip ci]

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
second-pass: broader security terminology
AI analysis · Low 42/100

This commit turns on HTTPS/SSL encryption for several built-in Ethereum and Polygon server connections in the Cake Wallet app. Without SSL, data sent between the wallet and those servers could be read or tampered with by attackers on the same network. The change is a security improvement, not a vulnerability introduction, but it fixes a real exposure for users who relied on these default nodes.

AI review queuedAdd support for Ledger Nano Gen 5 (#2609)by Konstantin Ullrich · 47d93bd4 · Oct 28, 2025 · 5 filesMessage 76 · AdequateInformational 21Details
Commit message · Konstantin Ullrich

Add support for Ledger Nano Gen 5 (#2609)

* chore: update `ledger_flutter_plus` dependency to new repository URL and commit hash in `pubspec_base.yaml`

* feat: add support for Ledger Nano Gen 5 hardware wallet and include new SVG asset

* chore: update `ledger_flutter_plus` dependency reference and remove redundant method call in `LedgerViewModel`

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: broader security terminologysecond-pass: security-sensitive path
AI analysis · Informational 21/100

This commit adds support for a new Ledger hardware wallet model (Ledger Nano Gen 5) in the Cake Wallet app. It updates an internal device list, adds an icon, and switches the app to use a fork of the Ledger library maintained by Cake Wallet's own team. The code change also removes a redundant method argument when listening for device connection state changes. There is no direct evidence in the commit that this fixes a security vulnerability; it appears to be a routine feature addition and dependency maintenance change.

AI review queuedCleanup and Bug fixesby OmarHatem · 7b9cd9ec · Oct 27, 2025 · 7 filesMessage 28 · OpaqueLow 32Details
Commit message · OmarHatem

Cleanup and Bug fixes

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 32/100

This commit is a routine 'Cleanup and Bug fixes' patch for the Cake Wallet cryptocurrency app. It mainly refactors transaction-committing code, fixes a possible crash when closing a payment-result screen, adds retry logic for Payjoin network setup, and improves how the exchange screen decides whether the deposit currency matches the current wallet. There is no clear security vulnerability being fixed, but the changes do remove some fragile UI behavior and make transaction handling more consistent.

AI review queuedEnhance EVM Fees Error Handling (#2610)by David Adegoke · 226addcc · Oct 25, 2025 · 2 filesMessage 76 · AdequateInformational 19Details
Commit message · David Adegoke

Enhance EVM Fees Error Handling (#2610)

* fix: Add more patterns to the EVM fees error handler

* refactor: Enhance EVM transaction error handling with multiple parsing patterns

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit improves how the Cake Wallet app reads and displays error messages when an Ethereum-compatible transaction fails due to not enough funds for fees. It adds support for more message formats and shows a simpler 'insufficient funds' message when the app cannot extract exact numbers. There is no direct evidence this fixes an active security vulnerability; it appears to be a user-experience and robustness improvement.