SW
← All projectsStack Wallet

Stack Wallet

Actively maintained multi-coin self-custody wallet with Monero support and on-device keys.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

1038 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

334security candidates400second-pass queue734AI analyses
66commits · 30 days
160commits · 60 days
606commits · 180 days
1009commits · 365 days
Backfill bands
Sep 27 → Mar 31404 seen73 candidatesComplete
Mar 31 → Jul 29463 seen238 candidatesComplete
Jul 29 → Aug 2887 seen8 candidatesComplete
Aug 28 → Sep 2753 seen6 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

51/100 average clarity
33Strong · 80–100
309Adequate · 60–79
506Thin · 40–59
190Opaque · 0–39
32security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Navid Rahimi1017154
sneurlax339158241062
julian347112269044
Julian18939136042
Dan Miller831525053
Reuben Yap20318052
julian-CStack222049
levoncrypto24121043
Tritonn204412052
cassandras-lies413048
NyanCatTW1111045
Cyrix126804045
Analysis record

Published AI watches

Last scanned 19 minutes ago

Low 35 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1450 from Ez3kiel-dev/fix/xelis-integration

This is a large feature/fix merge that restores and rewrites the Xelis (XEL) cryptocurrency integration in Stack Wallet. It swaps the old hand-rolled Xelis code for a new generated native interface (XWF), adds wallet restore/backup support…

Send-flow lifecycle hardening: prepared Xelis transactions are now discarded via cancelSend when the user cancels or the widget is disposedSession-generation checks prevent stale wallet handles from being used after close/reopenMutex serialization added around send preparation, balance, history, and rescan operations
ad945d43by Julian+4298−162634 files
No security note in commit
Low 32 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/xelis-integration

This commit is a large merge that mainly adds integration tests for a desktop 'forgot password' reset feature and makes supporting code changes to safely shut down background database workers during that reset. It also removes a large set …

New integration tests exercise a destructive 'forgot password' data-wipe featureTests assert that password store and wallet key store are deleted on successful resetTests assert that wallet files are deleted while backup and tor state are preserved
b0e5d35aby Julian+2678−330378 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1361 from cypherstack/fix/305-multiline-transaction-notes

This commit lets users type multi-line notes when editing transaction and trade notes, and fixes the desktop layout so long notes scroll instead of breaking the screen. It also swaps the old `mounted` check for the newer `context.mounted` …

5172e63eby Julian+402−1113 files
No security note in commit
Low 32 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/305-multiline-transaction-notes

This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive h…

Added safe shutdown of Firo cache isolates/SQLite databases before reset exitNew integration tests verify desktop forgot-password reset deletes secrets and preserves backupsTest harness intercepts exit() and IOOverrides to observe reset side effects
21491edbby Julian+2352−319075 files
No security note in commit
Moderate 57 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1455 from cypherstack/fix/desktop-pw-reset

This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to clos…

Desktop password reset now closes Firo cache workers and SQLite databases before deleting app data, reducing the risk of data leakage or corruption during wipeNew integration tests assert that a successful reset removes password store (hive/desktopdata.hive), wallet key store (isar/desktopStore.isar), and wallet files while preserving backups and tor stateFailed reset scenario leaves a .reset-pending marker and removes password/key stores first, preventing the reset from being undone after partial deletion
055e6c6bby Julian+1077−297154 files
No security note in commit
Low 37 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/desktop-pw-reset

This commit is a large merge that mainly adds a new 'prove you own a Spark address' feature to the Stack Wallet app, plus some related fixes. It also updates a dependency that handles SOCKS5 proxy connections and changes how the app decide…

New cryptographic signing path added: SparkInterface.signMessage now delegates to Spark ownership proof creation using the wallet's private key and spark derivation path.Ownership proof code rejects view-only wallets and blank messages, and searches a 100-address lookahead for the requested address before signing.Dependency upgrade: socks5_proxy 1.0.3+dev.3 -> 2.1.1, which may change SOCKS5/Tor proxy behavior; a new test verifies hostname/onion routing through a fake SOCKS server.
d9b5cc02by Julian+1275−21923 files
No security note in commit
Low 34 AI analysisMessage 83 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1439 from navidR/dev/navidr/spark-name-verification

This commit adds a new feature to Stack Wallet that lets users prove they own a Spark (privacy) address by generating a cryptographic ownership proof. It also improves the sign/verify screens so view-only wallets can still verify proofs, a…

New cryptographic proof generation using private key material (privateKeyHex, spendKeyIndex, diversifier) inside an isolateView-only wallet guard added for proof creation (throws if isViewOnly)Message whitespace now preserved for pasted/typed challenge messages, preventing proof/verification mismatches caused by silent trimming
a5411a50by Julian+1097−16616 files
No security note in commit
Low 39 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into dev/navidr/spark-name-verification

This commit merges several changes into a development branch. The most notable security-relevant change is a fix for how the Trocador exchange service routes traffic: it now automatically uses Tor (an anonymity network) when the user has T…

Trocador exchange API previously forced clearnet (`isOnion: false`) at every call site, bypassing Tor even when enabledNew `_useTor` getter centralizes Tor routing decision based on app feature flag and user preferenceOnion service address rotated to a new v3 .onion hostname
92955848by Julian+122−507 files
No security note in commit
Informational 24 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Spark: add address ownership proof signing and verification

This commit adds a new feature to Stack Wallet that lets Spark (Firo privacy) address owners prove they control an address, and lets others verify that proof. It also fixes a few related UI issues: view-only wallets can now only verify (no…

New cryptographic signing/verification API integrated into walletView-only wallet restriction added to prevent signing with private keysWhitespace preservation in pasted messages reduces signature/verification mismatch risk
eb370258by Navid Rahimi+1097−16616 files
No security note in commit
Informational 20 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into feat/trocador-onion

This commit adds a small convenience feature in Stack Wallet: when a user scans or opens a Firo payment QR code that contains a 'message' field and the payment address is a Spark privacy address, the wallet now automatically copies that me…

Untrusted paymentData.message is copied into a transaction memo field without visible escaping/sanitizationRelies on SparkInterface.validateSparkAddress to gate memo population; correctness of that helper is not shown in the diffBehavior parity with firo-qt suggests a UX fix rather than a vulnerability fix
a0a72593by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1463 from cypherstack/fix/firo-uri-message-to-spark-memo

This commit fixes a small user-experience gap in the Stack Wallet app for Firo cryptocurrency users. When someone scans or opens a Firo payment link (URI) that includes a message and the payment is going to a Spark privacy address, the app…

No security-relevant signals detected in the diff.Change is a UI autofill feature for Firo Spark memos from payment URI messages.No input sanitization changes beyond existing address validation.
48d10009by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

fix(firo): fill spark memo from payment URI message

This commit fixes a small user-experience bug in Stack Wallet for Firo cryptocurrency. When a user scanned or pasted a firo: payment link containing a message, the app previously put that message only in the local private note field. Now, …

No input sanitization on URI-derived memo before assigning to controllerBehavior aligned with firo-qt reference implementationNo changes to signing, encryption, address parsing, or network calls
60a6112dby sneurlax+20−02 files
No security note in commit
Low 30 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1452 from levoncrypto/masternode-operator-reward

This commit removes the user-facing 'operator reward' field from the Firo masternode registration screen and hard-codes that value to zero in the wallet logic. It is a feature removal rather than a fix for an active security flaw, but it d…

Removal of user-supplied numeric field that directly influenced on-chain transaction payload (nOperatorReward basis points)Elimination of locale-dependent decimal parsing and rounding path for a consensus-relevant valueHard-coding of a transaction field that previously had range/validation checks
7d9cba12by Julian+1−622 files
No security note in commit
Low 42 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit changes how a Firo cryptocurrency wallet picks a special 'owner address' when setting up a masternode. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also checks that t…

Address reuse prevention for masternode owner/payout rolesDefensive validation of derived addresses before useException raised when a suitable distinct address cannot be derived
e88cb980by Julian+9−81 file
No security note in commit
Low 42 AI analysisMessage 58 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1453 from levoncrypto/masternode-payout-ui

This change updates the Firo wallet's masternode owner address selection so that the chosen owner address is different from both the collateral address and the payout address. Previously, the code only ensured the owner address differed fr…

Defensive address-distinctness check added for masternode owner addressPrevents owner address from matching payout address, not just collateral addressError message updated to reflect new dual-distinctness requirement
fb70bccaby Julian+9−81 file
No security note in commit
Informational 19 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-payout-ui

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO across several app variants. It updates token lists, adds an icon, and includes a database migration so existing users automatically see the ne…

No security-relevant code changes observedNew asset and token configuration onlyDatabase migration is additive and idempotent (checks for existing contract before insert)
1324e37aby Julian+454−29520 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO, updates some app configuration scripts, refreshes a privacy-related Git dependency, and fills in missing API-key placeholders for exchange int…

Database migration inserts a hardcoded token contract if the app config includes it and the contract is not already presentExternal Git dependency mobile_app_privacy changed to a new commit; content of new commit not suppliedNew exchange API key placeholders added (Trocador, LetsExchange, CypherGoat) in test/prebuild scripts
8cc81383by Julian+500−30528 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1448 from reubenyap/codex/rsfiro-app-config

This commit adds support for a new Ethereum token called rsFIRO and makes the list of default Ethereum tokens configurable for each app flavor (Stack Wallet, Stack Duo, Campfire). It also includes a database migration so existing users get…

Database migration inserts a hardcoded ERC-20 contract address into user data based on app configurationMigration checks for existing contract by case-insensitive address comparison before insertionToken icon rendering now branches on contract address equality, which is a presentation-layer change
6203aeaeby Julian+454−29520 files
No security note in commit
Informational 24 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

allow owner address to equal voting address

This small change relaxes a wallet rule for the Firo cryptocurrency. Previously, when setting up a masternode-like service, the wallet required the 'owner address' to be different from the 'voting address'. Now it allows them to be the sam…

Removal of address distinctness check between owner and voting addressesChange affects Firo masternode address derivation logicNo input validation, cryptographic, or memory-safety changes present
19add823by levoncrypto+3−41 file
No security note in commit
Moderate 59 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

pick owner address distinct from payout and voting addresses

This change fixes how Stack Wallet picks a special 'owner address' for Firo masternode-related operations. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also ensures it differs fr…

Address reuse prevention across masternode rolesFiro masternode owner/payout/voting address separationPrivacy improvement by avoiding identical addresses for distinct transaction roles
86b9ec97by levoncrypto+10−81 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-priorityandroid wants this change or gradle complainsby Julian · 276494d1 · Aug 31, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Julian

android wants this change or gradle complains

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedupdate windows mwebdby Julian · abbe566a · Aug 28, 2026 · 3 filesMessage 28 · OpaqueInformational 24Details
Commit message · Julian

update windows mwebd

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 24/100

This commit updates the Windows build pipeline for a small helper program called mwebd, which Stack Wallet uses for Litecoin MWEB privacy features. It bumps the mwebd version from v0.1.8 to v0.1.19, switches to a newer Go compiler, removes an old workaround that disabled part of the upstream plugin, and fixes a checksum comparison bug caused by Windows file paths. There is no direct evidence in the commit that this fixes a security vulnerability, but updating dependencies and removing workarounds can have security side effects.

Lower-priorityci: android 37 fixby Julian · e46dcf29 · Aug 28, 2026 · 1 fileMessage 40 · ThinTriage 0Details
Commit message · Julian

ci: android 37 fix

40/100 · ThinMessage clarity
✓ Subject identifies a change✓ Uses a recognizable type or scope! No meaningful explanatory body
AI review queuedci test image goby Julian · c2443f27 · Aug 28, 2026 · 1 fileMessage 38 · OpaqueInformational 21Details
Commit message · Julian

ci test image go

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 21/100

This commit updates the project's Docker build image to install the Go programming language toolchain. It downloads Go 1.24.13 from the official Go website, verifies the file's integrity using a published SHA-256 checksum, extracts it, and adds it to the container's system PATH. The change appears to be a routine CI/build environment update rather than a security fix or vulnerability patch. There is no direct evidence in the commit that this addresses a security issue.

AI review queuedupdate mweb fee logicby Julian · d70c03d4 · Aug 28, 2026 · 4 filesMessage 28 · OpaqueLow 32Details
Commit message · Julian

update mweb fee logic

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 32/100

This commit rewrites how Stack Wallet calculates fees for MWEB (a privacy feature in Litecoin). It introduces a new helper module that reconciles the estimated fee against what the transaction actually pays, and loops up to 10 times to fix mismatches. The change appears to be a bug-fix/refactor of fee arithmetic rather than a new feature or an obvious security patch. There is no vendor statement that this fixes a security vulnerability.

AI review queuedfix frost input retryby Julian · c3cc7961 · Aug 28, 2026 · 1 fileMessage 28 · OpaqueLow 31Details
Commit message · Julian

fix frost input retry

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 31/100

This commit fixes a bug in the FROST Bitcoin wallet's coin-selection retry logic. Previously, when the first attempt to build a transaction didn't have enough funds, the code tried to add extra UTXOs but used a Set (which ignores duplicates and has no guaranteed order) and also accidentally included the current UTXO again instead of only the remaining ones. The fix switches to an ordered List and correctly picks/removes the next UTXO. This could have caused transaction building to fail, loop incorrectly, or select the wrong inputs.

Lower-priorityensure flutter native assets are included from all packagesby Julian · 53809d34 · Aug 28, 2026 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · Julian

ensure flutter native assets are included from all packages

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
AI review queuedupdate flutter_mwebdby Julian · f8f407a5 · Aug 28, 2026 · 2 filesMessage 18 · OpaqueLow 25Details
Commit message · Julian

update flutter_mwebd

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 25/100

This commit updates a single Flutter package dependency called flutter_mwebd from version 0.0.1-pre.11 to 0.0.1-pre.12. The change is routine maintenance: it bumps the version number in the project's lock file and in a template used to generate package configuration. The commit message gives no details about what changed in the new version or whether it fixes any security issue. Without access to the upstream package's changelog, we cannot determine if this update addresses a vulnerability.

AI review queuedupdate min flutter versionby Julian · e631414c · Aug 28, 2026 · 4 filesMessage 35 · OpaqueInformational 15Details
Commit message · Julian

update min flutter version

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply bumps the minimum Flutter version from 3.44.8 to 3.44.9 across build configuration files, a Dockerfile, and a dependency lock file. It is a routine tooling/maintenance update with no visible security relevance.

AI review queuedautoformat to satisfy ciby Julian · 25c93dac · Aug 27, 2026 · 4 filesMessage 28 · OpaqueInformational 15Details
Commit message · Julian

autoformat to satisfy ci

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is purely a code-style reformat. It changes whitespace, line breaks, and indentation in four Dart files to satisfy the project's continuous integration (CI) formatter. No program logic, behavior, or security-sensitive code was altered.

AI review queuedmweb custom fee fixby Julian · 35d7595b · Aug 27, 2026 · 2 filesMessage 28 · OpaqueLow 46Details
Commit message · Julian

mweb custom fee fix

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 46/100

This commit fixes how custom transaction fees are calculated for MWEB (a privacy feature in Litecoin) in Stack Wallet. Previously, when a user set a custom fee in 'satoshis per virtual byte' (sats/vByte), the app sometimes used the wrong fee rate or mixed up per-byte and per-kilobyte units. The fix makes the code consistently convert sats/vByte to a per-kilobyte rate before sending it to the MWEB library. A new test confirms that a custom sats/vByte setting now overrides the default per-kilobyte rate. This is a correctness bug that could cause users to overpay or underpay fees, and underpayment could potentially delay or stall transactions.

AI review queuedreplace error-prone refresh mutex/lock with wallet state coordination for xelis to start out withby Julian · c38227f0 · Aug 27, 2026 · 7 filesMessage 50 · ThinLow 35Details
Commit message · Julian

replace error-prone refresh mutex/lock with wallet state coordination for xelis to start out with

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 35/100

This commit rewrites how Stack Wallet's Xelis wallet handles background synchronization. It replaces a single refresh lock with a new 'operation coordinator' and an 'event batcher' that groups rapid blockchain notifications before acting on them. The stated goal is to fix race conditions and inconsistent state caused by the old mutex-based design. The change is defensive refactoring rather than a patch for a known exploit, but concurrency bugs in wallet code can historically lead to incorrect balances, missed transactions, or crashes.

AI review queuedclean up replaced eth transactionsby Julian · 6b853a9a · Aug 27, 2026 · 3 filesMessage 45 · ThinLow 34Details
Commit message · Julian

clean up replaced eth transactions

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 34/100

This commit adds a cleanup routine for Ethereum transactions that were replaced by another transaction with the same nonce. In Ethereum, if you send a second transaction with the same sequence number (nonce) but a higher fee, the first one can be dropped by the network. Stack Wallet previously kept these dropped transactions visible as 'pending' forever. The new code detects them by checking the blockchain and removes them from the local transaction list. It is a bug-fix/quality improvement rather than an active remote hack vulnerability.

AI review queuedremove unused parsing functionsby Julian · 5dd9fdb8 · Aug 26, 2026 · 1 fileMessage 35 · OpaqueInformational 12Details
Commit message · Julian

remove unused parsing functions

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 12/100

This commit simply deletes two unused helper functions that converted numbers between different locale formats (for example, swapping commas and periods used as decimal separators). Because the functions were not being used anywhere in the app, removing them does not change app behavior and does not fix or introduce a security issue.

Lower-priorityfix autoformat on save messby Julian · d2020384 · Aug 26, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Julian

fix autoformat on save mess

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedreset desktop fee rate type state providerby Julian · c4f0cb35 · Aug 26, 2026 · 1 fileMessage 45 · ThinModerate 50Details
Commit message · Julian

reset desktop fee rate type state provider

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 50/100

This commit fixes a state-carryover bug in the desktop version of Stack Wallet. A global fee-rate setting was not being reset when a user opened a new send form, so a custom fee chosen in one wallet could silently carry over to another wallet's send form. If the user did not notice, a transaction could be sent with an unexpected (possibly very low or very high) custom fee. The patch resets the fee type to 'average' each time the desktop send form is initialized.

Lower-prioritydon't reset memo field every address changeby Julian · 1711bc17 · Aug 26, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Julian

don't reset memo field every address change

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityclean up unused amount parsing stuffby Julian · fee5f397 · Aug 26, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Julian

clean up unused amount parsing stuff

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedfix(search): respect locale and coin precisionby Julian · d8efa9af · Aug 26, 2026 · 7 filesMessage 57 · ThinInformational 17Details
Commit message · Julian

fix(search): respect locale and coin precision

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 17/100

This commit fixes how the wallet's search and filter features interpret typed-in amounts. Previously, the app assumed everyone uses a dot (.) as the decimal separator and parsed amounts in a way that could misread or silently mishandle values for some currencies. Now it respects the user's locale (e.g., comma for German) and uses the coin's own precision rules. There is no direct evidence this was a security vulnerability, but incorrect amount parsing in a wallet can lead to users selecting wrong coins or filters, so it is treated as a correctness/reliability fix rather than an exploit.

Security candidateserialize external amounts with locale-independent decimals and use standard monero family query parametersby Julian · c0f7e2f2 · Aug 26, 2026 · 4 filesMessage 50 · ThinLow 45Details
Commit message · Julian

serialize external amounts with locale-independent decimals and use standard monero family query parameters

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 45/100

This commit fixes how the wallet builds payment QR codes and web links so that the amount is written in a standard, locale-independent decimal format and uses the correct parameter names for Monero-family coins. Before, a user in a country that uses a comma as the decimal separator could generate a QR code with an amount another wallet might misread, and Monero-style URIs used non-standard fields. The change also adds input formatting and parsing helpers to keep the user's typed amount consistent with their locale while exporting a canonical decimal string.

Lower-prioritykeep debounced send and receive text through swaps, pair changes, focus rewrites, and locale changes. Parse exchange input through the shared editable layer while retaining the for-lack-of-a-better-option-currently existing 8 decimal policyby Julian · a3bd6d95 · Aug 26, 2026 · 4 filesMessage 50 · ThinTriage 0Details
Commit message · Julian

keep debounced send and receive text through swaps, pair changes, focus rewrites, and locale changes. Parse exchange input through the shared editable layer while retaining the for-lack-of-a-better-option-currently existing 8 decimal policy

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queued- editable locale-aware text for mobile and desktop send flows - parse scanned payment amounts canonically, preserve values across locale changes, validate nonce text, and keep displayed fees separate from editable controller textby Julian · 62d0508c · Aug 26, 2026 · 9 filesMessage 73 · AdequateLow 47Details
Commit message · Julian

- editable locale-aware text for mobile and desktop send flows
- parse scanned payment amounts canonically, preserve values across locale changes, validate nonce text, and keep displayed fees separate from editable controller text

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: broader security terminologysecond-pass: security-sensitive path
AI analysis · Low 47/100

This commit is a hardening and bug-fix patch for Stack Wallet's send screens. It changes how payment amounts are entered, parsed, and displayed so the wallet respects the user's locale (for example, comma vs. period as a decimal separator) without losing or misinterpreting values. It also stops using formatted fee strings for internal calculations, instead keeping fees as raw numeric Amount objects, and adds validation for Ethereum transaction nonces so only whole numbers are accepted. The changes reduce the chance that a user accidentally sends the wrong amount because the app misread a pasted QR-code amount or a locale-formatted number.

Lower-priorityuse shared editable amount policy for buy, cakepay, masternode reward, and salvium staking inputsby Julian · 30ddf06a · Aug 26, 2026 · 4 filesMessage 50 · ThinTriage 0Details
Commit message · Julian

use shared editable amount policy for buy, cakepay, masternode reward, and salvium staking inputs

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityupdate and use adaptive text field for eth fee formby Julian · 0360a3c1 · Aug 26, 2026 · 2 filesMessage 50 · ThinTriage 0Details
Commit message · Julian

update and use adaptive text field for eth fee form

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queued- Treat maxFeePerGas as the total protocol cap for presets and custom fees. Validate it against base and priority fees, and use the same cap and gas limit for transaction construction and maximum-fee estimates.by Julian · 83f71a54 · Aug 26, 2026 · 10 filesMessage 65 · AdequateModerate 60Details
Commit message · Julian

- Treat maxFeePerGas as the total protocol cap for presets and custom fees. Validate it against base and priority fees, and use the same cap and gas limit for transaction construction and maximum-fee estimates.

- Localize custom fee input and reject malformed gas limits.

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
defensive validationsigning or wallet pathsecond-pass: near security thresholdsecond-pass: security-sensitive path
AI analysis · Moderate 60/100

This commit fixes how Stack Wallet handles Ethereum transaction fees. Previously, the app appears to have treated 'max base fee' and 'priority fee' as separate fields, which could let users set a priority fee higher than the total fee cap or set a total cap too low to cover the network's base fee. The patch makes the 'max fee per gas' the hard total cap, validates that the priority fee fits inside it, and uses the same cap and gas limit both when building the transaction and when showing the maximum possible fee. It also improves input validation so malformed gas limits are rejected and fee numbers are properly localized for different languages.