CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
421commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 16 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queueddisable exolix [skip ci]by Omar · 6c54a4ee · Jul 26, 2026 · 2 filesMessage 28 · OpaqueLow 32Details
Commit message · Omar

disable exolix [skip ci]

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 32/100

This commit disables the Exolix cryptocurrency exchange provider in the Cake Wallet app. It adds a one-time settings migration that turns Exolix off for all users and bumps the migration version so the change runs on app startup. The commit message gives no reason, and there are no supplied references explaining whether this is a security fix, a business decision, or a response to an incident.

AI review queuedfix btc address lookup (#3422)by Serhii · 24a884b3 · Jul 25, 2026 · 1 fileMessage 53 · ThinLow 44Details
Commit message · Serhii

fix btc address lookup (#3422)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 44/100

This commit fixes how Cake Wallet looks up Bitcoin addresses when checking transaction history. Previously, the code mixed up 'change' (internal) addresses and 'receive' (external) addresses, and did not properly separate newer standard addresses from older legacy addresses. The fix organizes addresses into four clear groups—standard receive, standard change, legacy receive, and legacy change—and checks each group separately. This likely prevents the wallet from missing transactions or incorrectly marking address gaps, which could affect balance accuracy. There is no direct evidence in the commit that this was a security vulnerability or that it could be exploited by an attacker.

AI review queuedupdate build numbersby Omar · a04171bd · Jul 23, 2026 · 2 filesMessage 28 · OpaqueInformational 15Details
Commit message · Omar

update build numbers

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates the app's version and build numbers in build scripts for Android and iOS. It does not change any code that handles money, user data, security, or app behavior. There is no security issue here.

AI review queuedfix: stop resetting coin control on swap (#3433)by Konstantin Ullrich · 8056cfec · Jul 22, 2026 · 2 filesMessage 65 · AdequateLow 26Details
Commit message · Konstantin Ullrich

fix: stop resetting coin control on swap (#3433)

65/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 26/100

This commit fixes a bug where the user's coin-control choices were being reset when swapping between send screens. Coin control lets a user choose exactly which coins (UTXOs) are spent. Previously, the app called a reset function after initial setup, clearing any selections the user had made. The patch removes that reset and also makes the code that tracks coins compare them by their unique transaction hash and output index rather than by a looser object equality, which should make coin tracking more reliable.

AI review queuedupdate build numbersby Omar · 7a05544c · Jul 22, 2026 · 2 filesMessage 28 · OpaqueInformational 15Details
Commit message · Omar

update build numbers

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only increments the app's build number from 4415 to 4416 on Android and from 425 to 426 on iOS. It changes no code, fixes no behavior, and has no security relevance visible in the diff.

AI review queuedfix: address leaks (#3426)by cyan · 7dd048d2 · Jul 21, 2026 · 1 fileMessage 55 · ThinLow 49Details
Commit message · cyan

fix: address leaks (#3426)

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 49/100

This commit changes how Zcash wallet addresses are stored in the app's local wallet info. Instead of saving the full address map to persistent storage, it now saves an empty map, while still saving related metadata like address info, used addresses, and hidden addresses. The commit title says this fixes 'address leaks,' which suggests the previous behavior may have exposed or stored more address data than intended. However, the diff alone does not show what specific sensitive data was leaking, to whom, or under what conditions.

AI review queuedupdate app versionsby Omar · e4f1660a · Jul 21, 2026 · 5 filesMessage 28 · OpaqueInformational 15Details
Commit message · Omar

update app versions

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only updates version numbers and build numbers across platform-specific build scripts. It does not change any application code, cryptographic logic, network handling, or user-facing behavior. There is no security relevance.

AI review queued26-07-21_Update Translation_de_DEby bsn21m · 0070c612 · Jul 21, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · bsn21m

26-07-21_Update Translation_de_DE

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only adds a few German translations for user-facing text strings (for example, labels related to passphrases and an 'Autoshield' feature). There are no code changes, no security fixes, and no behavior changes.

AI review queuedrefactor: remove deprecated payment URI classes and unify URI handling with `ERC681URI` implementation (#3423)by Konstantin Ullrich · b336da4a · Jul 20, 2026 · 3 filesMessage 93 · StrongInformational 14Details
Commit message · Konstantin Ullrich

refactor: remove deprecated payment URI classes and unify URI handling with `ERC681URI` implementation (#3423)

* refactor: remove deprecated payment URI classes and unify URI handling with `ERC681URI` implementation

* refactor: apply lint [skip ci]

93/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 14/100

This commit is a code cleanup: it removes several old, near-duplicate payment-URI classes for Ethereum-compatible chains (Polygon, Base, Arbitrum, BSC) and makes every EVM chain use a single shared ERC-681 URI builder. It also adds a parser to read those URIs back. The change is mostly a refactor with no obvious security bug, but it touches code that formats crypto payment amounts and addresses, so a small risk of accidental parsing/formatting mistakes remains.

AI review queuedCw 1539 lightning enhancements (#3400)by Konstantin Ullrich · 03edd658 · Jul 17, 2026 · 18 filesMessage 86 · StrongInformational 24Details
Commit message · Konstantin Ullrich

Cw 1539 lightning enhancements (#3400)

* feat: add Lightning transaction URL support in transaction details view model

* fix: update currency selection logic in WalletAddressListViewModel and ReceivePage

* feat: integrate computed transaction amount and fee getters in TransactionDetailsViewModel, refactor CopyWrapper logic in TransactionDetailsModal

* refactor: apply lint rules

* refactor: apply lint rules and improve LNURL handling with new methods for withdrawal requests and error checks

* auto-reformat

* fix: receive_page regression

* fix: Withdraw lightning to other btc wallet gives LN address

* chore: update .lock files [skip ci]

---------

Co-authored-by: Robert Malikowski <malikowskirobert@gmail.com>
Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

86/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 24/100

This is a routine feature and bug-fix update for Cake Wallet's Lightning (Bitcoin layer-2) support. It adds the ability to handle LNURL withdrawal requests, fixes currency selection when receiving Bitcoin vs Lightning, and cleans up transaction-detail display. There is no clear security vulnerability in the diff, but the new network code that calls external Lightning services and parses invoices is a place where future bugs could matter, so it deserves normal review and testing.

AI review queuedadd spaceby Robert Malikowski · 07d78b0a · Jul 17, 2026 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Robert Malikowski

add space

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit fixes a simple Dart syntax error by adding a missing space between the keyword `const` and `BorderRadius.only`. It is a cosmetic/code-correctness change with no security relevance.

AI review queuedmergeby Robert Malikowski · 108363c5 · Jul 17, 2026 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Robert Malikowski

merge

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit adds a single optional parameter named `bottomText` to a user-interface widget class. It is a straightforward code change with no visible security relevance.

AI review queueddart fixby Robert Malikowski · fa9229ec · Jul 17, 2026 · 1 fileMessage 0 · OpaqueInformational 15Details
Commit message · Robert Malikowski

dart fix

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a routine code cleanup of a single Dart file in the Cake Wallet app's buy/sell screen. It changes quote styles on imports, adds 'const' keywords, reformats function bodies, and reorders constructor parameters. There is no change to app behavior, no bug fix, and no security relevance visible in the diff.

AI review queueddelete solana sync keys when removing the walletby Omar · c10ce20c · Jul 16, 2026 · 1 fileMessage 45 · ThinLow 47Details
Commit message · Omar

delete solana sync keys when removing the wallet

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 47/100

This commit fixes a cleanup issue in Cake Wallet's Solana support. When a user deleted a Solana wallet, the app left behind leftover 'last synced signature' data stored on the device. This patch now deletes those leftover records when the wallet is removed. It is a privacy/data-hygiene fix rather than a remote hack vulnerability.

AI review queuedCW-1548: Solana wallet performance improvements (#3404)by David Adegoke · 0822c7d9 · Jul 16, 2026 · 10 filesMessage 81 · StrongInformational 17Details
Commit message · David Adegoke

CW-1548: Solana wallet performance improvements (#3404)

* fix android CI

* add incremental sync, parallel fetch for native and spl token, and other improvments on perf and display regarding lagging

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 17/100

This commit is a routine performance and reliability improvement for Solana wallets in Cake Wallet. It makes transaction syncing faster by only fetching new signatures since the last sync, batches network requests, prevents duplicate refreshes, and fixes a few small UI calculation bugs. There is no clear security vulnerability being patched, and the changes do not appear to introduce one.

AI review queuedawait wallet address saving (#3393)by Omar Hatem · bfc2c5ee · Jul 14, 2026 · 4 filesMessage 53 · ThinLow 29Details
Commit message · Omar Hatem

await wallet address saving (#3393)

minor CI fix

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 29/100

This commit fixes a timing bug in how the wallet saves address records. Previously, several save operations were started without waiting for each to finish, which could cause them to overlap or complete out of order. The change makes the code wait for each save step before starting the next one, and also tweaks how address lists are copied to avoid a subtle race where the list could change mid-save. A new network error message is also added to the ignore list, and a CI workflow step is adjusted.

AI review queuedadd-lints (#3356)by malik1004x · 01c977e8 · Jul 14, 2026 · 37 filesMessage 69 · AdequateInformational 15Details
Commit message · malik1004x

add-lints (#3356)

* test add lint as separate action
* nicer logging
* only detect changes in dart files
* fix printV warnings being displayed when editing printV

---------

Co-authored-by: Czarek Nakamoto <cyjan@mrcyjanek.net>

69/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 15/100

This commit is a routine code-quality and CI housekeeping change. It adds and reorganizes Dart lint rules, creates a custom lint plugin to enforce coding standards (e.g., prefer a verbose print helper, avoid direct HTTP imports, restrict cross-package imports), and updates several tool scripts to use plain print() instead of the app's verbose logger. There is no user-facing security fix or vulnerability patch in the diff.

AI review queued26-07-14_Update Translation_de_DEby bsn21m · 1a27345e · Jul 14, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · bsn21m

26-07-14_Update Translation_de_DE

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a routine German translation update. It adds, removes, and tweaks German text strings used in the app's user interface. There is no code change and no security impact.

AI review queuedShuffle input order on bitcoin sends (#3379)by Cindy · 031a117f · Jul 14, 2026 · 1 fileMessage 53 · ThinLow 32Details
Commit message · Cindy

Shuffle input order on bitcoin sends (#3379)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 32/100

This change makes Bitcoin transactions shuffle the order of their inputs (the coins being spent). Shuffling input order is a common privacy improvement because it makes it harder for outside observers to guess which inputs belong to the same wallet or link transactions together. It does not fix a crash, theft bug, or direct exploit.

AI review queuedminor fixes [skip ci]by Omar · 5423484c · Jul 14, 2026 · 5 filesMessage 28 · OpaqueLow 27Details
Commit message · Omar

minor fixes [skip ci]

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 27/100

This commit makes several small UI and error-handling tweaks in a cryptocurrency wallet app. The most user-relevant change is that address and amount text fields now disable autocorrect and predictive suggestions, which reduces the chance that a sensitive crypto address or amount gets leaked to a third-party keyboard/cloud service. Other changes clean up clipboard pasting, Bluetooth error handling, and which non-fatal errors are suppressed. There is no obvious severe security bug being fixed, but the autocorrect change is a privacy improvement.

AI review queuedadd paddingby Robert Malikowski · 90cbf677 · Jul 13, 2026 · 5 filesMessage 0 · OpaqueInformational 15Details
Commit message · Robert Malikowski

add padding

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a routine UI polish: it adds bottom padding to a transaction history list and renames an internal counter from 'enabledProviders' to 'enabledProvidersCount' to make the code clearer. There is no security change.

AI review queuedminor fix [skip ci]by Omar · bff9b2fa · Jul 13, 2026 · 2 filesMessage 28 · OpaqueLow 44Details
Commit message · Omar

minor fix [skip ci]

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 44/100

This commit fixes two bugs in Cake Wallet's exchange flow. First, when creating a trade record for the NEAR Intents exchange provider, the app was accidentally recording the 'from' currency as both the source and destination currency. Second, the code that checks whether the user's wallet can send funds for a trade was refactored to return error strings instead of throwing exceptions, and logging of those errors was moved to the caller. The first fix is a real functional bug that could mislead users about what they are receiving in a trade. The second is mostly a code-quality and reliability improvement.

AI review queuedhandle lightning balance fetch failures (#3382)by Serhii · 7403aec3 · Jul 13, 2026 · 1 fileMessage 53 · ThinInformational 20Details
Commit message · Serhii

handle lightning balance fetch failures (#3382)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100

This commit wraps a lightning balance lookup in a try/catch so that if the lookup fails, the app logs an error instead of crashing or throwing an unhandled exception. It is a defensive reliability fix; there is no direct evidence it fixes an exploitable security vulnerability.

AI review queuedImprove how wallets are renamed. (#3352)by Omar Hatem · 00088502 · Jul 12, 2026 · 16 filesMessage 76 · AdequateLow 32Details
Commit message · Omar Hatem

Improve how wallets are renamed. (#3352)

* Improve how wallets are renamed.
affected wallets (Electrum-like) (BTC, LTC, BCH, Doge)

* more improvements
also added Solana, Tron, EVM

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 32/100

This commit refactors how Cake Wallet renames cryptocurrency wallets. Previously, each wallet type had its own rename code that opened the wallet, copied specific files, and deleted the old directory. The new code centralizes the file-copying logic and makes the process more consistent across Bitcoin-like coins, Litecoin, Bitcoin Cash, Dogecoin, EVM chains, Solana, and Tron. The change appears to be a code-quality and reliability improvement rather than an obvious security fix, but it does address some risky patterns in the old rename implementation—such as deleting the old wallet directory before confirming the new one is valid, and not checking whether the destination wallet already exists.

AI review queuedfix android CIby Blazebrain · 5b2045af · Jul 11, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · Blazebrain

fix android CI

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit changes the source of a software dependency (ledger-usb-plus) from a third-party developer's repository to Cake Wallet's own fork, and updates which version is used. The stated reason is to fix Android CI (continuous integration). There is no direct evidence in the commit that this is a security fix, but switching dependency sources can carry supply-chain security implications that are worth reviewing.