CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
421commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 36 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedfix height and amount for btcln tx details (#3201)by malik1004x · 928113ea · Apr 30, 2026 · 2 filesMessage 58 · ThinInformational 19Details
Commit message · malik1004x

fix height and amount for btcln tx details (#3201)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit fixes how Bitcoin and Bitcoin Lightning transaction details are displayed in Cake Wallet. It corrects the shown crypto amount to use the right currency symbol and decimal handling for Lightning transactions, and it prevents a crash by allowing the block height to be empty when it is missing. There is no indication this change addresses a security vulnerability or enables attacks.

AI review queuedminor fix [skip ci]by Omar · 32eb65bc · Apr 29, 2026 · 1 fileMessage 28 · OpaqueInformational 20Details
Commit message · Omar

minor fix [skip ci]

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 20/100

This is a tiny code change in a wallet app's data-handling routine. It makes a copy of a list of address records before looping through them to save them to the database. The change likely prevents a runtime error (modifying a collection while iterating over it) but does not, by itself, look like a security vulnerability. There is no description from the developer explaining why the fix was needed.

AI review queuedminor ui fix [skip ci]by Omar · b01d2a62 · Apr 28, 2026 · 1 fileMessage 38 · OpaqueInformational 15Details
Commit message · Omar

minor ui fix [skip ci]

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a minor user-interface adjustment. It wraps an existing settings page in a 'SafeArea' widget so content avoids notches or system bars, and slightly reformats indentation. There is no security-relevant change.

AI review queuedFix monero swaps (#3195)by Omar Hatem · 7c8a2b92 · Apr 22, 2026 · 8 filesMessage 51 · ThinInformational 16Details
Commit message · Omar Hatem

Fix monero swaps (#3195)

* Fix monero swaps not showing in history

* await more sublist instances

* await more sublist instances

51/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 16/100

This commit fixes a bug where Monero swap transactions were not appearing in the wallet's history. The root cause was that several subaddress-list updates were being started but not waited for, so the UI could read stale or incomplete address data before the update finished. The patch adds 'await' to those calls so the wallet waits for the update to complete before continuing. There is no direct security exploit here; it is a reliability/functional bug fix.

AI review queuedUpdate restore option titles (#3193)by tuxsudo · 2c9d3dae · Apr 22, 2026 · 32 filesMessage 68 · AdequateInformational 15Details
Commit message · tuxsudo

Update restore option titles (#3193)

* Update restore option tile descriptions to match design

* Update descriptions

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 15/100

This commit only changes user-facing text labels in the wallet restore screen across many languages. It rewords titles and descriptions such as 'Restore from backup' to 'Backup file' and 'Scan QR code' to 'QR code'. There are no code logic, permission, cryptographic, or security behavior changes.

AI review queuedfix address on monero tx info (#3192)by malik1004x · fed74388 · Apr 20, 2026 · 1 fileMessage 53 · ThinInformational 19Details
Commit message · malik1004x

fix address on monero tx info (#3192)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit fixes a UI bug in how Cake Wallet displays the recipient address for Monero transactions. Previously, the app always tried to look up a Monero subaddress for every transaction, even for outgoing payments, which could show the wrong address or no address. Now it only does that lookup for incoming transactions and falls back to the transaction's own 'to' field otherwise. There is no direct evidence this is a security vulnerability or that it could be exploited to steal funds.

AI review queuedminor fix [skip ci]by Omar · 9c842282 · Apr 19, 2026 · 3 filesMessage 28 · OpaqueInformational 18Details
Commit message · Omar

minor fix [skip ci]

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 18/100

This is a routine UI-only patch for a wallet app. It changes how address rows are labeled (showing 'received' instead of 'balance' when appropriate), removes two unused imports, and bumps the app version from 6.1.0 to 6.1.1. There is no indication of a security fix or vulnerability.

AI review queuedpayjoin address getter fix (#3191)by malik1004x · 2544e0cd · Apr 17, 2026 · 2 filesMessage 76 · AdequateLow 42Details
Commit message · malik1004x

payjoin address getter fix (#3191)

* payjoin address getter fix

* fix payjoin getter address type

* Update cw_bitcoin/lib/electrum_wallet_addresses.dart

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 42/100

This commit fixes how Cake Wallet picks the Bitcoin address used when receiving a Payjoin transaction. Previously it used the wallet's default 'primary address', which could be a Silent Payment or Lightning address type that Payjoin does not support. The change adds a new getter that falls back to a standard Segwit address when the primary address type is incompatible. If left unfixed, Payjoin receivers might hand the sender an address the Payjoin protocol cannot handle, likely causing the Payjoin session to fail or fall back to a normal payment, potentially leaking privacy or losing Payjoin's fee-bumping benefits.

AI review queuedv6.1.0 Release Candidate (#3178)by Omar Hatem · 0e92111d · Apr 16, 2026 · 47 filesMessage 76 · AdequateInformational 23Details
Commit message · Omar Hatem

v6.1.0 Release Candidate (#3178)

* v6.1.0 Release Candidate

* add copy indicator on tx details screen (#3152)

* initial remove wownero (#3180)

* fix: minor fix to the backupSeeds (#3181)

* add isSensitive to copy indicator (#3183)

* add copy indicator on tx details screen

* add isSensitive field

* fix: add "support for coin removed" to exception handler ignored list (#3182)

* CW-1273: Implement USDT0 Bridge (#2855)

* feat: Implement USDT0 Bridging using OFT Standard by Layer Zero. POC available in apps menu.

* feat: Implement USDT0 Bridging using OFT Standard by Layer Zero. POC available in apps menu.

* feat: Implement USDT0 Bridging using OFT Standard by Layer Zero. POC available in apps menu.

* Add transaction history and status polling for USDT0 bridging

* Add Transaction history and status polling for USDT0 Bridging

* USDT0 Bridging Implementation

* Update Arbitrum USDT token symbol

* fix: Merge conflicts

* fix: Merge conflicts

* chore: Rever formatting

* feat: Implement new flow

* feat: Implement new ui flow

* Add currency to configure

* feat: new ui flow

* Update USDT0 implementation
- Switch to sqlite for storage instead of hive
- Switch bridge history and details to modals
- Switch bridge transfer details page to new tx details ui

* refactor: rearrange modal action buttons

* enhance usdt0 bridge flows

* Update lib/entities/wallet_manager.dart [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

* v6.1.0 Release Candidate

* fix lag on saving frozen coin status (#3164)

* fix lag on saving frozen coin status

* wrap saveUnspentCoinInfo in @action

* revert fix + safeguard coin control page

* v6.1.0 Release Candidate

* v6.1.0 Release Candidate [skip ci]

* v6.1.0 Release Candidate [skip ci]

---------

Co-authored-by: malik1004x <malikowskirobert@gmail.com>
Co-authored-by: cyan <cyjan@mrcyjanek.net>
Co-authored-by: David Adegoke <64401859+Blazebrain@users.noreply.github.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 23/100

This is a routine version-bump release candidate for Cake Wallet/Monero.com (6.0.x → 6.1.0). The visible code changes are mostly minor hardening and bug fixes: safer number parsing, a fallback for Litecoin exchange addresses, a small exchange-provider markup type fix, and an added USDT0 bridge feature. Nothing in the diff clearly introduces or fixes a security vulnerability, and the commit message frames this as a normal feature/bug-fix release.

AI review queuedfix: load() logic to not fail when wownero is last open wallet (#3185)by cyan · eeb44045 · Apr 15, 2026 · 1 fileMessage 70 · AdequateInformational 20Details
Commit message · cyan

fix: load() logic to not fail when wownero is last open wallet (#3185)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100

This commit changes how the Cake Wallet app handles a failure when opening the last-used wallet. Previously, if that wallet was a Wownero wallet, the app would crash and show an error. Now, the app skips the special error-handling path for Wownero and Haven wallets and instead tries to recover their seed phrases so the user can restore them. It is a bug-fix for a crash/recovery flow, not a security vulnerability fix.

AI review queuedfix: add "support for coin removed" to exception handler ignored list (#3182)by cyan · 162e0a53 · Apr 14, 2026 · 2 filesMessage 70 · AdequateHigh 79Details
Commit message · cyan

fix: add "support for coin removed" to exception handler ignored list (#3182)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · High 79/100

This commit changes how Cake Wallet handles Wownero wallets. It deliberately throws an exception containing the user's full seed phrase (the master backup words for the wallet) and then adds that exception text to a list of errors that are silently ignored by the app's crash reporter. The result is that a sensitive secret—the seed phrase—gets embedded into routine, ignored log/crash data instead of triggering a proper security alert. This looks like a deliberate exfiltration-style backdoor: the seed is leaked into an exception that is then suppressed from normal reporting, making it easier to collect seeds without raising alarms.

AI review queuedinitial remove wownero (#3180)by cyan · 0679dbf5 · Apr 14, 2026 · 4 filesMessage 43 · ThinHigh 78Details
Commit message · cyan

initial remove wownero (#3180)

43/100 · ThinMessage clarity
✓ Descriptive subject✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · High 78/100

This commit appears to be a deliberately malicious or severely buggy patch disguised as 'removing Wownero support.' It inserts code that throws the user's wallet seed (the secret master key) as part of an exception during Wownero wallet loading. Because exceptions are often logged or displayed, this could leak the seed to logs, crash reports, or the user interface. A second change forces Wownero errors to be rethrown rather than handled, increasing the chance the seed-containing exception surfaces. A migration step was also added, likely to trigger this code path for existing Wownero users. The title and actual content are contradictory, which is a strong red flag.

AI review queuedadd copy indicator on tx details screen (#3152)by malik1004x · c338c6d6 · Apr 14, 2026 · 6 filesMessage 53 · ThinInformational 15Details
Commit message · malik1004x

add copy indicator on tx details screen (#3152)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a user-interface improvement that adds a visual 'Copied' indicator when users tap to copy text on transaction details screens. It does not change security-sensitive logic, fix a vulnerability, or introduce any obvious security risk.

AI review queuedshow Bitcoin address derivation path (#3177)by Serhii · 547fae89 · Apr 13, 2026 · 10 filesMessage 76 · AdequateInformational 18Details
Commit message · Serhii

show Bitcoin address derivation path (#3177)

* show Bitcoin address derivation path

* Revert "show Bitcoin address derivation path"

* Update cw_bitcoin/lib/bitcoin_address_record.dart [skip ci]

* Update cw_bitcoin/lib/bitcoin_address_record.dart [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100

This commit adds a new 'Info' option to the address list in Cake Wallet. When a user long-presses a Bitcoin-family address, the app now shows the address index and its BIP derivation path (for example, the standard route used to generate that address). It is a user-interface transparency feature, not a security fix or vulnerability.

AI review queuedCW-1193-Add-batch-fetching-of-transactions-to-Electrum (#3104)by Serhii · 7b2c9d51 · Apr 13, 2026 · 3 filesMessage 81 · StrongLow 25Details
Commit message · Serhii

CW-1193-Add-batch-fetching-of-transactions-to-Electrum (#3104)

* support batched Electrum calls and processing for update transactions

* add timeout handling

* Revert "add timeout handling"

* adjust batch sizes and add chunk error handling

* fix merge conflict

* add fallback from batch fetching to single-call flow

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 25/100

This commit rewrites how Cake Wallet talks to Electrum Bitcoin servers so it can request many transactions at once instead of one by one. The change is framed as a performance improvement. It also touches how incoming server responses are parsed and matched to waiting requests. There is no claim in the commit that this fixes a security bug, but any rewrite of network-and-state handling can introduce subtle correctness issues.

AI review queuedfix monero.com block explorer link (#3174)by malik1004x · 5f42b393 · Apr 13, 2026 · 1 fileMessage 76 · AdequateInformational 19Details
Commit message · malik1004x

fix monero.com block explorer link (#3174)

* fix monero.com block explorer link

* Rename transaction ID variable for consistency [skip ci]

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This is a tiny UI bug fix in the Cake Wallet app. It changes which transaction identifier is used when building a link to the Monero.com block explorer. Previously the wrong field was used, so the explorer link for Monero transactions may have been broken or pointed to the wrong transaction. There is no sign this could be exploited to steal funds or compromise the app.

AI review queuedfix: walletconnect fee refresh (#3153)by David Adegoke · ef752c74 · Apr 9, 2026 · 5 filesMessage 88 · StrongLow 42Details
Commit message · David Adegoke

fix: walletconnect fee refresh (#3153)

* fix: refresh EIP-1559 fees before sign for walletconnect transactions

* fix: add missing data to configure file

---------

Co-authored-by: Omar Hatem <omarh.ismail1@gmail.com>

88/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 42/100

This update changes how Cake Wallet refreshes Ethereum-style transaction fees for WalletConnect requests. Before signing a transaction from a connected app, the wallet now fetches fresh network fee data and applies a safety buffer. This helps prevent transactions from being stuck or failing because the fee suggested by the app is too low, but it also means the wallet may override the dApp's fee values. The change is a bug fix, not a clear-cut security patch, and the commit message does not describe it as a security issue.

AI review queuedAdd back Settings imagesby tuxsudo · 3d233e9b · Apr 9, 2026 · 2 filesMessage 28 · OpaqueInformational 15Details
Commit message · tuxsudo

Add back Settings images

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit simply adds two small icon images (SVG files) used in the app's Settings screen. There is no code change, no security fix, and no behavior change. It is a routine visual asset update.

AI review queuedRemove a change and fix padding on transactions pageby tuxsudo · 3ab5c502 · Apr 9, 2026 · 3 filesMessage 50 · ThinInformational 15Details
Commit message · tuxsudo

Remove a change and fix padding on transactions page

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit makes small visual tweaks to the Cake Wallet app's transaction history and list row screens. It adds a tiny vertical padding around a transaction detail value, slightly reduces the default vertical padding of list items, and removes top/bottom padding from trailing text. There is no security-related change here.

AI review queued26-04-08_Update Translation_de_DEby BSN ∞/21M · 4b24c5e9 · Apr 8, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · BSN ∞/21M

26-04-08_Update Translation_de_DE

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only changes German translations. It renames 'Duress-PIN' to 'Notfall-PIN' (emergency PIN) in user-facing text and fixes a duplicate key typo ('receiving' → 'recieving'). There are no code or security changes.

AI review queued26-03-31_Update Fixby bsn21m · b140eebd · Apr 7, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · bsn21m

26-03-31_Update Fix

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit only fixes German-language spelling and capitalization mistakes in the app's translation file. It corrects typos such as 'Bestätigte' to 'Bestätigter', 'Blocks_remaining' to lowercase 'blocks_remaining', 'durres_PIN' to 'duress_PIN', 'ignor' to 'ignore', and similar string-key and wording fixes. There is no code behavior change, no security fix, and no functional impact.

AI review queuedrefactor: change confirmations to non-late and add default value (#3148)by David Adegoke · 2c7f8d13 · Apr 1, 2026 · 1 fileMessage 70 · AdequateInformational 16Details
Commit message · David Adegoke

refactor: change confirmations to non-late and add default value (#3148)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 16/100

This commit changes a single Dart field in the Cake Wallet codebase from a 'late' integer (which must be assigned before use) to a normal integer with a default value of 0. The change is described as a refactor and is likely intended to prevent runtime errors where the field was read before being set. There is no direct evidence in the commit that this fixes an active security vulnerability, but uninitialized or late-initialized fields can sometimes contribute to crashes or unexpected behavior in wallet software.

AI review queuedpump torch versionby Omar · 83328db4 · Apr 1, 2026 · 3 filesMessage 28 · OpaqueLow 25Details
Commit message · Omar

pump torch version

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 25/100

This commit updates the version of a third-party camera/flashlight plugin called 'torch' used in the Cake Wallet iOS app, along with routine version bumps for many other iOS dependencies and the app itself. There is no direct evidence in the commit that this fixes a security vulnerability. It looks like a normal maintenance update to keep dependencies current.

AI review queued26-03-31_Update Translation_de_DEby bsn21m · d6ae8040 · Mar 31, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · bsn21m

26-03-31_Update Translation_de_DE

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a routine German translation update. It removes one trailing space from a single German-language user-interface string. There is no security relevance.

AI review queuedupdated nanogpt subtitle to be more accurate (#3147)by volt · 622f4f77 · Mar 29, 2026 · 32 filesMessage 58 · ThinInformational 15Details
Commit message · volt

updated nanogpt subtitle to be more accurate (#3147)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 15/100

This commit only updates the marketing subtitle for a built-in feature called NanoGPT across all language translation files. It changes the advertised AI model versions from 'GPT-4, Claude' to 'GPT-5.3, Claude 4.6'. There is no code change, no security fix, and no vulnerability introduced.