CW
← All projectsCake Wallet

Cake Wallet / Monero.com

Noncustodial mobile and desktop wallet code for Cake Wallet and the Monero-only Monero.com wallet.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

765 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

112security candidates333second-pass queue445AI analyses
62commits · 30 days
152commits · 60 days
421commits · 180 days
751commits · 365 days
Backfill bands
Sep 27 → Mar 31329 seen44 candidatesComplete
Mar 31 → Jul 29266 seen28 candidatesComplete
Jul 29 → Aug 2891 seen17 candidatesComplete
Aug 28 → Sep 2765 seen18 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

59/100 average clarity
141Strong · 80–100
251Adequate · 60–79
235Thin · 40–59
138Opaque · 0–39
5security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
cyan711035268
David Adegoke1022567178
Omar Hatem54838165
malik1004x1231452062
Konstantin Ullrich551434076
Blazebrain191012058
Serhii46617066
tuxsudo22613057
Omar48334035
Seth For Privacy20311080
claude[bot]633077
Cindy635076
Analysis record

Published AI watches

Last scanned 10 minutes ago

Informational 15 AI analysisMessage 80 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: add new images and fix integration tests (#3679)

This commit is a routine product update for the Cake Wallet app. It swaps in new Robinhood-themed icons and card backgrounds, adjusts a color gradient, adds Robinhood to integration-test wallet lists, fixes a QR-code image reference to poi…

ad93901aby David Adegoke+216−3417 files
No security note in commit
Low 35 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add Robinhood Chain (#3398)

This commit adds support for a new blockchain, "Robinhood Chain" (chain ID 4663), to the Cake Wallet app. It is a large feature patch that wires the new chain into wallet creation, sending, receiving, exchange providers, transaction histor…

New EVM chain integration with custom transaction signing path (RobinhoodClient forces gasPrice instead of EIP-1559)New third-party RPC endpoints added to default node list (PublicNode, NOWNodes, Robinhood, Alchemy)New API secret (ALCHEMY_API_KEY) written into generated secrets file in CI workflows
046e57c5by David Adegoke+1214−159143 files
No security note in commit
Informational 16 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

chore: migrate to hosted scalable CI (#3620)

This commit is an infrastructure change: Cake Wallet moved its automated build system from GitHub's standard runners to a third-party hosted service ('puzl-ubuntu-latest') and split the build into many smaller parallel jobs. It also adds a…

Third-party CI runner label `puzl-ubuntu-latest` replaces GitHub-managed `ubuntu-24.04`Committed RSA private key and self-signed certificate (`scripts/android/dev-test-key.pem`, `scripts/android/dev-test-key.crt`) used only for debug/CI keystoresCI jobs now log in to GHCR using `secrets.GITHUB_TOKEN` and run Docker with broad socket permissions (`sudo chmod 666 /var/run/docker.sock`)
77e4b946by cyan+1306−23423 files
No security note in commit
Informational 23 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

cw-1683-prepare-zano-removal (#3668)

This commit prepares Cake Wallet to remove support for Zano and Decred wallets. It adds a new database table to store encrypted seed phrases for wallets that are being deprecated, shows warning popups to users so they back up their seeds, …

New database table stores seed/passphrase for deprecated walletsUI added to warn users to back up seeds before wallet type removalWallet type removal prevents future creation of Zano/Decred wallets
86616811by malik1004x+192−912 files
No security note in commit
Low 29 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

only check address validation once for old addresses

This commit changes how Cake Wallet verifies whether stored Bitcoin and Bitcoin Cash addresses belong to the 'hidden' (change) side of a wallet. Previously, the app re-checked every address on every wallet open, which could flip address la…

Address label (hidden/visible) correctness affects which addresses users believe are receive vs change addressesRepeated re-derivation on every startup removed, reducing side-channel/performance exposureLogic change prevents arbitrary flipping of `isHidden` for addresses that do not match either derivation path
1972efd0by Omar+30−253 files
No security note in commit
Low 33 AI analysisMessage 50 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix balance being stale cuz it's overriden by an old value

This commit fixes a bug where a Bitcoin wallet's displayed balance could become stale or be overwritten with an outdated value. The changes make balance updates copy the new value instead of sharing a reference, recalculate balances per ac…

Balance display correctness bug fixedReference sharing replaced with explicit copy to avoid stale shared-mutable stateNetwork disconnect guard added before persisting fetched balance
1de16191by Omar+84−153 files
No security note in commit
Low 33 AI analysisMessage 76 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Cw 1551 quick bitcoin wallet sync (#3446)

This is a large feature commit that adds multi-account support for Bitcoin wallets in Cake Wallet, along with a 'quick sync' optimization. It changes how addresses, transactions, balances, and unspent coins are tracked per account. The cha…

Multi-account key derivation path now uses accountIndex from address record rather than parsing derivation path, reducing risk of deriving wrong account keysUTXO selection and transaction building restricted to current account's unspent coins (unspentCoinsForCurrentAccount)Address generation throws UnsupportedAddressTypeForAccountException for unsupported account/type combinations, preventing accidental key derivation for invalid paths
d7ebf428by Serhii+3966−216184 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: prefill rescan height with the saved Monero and Zcash restore height (#3669)

This commit changes the wallet's rescan screen so that, for Monero and Zcash wallets, the starting block height is automatically filled in with the wallet's saved restore/birth height. This is a convenience feature that helps users avoid t…

UI convenience change, no cryptographic or network code modifiedNo input validation changes; prefill only occurs when field is empty and height > 0Reduces likelihood of user error (e.g., rescanning from genesis or an incorrect height)
0503d542by Seth For Privacy+32−05 files
No security note in commit
Informational 16 AI analysisMessage 83 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Merge pull request #3658 from cake-tech/integration-test-fixes

This commit fixes flaky integration tests in the project's automated CI pipeline and makes a small UI cleanup change in the app's authentication screen. It does not appear to fix a security vulnerability. The auth-page change replaces a di…

No security-relevant signals in commit title or messageNo CVE, advisory, or security disclosure references presentAuth page change is defensive UI hardening, not an access-control or cryptographic fix
bc302f0eby David Adegoke+38−113 files
No security note in commit
Informational 23 AI analysisMessage 47 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: handle flushbar dismissal

This commit fixes how the app dismisses on-screen notification banners (called 'flushbars') during login. Previously, the code tried to dismiss a banner even when it wasn't currently shown, which could cause the app to crash or behave oddl…

UI state handling bug fixPotential null/invalid route dereference mitigatedNo explicit security claim in commit message or diff
88a7e72cby Blazebrain+17−62 files
No security note in commit
Informational 21 AI analysisMessage 81 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Add onionbalance Tor frontends to default node lists (#3431)

This commit updates Cake Wallet's built-in lists of cryptocurrency network servers. It replaces some single Tor/onion server addresses with new load-balanced Tor frontends, adds missing Tor server options for Bitcoin and Litecoin, and make…

Adds Tor/onion routing for Bitcoin fee estimatesReplaces single Tor nodes with load-balanced onionbalance frontendsMarks Cake Wallet Tor nodes as official in default node lists
c8cad835by Seth For Privacy+21−95 files
No security note in commit
Informational 19 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

fix: enter Lightning invoice amounts in sats (#3525)

This commit fixes a user-interface bug when receiving Bitcoin over the Lightning Network in Cake Wallet. Previously, the app showed the invoice amount in whole Bitcoin (BTC) instead of satoshis (sats), because an internal currency code was…

No memory-safety, cryptographic, or authorization changes observedNo input validation, parsing, or serialization changes observedNo network, wallet-seed, or key-handling changes observed
fdb82675by Omid+7−12 files
No security note in commit
Moderate 60 AI analysisMessage 73 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Revert "Revert "fix: unify encryption across platforms (#3470)" (#3634)" (#3635)

This commit re-applies a change that makes wallet file encryption consistent across all platforms. It replaces an older, weaker encryption method (Salsa20) with a stronger one (XChaCha20) and adds automatic migration of old wallet files. T…

Replaces Salsa20 with XChaCha20 for wallet file encryptionAdds transparent migration path from legacy Salsa20 filesPins cake_backup dependency to a specific git commit instead of floating branch
2d8d0684by Omar Hatem+555−8610 files
Vendor flagged security relevance
Low 26 AI analysisMessage 93 · Strong
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

Integration tests (#3477)

This is a large commit that adds and reorganizes automated integration tests for the Cake Wallet app. Most of the changes are test code, CI workflow files, and small app-side widget key additions so tests can find on-screen elements. There…

Large test-only refactor with no obvious malicious codeProduction-side changes are additive widget keys and one Solana decimals fixCI now posts Slack reports and supports manual funds-spending tests with a default-off SPEND flag
dfa51657by David Adegoke+6024−4772137 files
No security note in commit
Moderate 57 AI analysisMessage 65 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

feat: warn when txCount != 1 (#3644)

This commit adds a safety check in Cake Wallet's Monero wallet code. When a user tries to send Monero, the app now checks how many separate transactions would be created. If it is not exactly one transaction, the app stops and warns the us…

Defensive guard added against multi-transaction payment splitsUser-facing error thrown instead of silent multi-tx executionPreviously commented-out status check not restored
28d540d5by cyan+9−23 files
No security note in commit
Informational 22 AI analysisMessage 49 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

charts (#3162)

This commit adds a new cryptocurrency price-charts feature to the Cake Wallet app. It introduces screens, data models, a price API client, local database tables to cache prices, and related UI assets. There is no direct evidence in the com…

New network client sends fiatApiKey header to prices.cakewallet.comNew SQLite tables store price data and favorite assets; migration version bumped from 12 to 13currencyFromApiString throws UnimplementedError for evm and sol token types, which could cause runtime crashes if those asset types are selected
b88fbf32by malik1004x+2544−27094 files
No security note in commit
Informational 18 AI analysisMessage 59 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

remove old ui (#3629)

This is a large cleanup commit that removes the old user interface code from the Cake Wallet app and switches the app to use only the new UI. It deletes many old screens, view models, fonts, and related dependency-injection registrations. …

Large-scale deletion of legacy UI code and unreachable routesRemoval of disabled/unused Yat emoji-id integration code (commented-out network calls and empty URL constants)Removal of old buy/sell webview pages that handled external payment flows
d38c7481by malik1004x+74−18935155 files
No security note in commit
Informational 17 AI analysisMessage 45 · Thin
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

ignore pointless throw [skip ci]

A single throw statement in the Decred wallet code was replaced with returning the string 'closed'. Previously, calling syncStatus() after the wallet was closed would crash with an error. Now it returns a status string instead. This is a m…

Removal of an exception path in wallet lifecycle state handlingChange from fail-closed (throw) to fail-open (return string) on closed walletNo input validation, bounds checking, or cryptographic changes present
c9635932by Omar+3−11 file
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

minor fix [skip ci]

This commit is a routine code cleanup in a single Flutter UI file. It replaces verbose 'return { ... }' function bodies with arrow syntax, adds 'const' keywords where Flutter can optimize widget rebuilds, and tweaks one loading-state updat…

88498e84by Omar+29−441 file
No security note in commit
Low 33 AI analysisMessage 69 · Adequate
CW Cake WalletCake Wallet / Monero.com MoneroPrivacy protocolsSoftware wallets

V6.4.5 rc (#3639)

This is a routine release-candidate commit for Cake Wallet version 6.4.5. Most of the changes are version bumps, translated changelogs, and a new user-facing string about Trezor locktime. The actual code changes are small bug fixes and usa…

Mutex release moved into finally block, reducing risk of deadlock on exception pathsMonero coin-control concurrency fix and improved coin metadata matching for hardware walletsTrezor session management changes to prevent cross-wallet session misuse
9fe23970by Omar Hatem+296−8574 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedignore timeout exceptionby OmarHatem · 628bd9d4 · Mar 28, 2026 · 4 filesMessage 28 · OpaqueInformational 22Details
Commit message · OmarHatem

ignore timeout exception

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 22/100

This commit makes three small code changes: two places now silently ignore Lightning/Bitcoin network timeout errors in addition to DNS errors, and one Flutter UI check was simplified from 'context.mounted' to 'mounted'. The SVG asset change is unrelated binary data. The main concern is that hiding timeout errors could mask network or service problems, but there is no direct evidence this creates a security vulnerability.

AI review queuedupdate gitignoreby Robert Malikowski · 980c0278 · Mar 27, 2026 · 1 fileMessage 18 · OpaqueInformational 15Details
Commit message · Robert Malikowski

update gitignore

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply adds a rule to the project's .gitignore file so that generated .svg.vec files in the assets/new-ui directory are not tracked by Git. There is no code change, no security fix, and no indication of a vulnerability.

AI review queuedadd guard Lightning usage with isInitialized check (#3128)by Serhii · 083ffdac · Mar 27, 2026 · 2 filesMessage 58 · ThinLow 32Details
Commit message · Serhii

add guard Lightning usage with isInitialized check (#3128)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 32/100

This commit adds a safety check to prevent the app from using a Lightning wallet before it has finished initializing. Previously, the app only checked whether a Lightning wallet existed, not whether it was ready. This could have caused crashes or incorrect balance/update behavior if the app tried to use the wallet while it was still starting up.

AI review queuedfeat(984): enable Enter key submission on desktop wallet unlock (#3137)by Manuel Reschke · fa0acbf7 · Mar 27, 2026 · 2 filesMessage 70 · AdequateInformational 15Details
Commit message · Manuel Reschke

feat(984): enable Enter key submission on desktop wallet unlock (#3137)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit adds the ability to press the Enter/Return key to submit a wallet unlock password on desktop, instead of only being able to tap the unlock button. It also cleans up the unlock logic into one shared method and properly disposes of the password text controller. There is no security vulnerability here; it is a normal user-experience improvement.

AI review queuedadd compile graphics to configure script (#3142)by malik1004x · 06c3144e · Mar 27, 2026 · 1 fileMessage 53 · ThinInformational 15Details
Commit message · malik1004x

add compile graphics to configure script (#3142)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit simply adds one line to a setup script so that a graphics-compilation step runs automatically when configuring the Cake Wallet app. There is no indication of a security fix, vulnerability, or behavior change that affects users or their funds.

AI review queuedmake walletconnect work from the scan buttonby Robert Malikowski · b6f614fd · Mar 26, 2026 · 4 filesMessage 45 · ThinInformational 20Details
Commit message · Robert Malikowski

make walletconnect work from the scan button

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100

This commit lets users scan a WalletConnect QR code from the main scan button. It adds a check that the current wallet supports EVM-compatible chains before allowing the connection, and routes the scanned 'wc:' URI into the existing WalletConnect pairing flow. It also bumps a Lightning SDK dependency version in the iOS lockfile. There is no obvious security fix or vulnerability being patched; it reads like a feature/UX improvement.

AI review queuedadd compile graphics to configure scriptby Robert Malikowski · a8140f2d · Mar 26, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · Robert Malikowski

add compile graphics to configure script

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit simply adds one line to a setup script so that it runs a graphics compilation step during the normal build configuration process. There is no security-relevant change visible in the diff.

AI review queuedCW-1157-Use-correct-derivation-paths-for-other-address-types (#2825)by Serhii · 6378e929 · Mar 26, 2026 · 18 filesMessage 81 · StrongModerate 61Details
Commit message · Serhii

CW-1157-Use-correct-derivation-paths-for-other-address-types (#2825)

* feat: use bitcoin standard derivation paths per address type

* add support for Electrum derivation type in wallet

* fix merge conflict

* Use segwit HD for key export and simplify _hdFor

* skip derivation chooser for standard scan paths

* add legacy and P2SH derivation paths

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 61/100

This commit changes how Cake Wallet derives Bitcoin-style addresses from a user's recovery seed. Previously, the app used a single derivation scheme for all address types. Now it uses the standard BIP44/49/84/86 paths per address type (legacy, SegWit, Taproot, etc.) while keeping an older 'legacy' path for compatibility with existing wallets. The change is a feature/fix for correctness and interoperability, not an obvious security vulnerability. However, any change to key derivation is sensitive because mistakes can make funds inaccessible or cause users to share/scan the wrong addresses.

AI review queuedadd balance hidden message (#3132)by malik1004x · cbc9f99b · Mar 25, 2026 · 35 filesMessage 68 · AdequateInformational 15Details
Commit message · malik1004x

add balance hidden message (#3132)

* add balance hidden message

* add to translation

* add to translation

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
second-pass: unusually broad change
AI analysis · Informational 15/100

This commit is a user-interface enhancement, not a security fix. It adds a small on-screen hint that appears when a user has chosen to hide their wallet balance, reminding them that they can long-press the balance card to reveal it. The hint stops showing after the user has hidden the balance ten times. There is no vulnerability or security-relevant change here.

AI review queuedmake tx details modal full screen by default (#3133)by malik1004x · 312d88dc · Mar 25, 2026 · 1 fileMessage 58 · ThinInformational 15Details
Commit message · malik1004x

make tx details modal full screen by default (#3133)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit simply changes a transaction details popup to open nearly full-screen by default instead of opening at 60% of the screen height. It is a user-interface tweak with no security relevance.

AI review queuedfix: prevent off by one error in ensureMwebAddressUpToIndexExists (#3131)by cyan · 2010ef1b · Mar 25, 2026 · 1 fileMessage 70 · AdequateLow 30Details
Commit message · cyan

fix: prevent off by one error in ensureMwebAddressUpToIndexExists (#3131)

70/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 30/100

This commit fixes an off-by-one error in a Litecoin wallet feature that ensures enough MWEB (privacy) addresses exist up to a requested index. The fix adds 1 to the requested index before generating addresses. Without the fix, the wallet might create one fewer MWEB address than needed, which could cause address lookup or balance detection issues for privacy transactions. There is no direct evidence in the commit of a security vulnerability or exploit.

AI review queuedRevert "Revert "monero: update dependencies"" (#3115)by Omar Hatem · 3917e55f · Mar 25, 2026 · 32 filesMessage 81 · StrongLow 30Details
Commit message · Omar Hatem

Revert "Revert "monero: update dependencies"" (#3115)

* Revert "Revert "monero: update dependencies (#3064)" (#3114)"

This reverts commit 2d034091ffc95dc36530d23cb0cce401b19db9bf.

* bump: moneroc

* fix: macos builds

---------

Co-authored-by: Czarek Nakamoto <cyjan@mrcyjanek.net>

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Low 30/100

This commit is a routine dependency update for the Monero-related libraries used by Cake Wallet. It reverts an earlier revert, bumps the 'monero_c' code to a newer commit, changes how prebuilt native library files are named and organized, and fixes macOS build scripts. There is no direct evidence in the commit message or diff that this fixes a known security vulnerability; it appears to be a build/dependency maintenance change.

AI review queuedHandle network errors, improve Lightning setup, and add deposit events (#3127)by Konstantin Ullrich · e7b82294 · Mar 25, 2026 · 11 filesMessage 81 · StrongLow 33Details
Commit message · Konstantin Ullrich

Handle network errors, improve Lightning setup, and add deposit events (#3127)

* fix: send all for lightning

* fix: adjust crypto amount parsing logic for send page outputs

* feat: add event handling for deposit transactions in Bitcoin and Lightning wallets

- Introduced `onCreateDepositTransactionEvent` and `onUpdateDepositTransactionEvent` callbacks to manage deposit transaction updates.
- Updated event listener logic to handle unclaimed and claimed deposit events.
- Added support for processing deposit transaction info with `ElectrumTransactionInfo`.

* fix: handle network errors on username validation and improve Lightning address setup

- Added network error handling for username validation with a fallback error.
- Enhanced Lightning address setup logic with error handling and a fail-safe mechanism to disable Lightning usage if the setup fails.

* fix: enhance error handling for Lightning and update validation patterns

* fix: remove redundant raw string mark from amount validation pattern

* fix: normalize crypto amount input by replacing commas with dots

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 33/100

This commit is a routine bug-fix and feature update for Cake Wallet's Bitcoin and Lightning support. It improves how the app handles network errors when checking Lightning usernames, fixes 'send all' behavior for Lightning payments, normalizes amount inputs that use commas instead of dots, and adds event handling for deposit transactions. There is no clear security vulnerability being fixed; the changes mostly improve robustness and user experience.

AI review queueddisable mweb on desktopby OmarHatem · d5ee2abe · Mar 24, 2026 · 3 filesMessage 28 · OpaqueInformational 22Details
Commit message · OmarHatem

disable mweb on desktop

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 22/100

This commit removes the Mimblewimble Extension Blocks (MWEB) privacy feature from the Litecoin wallet on desktop platforms (Windows, macOS, Linux). It keeps MWEB available only on Android and iOS. The change is a feature gating / platform restriction, not a fix for an active security vulnerability in the code itself.

AI review queuedminor fixesby OmarHatem · 079fb1a0 · Mar 24, 2026 · 2 filesMessage 0 · OpaqueInformational 16Details
Commit message · OmarHatem

minor fixes

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 16/100

This commit makes two small hardening changes in a cryptocurrency wallet app. It switches log writes to a synchronous (blocking) mode, which helps avoid file corruption if multiple log lines arrive quickly. It also replaces a strict number parser with a safer one that falls back to zero when the amount text is invalid, preventing the app from crashing if a user enters a non-numeric value in a fiat conversion field.

AI review queuedTransaction details (New UI) (#3070)by malik1004x · a864655e · Mar 24, 2026 · 43 filesMessage 76 · AdequateInformational 22Details
Commit message · malik1004x

Transaction details (New UI) (#3070)

* merge

* strings

* layout fixes

* add modal for tx details

* add copy option

* fix bottomWidget

* fix bottomWidget

* remove import

* add rbf

* add observer for rbf

* post-review fixes

* add mweb explorer

* proper formatting for source address

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 22/100

This commit is a user-interface redesign for the transaction details screen in the Cake Wallet cryptocurrency app. It replaces the old full-page transaction details with a new bottom-sheet modal, adds a copy-to-clipboard option for each detail row, and refactors how transaction detail rows are generated. There is no obvious security vulnerability in the changes, but the refactor is large and touches many wallet types, so small functional regressions are possible.

AI review queuedfix tx status update (#3123)by malik1004x · 212441d1 · Mar 23, 2026 · 4 filesMessage 68 · AdequateInformational 23Details
Commit message · malik1004x

fix tx status update (#3123)

* fix tx status update

* fix infobox with disabled address rotation

* check transaction direction (edge case)

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 23/100

This commit fixes how the Cake Wallet app updates and displays transaction statuses. It prevents duplicate transactions from appearing in the history list, ensures pending/completed transactions are correctly distinguished, and fixes a small UI issue on the receive screen when automatic address rotation is turned off. There is no direct evidence this is a security vulnerability, but stale or incorrect transaction status could mislead users about whether a payment was confirmed.

AI review queuedfix wallet type resolution for arb (#3120)by malik1004x · 9cbfeaaa · Mar 21, 2026 · 1 fileMessage 53 · ThinInformational 18Details
Commit message · malik1004x

fix wallet type resolution for arb (#3120)

53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 18/100

This is a tiny one-line fix in a Dart file that maps a cryptocurrency ticker (ARB) to the correct wallet type (Arbitrum). Before the fix, selecting or handling the ARB asset may have failed because only a related ticker (arbEth) was recognized. There is no direct security exploit here; it is a functional bug fix that could only indirectly affect user funds by causing wrong wallet behavior or failed transactions.

AI review queuedfix receive option switching after ln invoice is generated (#3119)by malik1004x · 44d61e82 · Mar 21, 2026 · 1 fileMessage 58 · ThinInformational 17Details
Commit message · malik1004x

fix receive option switching after ln invoice is generated (#3119)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 17/100

This commit fixes a UI bug in Cake Wallet's receive screen. Previously, after generating a Lightning Network invoice, the app could keep showing that Lightning invoice even when the user switched to a different receive option (like a regular Bitcoin address). The fix makes the app check the wallet's actual current payment type instead of relying on a cached value.

AI review queuedRevert "monero: update dependencies (#3064)" (#3114)by Omar Hatem · 2d034091 · Mar 20, 2026 · 27 filesMessage 73 · AdequateLow 31Details
Commit message · Omar Hatem

Revert "monero: update dependencies (#3064)" (#3114)

This reverts commit e37f478588446764efe2d5c0ecef133ce2295954.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Low 31/100

This commit reverts a previous dependency update for the Monero-related libraries used by Cake Wallet. It downgrades the bundled 'monero_c' code and prebuilt binaries from a newer release (v0.18.4.6-RC1) back to an older one (v0.18.4.0-RC9), and changes how those native library files are organized and named. The commit itself does not contain a clear security fix or vulnerability disclosure; it looks like a build/dependency rollback, possibly because the newer version caused build or runtime problems.

AI review queuedmonero: update dependencies (#3064)by cyan · e37f4785 · Mar 19, 2026 · 27 filesMessage 43 · ThinInformational 24Details
Commit message · cyan

monero: update dependencies (#3064)

43/100 · ThinMessage clarity
✓ Descriptive subject✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 24/100

This commit updates the Monero-related wallet libraries (monero_c) used by Cake Wallet from an older release candidate (v0.18.4.0-RC9) to a newer one (v0.18.4.6-RC1). It also reorganizes how the compiled native libraries are stored and named across Android, iOS, Linux, and macOS. The change is a routine dependency upgrade and build-system refactor. There is no direct evidence in the commit that this fixes a specific security vulnerability, but updating cryptographic/wallet libraries is generally a good security practice because newer versions often include bug fixes.

AI review queuedensure wallet is saved after walletInfo is created (#3101)by malik1004x · c9b69b88 · Mar 19, 2026 · 1 fileMessage 58 · ThinInformational 24Details
Commit message · malik1004x

ensure wallet is saved after walletInfo is created (#3101)

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 24/100

This commit adds one line to make sure a newly created wallet is saved to disk right after its metadata record is saved. Without this save, the app might continue using or switching to a wallet whose underlying files were not yet persisted, which could lead to crashes, missing wallet data, or a user being unable to reopen the wallet later. It is a data-consistency fix rather than an obvious remote attack vector.

AI review queuedMinor UI Fixes (#3108)by tuxsudo · a8d9f087 · Mar 19, 2026 · 2 filesMessage 61 · AdequateInformational 15Details
Commit message · tuxsudo

Minor UI Fixes (#3108)

* Fix Filter button padding

* Fix sign/verify closing popup

61/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Provides an explanatory body✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit contains two small user-interface fixes: it adjusts the spacing inside a filter button and fixes a bug where an error popup on the sign/verify screen might not close correctly. There is no indication these changes address a security problem.

AI review queuedimprove transaction list performance (#3082)by malik1004x · 2de86c80 · Mar 14, 2026 · 11 filesMessage 68 · AdequateInformational 15Details
Commit message · malik1004x

improve transaction list performance (#3082)

* improve transaction list performance

* fix "no transactions" placeholder positioning

* format

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a routine user-interface performance improvement. It replaces several nested scrolling lists with Flutter's more efficient 'sliver' scrolling widgets, adds a small delay to a transaction-update callback, and updates a lightning-bolt icon asset. There is no indication it fixes a security vulnerability or introduces a security-relevant change.

AI review queuedNew Settings (#3065)by tuxsudo · 3815fc30 · Mar 14, 2026 · 80 filesMessage 59 · ThinInformational 18Details
Commit message · tuxsudo

New Settings (#3065)

* Update display_settings_page.dart

* Update settings_choices_cell.dart

* Update settings_theme_choice.dart

* Convert display_settings_page.dart to NewListSection

* Cleanup [skip ci]

* Minor

* Minor [skip ci]

* Add SizedBox to scroll view

* Upgrade receive_top_bar.dart with gradient and optional child content

* Adjust animations

* Add modal_page_wrapper.dart

* Add option to hide AppBar for BasePage [skip ci]

* New settings all final (#3067)

* Conflict

* ModalPageWrapper improved abstraction

* display_settings_page.dart minor update

* connection_sync_page.dart redesign

* Conflict

* manage_nodes_page.dart initial redesign

* other settings initial

* Conflict

* add optional subtitle to standard_list.dart

* add connection_sync_view_model.dart

* Add missing images

* Conflict

* Update list item widgets

* Conflict

* Conflict

* Conflict

* minor updates

* Conflict

* Fixes + move Mweb to privacy page

* Conflict

* Remove observer from modal_page_wrapper.dart

* Conflict

* Conflict

* Refactor settings_page.dart with suggestions

* Suggestion fixes

* Conflicts + fix About page

* Fix sync bar conflict

* Update Connections page title [skip ci]

* Trigger CI

* Fix Lightning and Payjoin log export

* Update MWEB node page

* Add FeatureFlag to AutomaticNodeSwitching

* Fix address text on privacy_page.dart

* Move WalletConnect from connection_sync_page.dart to settings_page.dart

* Add WalletConnect icon

* Fix settings icons

* Make text strings use S.of(context) and fix About string in settings_page.dart

* Display settings page fixes

* modal_page_wrapper.dart minor suggestions

* Missingimage

* Add spacing to list_item_selector_widget.dart

* Fix error on manage_nodes_page.dart

59/100 · ThinMessage clarity
✓ Subject identifies a change✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 18/100

This commit is a large user-interface redesign of the settings screens in the Cake Wallet mobile app. It replaces old settings widgets with newer components, reorganizes settings into new categories, adds new view models, and updates icons and navigation. There is no clear security vulnerability in the diff itself; it is primarily a cosmetic and structural refactor.