Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
This commit removes a feature that automatically cranked screen brightness to maximum when showing a wallet's seed/keys as a QR code. In some cases the brightness stayed stuck at max after closing the QR screen, which could let someone nea…
Removal of forced-max-brightness wrapper around sensitive QR displayPotential shoulder-surf / camera-surveillance risk from bright screen showing seed/keysState-cleanup bug in brightness restoration on non-normal route returns
This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…
This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…
New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…
Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …
New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…
Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…
Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…
Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…
UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…
No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…
UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…
Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…
No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…
Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…
Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…
Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…
New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …
Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…
Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100
This commit improves how the Cake Wallet app reads and displays error messages when an Ethereum-compatible transaction fails due to not enough funds for fees. It adds support for more message formats and shows a simpler 'insufficient funds' message when the app cannot extract exact numbers. There is no direct evidence this fixes an active security vulnerability; it appears to be a user-experience and robustness improvement.
AI review queuedfix: Already Known Error (#2606)by David Adegoke · b0b053a1 · Oct 25, 2025 · 5 filesMessage 88 · StrongInformational 23Details
Commit message · David Adegoke
fix: Already Known Error (#2606)
* fix: Already made error and update transactions two seconds after successful send for evm, tron and sol
* feat: Add updateTransactionsHistory method on WalletBase to handle transaction update immediately after sending
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 23/100
This commit fixes a user-facing bug where sending cryptocurrency through EVM chains (Ethereum, Polygon, Base), Solana, or Tron could produce an 'Already Known' error or fail to show the new transaction promptly. It adds a new method to refresh transaction history and calls it a few seconds after a successful send. The code also includes unrelated formatting cleanups and a small refactor of how EVM wallet types are detected. There is no direct evidence in the commit of a security vulnerability being patched.
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 15/100
This commit only changes user-facing text (translations) in the app. It updates the description for the hardware wallet restore option from mentioning only 'Ledger' to a more generic wording about linking hardware wallets from various manufacturers. No code logic, security behavior, or functionality was modified.
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 34/100
This commit fixes how Dogecoin transaction fees are calculated in Cake Wallet. Previously, the app likely relied on a Bitcoin-style size estimate that doesn't match Dogecoin's typical transaction structure. The change adds a Dogecoin-specific formula to estimate transaction size (and therefore fee) more accurately. An incorrect size estimate could lead to users paying too much or too little in fees, which in extreme cases can cause transactions to get stuck or be delayed.
AI review queuedCw 1117 prevent sending a transaction twice by mistake (#2567)by Serhii · f7d29c9f · Oct 9, 2025 · 4 filesMessage 81 · StrongLow 46Details
Commit message · Serhii
Cw 1117 prevent sending a transaction twice by mistake (#2567)
* Revert "Prevent double send actions in SendPage (#2542)"
This reverts commit dd4c941d2f356d7c4f2d39e9744ab43bbe1962c7.
* disable send buttons when ExecutedSuccessfully
* return value on bottom sheet pop [skip ci]
81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 46/100
This update fixes a user-interface bug where someone could accidentally trigger a cryptocurrency send twice in a row, for example by double-tapping a button. The app now disables the send button once a transaction has been successfully prepared, and it properly cancels the prepared transaction if the confirmation bottom sheet is closed without sliding to confirm. This reduces the chance of sending funds twice or leaving a half-prepared transaction open.
AI review queuedfix: Remove check for zero transaction amounts in transactions page (#2559)by David Adegoke · 6cacfd08 · Oct 6, 2025 · 1 fileMessage 93 · StrongInformational 19Details
Commit message · David Adegoke
fix: Remove check for zero transaction amounts in transactions page (#2559)
* fix: Polygon transactions not coming up in transactions history page
* fix: Filter out polygon spam transactions
* fix: Remove check for zero transaction amounts in transactions page
* fix: remove redundant check for zero transaction amounts in transactions page
93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100
This commit removes a UI filter that previously hid transactions with a zero amount from the wallet's transaction history page. The change means users will now see zero-amount transactions (for example, some Polygon spam transactions or failed/minimal transfers) in their history instead of them being hidden. There is no direct evidence in the commit that this fixes a security vulnerability; it appears to be a usability fix to ensure legitimate transactions are not accidentally hidden.
AI review queuedminor fix [skip ci]by OmarHatem · 9214fd63 · Oct 5, 2025 · 1 fileMessage 28 · OpaqueLow 28Details
Commit message · OmarHatem
minor fix [skip ci]
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 28/100
This is a small defensive fix in a mobile wallet's gift-card purchase screen. It checks that the Flutter UI context is still active before opening a bottom-sheet popup. Without the check, the app could try to display a popup after the user had already left the screen, which can cause a crash or a confusing error message. It is a stability/reliability improvement, not a security vulnerability fix.
AI review queuedminor fix [skip ci]by OmarHatem · b7156c3f · Oct 4, 2025 · 1 fileMessage 28 · OpaqueInformational 18Details
Commit message · OmarHatem
minor fix [skip ci]
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 18/100
This is a small UI hardening change in a wallet app's back-arrow button. It now checks whether the screen is still active and whether there is a previous screen before trying to go back. Without the guard, pressing the button at the wrong moment could trigger a harmless framework warning or a minor navigation error, but it does not appear to expose funds, keys, or sensitive data.
AI review queuedfeat: handle `label` restore field from cupcake (#2551)by cyan · 9843c3c1 · Oct 3, 2025 · 2 filesMessage 70 · AdequateInformational 19Details
Commit message · cyan
feat: handle `label` restore field from cupcake (#2551)
70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100
This commit adds support for a 'label' field when restoring a wallet from a backup or QR code created by another app called Cupcake. It simply copies that label into the wallet name fields during restore. There is no obvious security bug here; it is a small feature addition.