SW
← All projectsStack Wallet

Stack Wallet

Actively maintained multi-coin self-custody wallet with Monero support and on-device keys.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

1038 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

334security candidates400second-pass queue734AI analyses
66commits · 30 days
160commits · 60 days
606commits · 180 days
1009commits · 365 days
Backfill bands
Sep 27 → Mar 31404 seen73 candidatesComplete
Mar 31 → Jul 29463 seen238 candidatesComplete
Jul 29 → Aug 2887 seen8 candidatesComplete
Aug 28 → Sep 2753 seen6 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

51/100 average clarity
33Strong · 80–100
309Adequate · 60–79
506Thin · 40–59
190Opaque · 0–39
32security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Navid Rahimi1017154
sneurlax339158241062
julian347112269044
Julian18939136042
Dan Miller831525053
Reuben Yap20318052
julian-CStack222049
levoncrypto24121043
Tritonn204412052
cassandras-lies413048
NyanCatTW1111045
Cyrix126804045
Analysis record

Published AI watches

Last scanned 30 minutes ago

Low 35 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1450 from Ez3kiel-dev/fix/xelis-integration

This is a large feature/fix merge that restores and rewrites the Xelis (XEL) cryptocurrency integration in Stack Wallet. It swaps the old hand-rolled Xelis code for a new generated native interface (XWF), adds wallet restore/backup support…

Send-flow lifecycle hardening: prepared Xelis transactions are now discarded via cancelSend when the user cancels or the widget is disposedSession-generation checks prevent stale wallet handles from being used after close/reopenMutex serialization added around send preparation, balance, history, and rescan operations
ad945d43by Julian+4298−162634 files
No security note in commit
Low 32 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/xelis-integration

This commit is a large merge that mainly adds integration tests for a desktop 'forgot password' reset feature and makes supporting code changes to safely shut down background database workers during that reset. It also removes a large set …

New integration tests exercise a destructive 'forgot password' data-wipe featureTests assert that password store and wallet key store are deleted on successful resetTests assert that wallet files are deleted while backup and tor state are preserved
b0e5d35aby Julian+2678−330378 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1361 from cypherstack/fix/305-multiline-transaction-notes

This commit lets users type multi-line notes when editing transaction and trade notes, and fixes the desktop layout so long notes scroll instead of breaking the screen. It also swaps the old `mounted` check for the newer `context.mounted` …

5172e63eby Julian+402−1113 files
No security note in commit
Low 32 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/305-multiline-transaction-notes

This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive h…

Added safe shutdown of Firo cache isolates/SQLite databases before reset exitNew integration tests verify desktop forgot-password reset deletes secrets and preserves backupsTest harness intercepts exit() and IOOverrides to observe reset side effects
21491edbby Julian+2352−319075 files
No security note in commit
Moderate 57 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1455 from cypherstack/fix/desktop-pw-reset

This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to clos…

Desktop password reset now closes Firo cache workers and SQLite databases before deleting app data, reducing the risk of data leakage or corruption during wipeNew integration tests assert that a successful reset removes password store (hive/desktopdata.hive), wallet key store (isar/desktopStore.isar), and wallet files while preserving backups and tor stateFailed reset scenario leaves a .reset-pending marker and removes password/key stores first, preventing the reset from being undone after partial deletion
055e6c6bby Julian+1077−297154 files
No security note in commit
Low 37 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/desktop-pw-reset

This commit is a large merge that mainly adds a new 'prove you own a Spark address' feature to the Stack Wallet app, plus some related fixes. It also updates a dependency that handles SOCKS5 proxy connections and changes how the app decide…

New cryptographic signing path added: SparkInterface.signMessage now delegates to Spark ownership proof creation using the wallet's private key and spark derivation path.Ownership proof code rejects view-only wallets and blank messages, and searches a 100-address lookahead for the requested address before signing.Dependency upgrade: socks5_proxy 1.0.3+dev.3 -> 2.1.1, which may change SOCKS5/Tor proxy behavior; a new test verifies hostname/onion routing through a fake SOCKS server.
d9b5cc02by Julian+1275−21923 files
No security note in commit
Low 34 AI analysisMessage 83 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1439 from navidR/dev/navidr/spark-name-verification

This commit adds a new feature to Stack Wallet that lets users prove they own a Spark (privacy) address by generating a cryptographic ownership proof. It also improves the sign/verify screens so view-only wallets can still verify proofs, a…

New cryptographic proof generation using private key material (privateKeyHex, spendKeyIndex, diversifier) inside an isolateView-only wallet guard added for proof creation (throws if isViewOnly)Message whitespace now preserved for pasted/typed challenge messages, preventing proof/verification mismatches caused by silent trimming
a5411a50by Julian+1097−16616 files
No security note in commit
Low 39 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into dev/navidr/spark-name-verification

This commit merges several changes into a development branch. The most notable security-relevant change is a fix for how the Trocador exchange service routes traffic: it now automatically uses Tor (an anonymity network) when the user has T…

Trocador exchange API previously forced clearnet (`isOnion: false`) at every call site, bypassing Tor even when enabledNew `_useTor` getter centralizes Tor routing decision based on app feature flag and user preferenceOnion service address rotated to a new v3 .onion hostname
92955848by Julian+122−507 files
No security note in commit
Informational 24 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Spark: add address ownership proof signing and verification

This commit adds a new feature to Stack Wallet that lets Spark (Firo privacy) address owners prove they control an address, and lets others verify that proof. It also fixes a few related UI issues: view-only wallets can now only verify (no…

New cryptographic signing/verification API integrated into walletView-only wallet restriction added to prevent signing with private keysWhitespace preservation in pasted messages reduces signature/verification mismatch risk
eb370258by Navid Rahimi+1097−16616 files
No security note in commit
Informational 20 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into feat/trocador-onion

This commit adds a small convenience feature in Stack Wallet: when a user scans or opens a Firo payment QR code that contains a 'message' field and the payment address is a Spark privacy address, the wallet now automatically copies that me…

Untrusted paymentData.message is copied into a transaction memo field without visible escaping/sanitizationRelies on SparkInterface.validateSparkAddress to gate memo population; correctness of that helper is not shown in the diffBehavior parity with firo-qt suggests a UX fix rather than a vulnerability fix
a0a72593by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1463 from cypherstack/fix/firo-uri-message-to-spark-memo

This commit fixes a small user-experience gap in the Stack Wallet app for Firo cryptocurrency users. When someone scans or opens a Firo payment link (URI) that includes a message and the payment is going to a Spark privacy address, the app…

No security-relevant signals detected in the diff.Change is a UI autofill feature for Firo Spark memos from payment URI messages.No input sanitization changes beyond existing address validation.
48d10009by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

fix(firo): fill spark memo from payment URI message

This commit fixes a small user-experience bug in Stack Wallet for Firo cryptocurrency. When a user scanned or pasted a firo: payment link containing a message, the app previously put that message only in the local private note field. Now, …

No input sanitization on URI-derived memo before assigning to controllerBehavior aligned with firo-qt reference implementationNo changes to signing, encryption, address parsing, or network calls
60a6112dby sneurlax+20−02 files
No security note in commit
Low 30 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1452 from levoncrypto/masternode-operator-reward

This commit removes the user-facing 'operator reward' field from the Firo masternode registration screen and hard-codes that value to zero in the wallet logic. It is a feature removal rather than a fix for an active security flaw, but it d…

Removal of user-supplied numeric field that directly influenced on-chain transaction payload (nOperatorReward basis points)Elimination of locale-dependent decimal parsing and rounding path for a consensus-relevant valueHard-coding of a transaction field that previously had range/validation checks
7d9cba12by Julian+1−622 files
No security note in commit
Low 42 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit changes how a Firo cryptocurrency wallet picks a special 'owner address' when setting up a masternode. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also checks that t…

Address reuse prevention for masternode owner/payout rolesDefensive validation of derived addresses before useException raised when a suitable distinct address cannot be derived
e88cb980by Julian+9−81 file
No security note in commit
Low 42 AI analysisMessage 58 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1453 from levoncrypto/masternode-payout-ui

This change updates the Firo wallet's masternode owner address selection so that the chosen owner address is different from both the collateral address and the payout address. Previously, the code only ensured the owner address differed fr…

Defensive address-distinctness check added for masternode owner addressPrevents owner address from matching payout address, not just collateral addressError message updated to reflect new dual-distinctness requirement
fb70bccaby Julian+9−81 file
No security note in commit
Informational 19 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-payout-ui

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO across several app variants. It updates token lists, adds an icon, and includes a database migration so existing users automatically see the ne…

No security-relevant code changes observedNew asset and token configuration onlyDatabase migration is additive and idempotent (checks for existing contract before insert)
1324e37aby Julian+454−29520 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO, updates some app configuration scripts, refreshes a privacy-related Git dependency, and fills in missing API-key placeholders for exchange int…

Database migration inserts a hardcoded token contract if the app config includes it and the contract is not already presentExternal Git dependency mobile_app_privacy changed to a new commit; content of new commit not suppliedNew exchange API key placeholders added (Trocador, LetsExchange, CypherGoat) in test/prebuild scripts
8cc81383by Julian+500−30528 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1448 from reubenyap/codex/rsfiro-app-config

This commit adds support for a new Ethereum token called rsFIRO and makes the list of default Ethereum tokens configurable for each app flavor (Stack Wallet, Stack Duo, Campfire). It also includes a database migration so existing users get…

Database migration inserts a hardcoded ERC-20 contract address into user data based on app configurationMigration checks for existing contract by case-insensitive address comparison before insertionToken icon rendering now branches on contract address equality, which is a presentation-layer change
6203aeaeby Julian+454−29520 files
No security note in commit
Informational 24 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

allow owner address to equal voting address

This small change relaxes a wallet rule for the Firo cryptocurrency. Previously, when setting up a masternode-like service, the wallet required the 'owner address' to be different from the 'voting address'. Now it allows them to be the sam…

Removal of address distinctness check between owner and voting addressesChange affects Firo masternode address derivation logicNo input validation, cryptographic, or memory-safety changes present
19add823by levoncrypto+3−41 file
No security note in commit
Moderate 59 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

pick owner address distinct from payout and voting addresses

This change fixes how Stack Wallet picks a special 'owner address' for Firo masternode-related operations. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also ensures it differs fr…

Address reuse prevention across masternode rolesFiro masternode owner/payout/voting address separationPrivacy improvement by avoiding identical addresses for distinct transaction roles
86b9ec97by levoncrypto+10−81 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

AI review queuedfix node backup restoresby Julian · f8c2bb12 · Aug 15, 2026 · 3 filesMessage 28 · OpaqueLow 30Details
Commit message · Julian

fix node backup restores

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 30/100

This commit fixes how Stack Wallet restores saved cryptocurrency node settings from backups. Previously, the restore code assumed fields like SSL, Tor, and primary-node flags were stored in specific formats (sometimes text, sometimes true/false) and could misread or drop values, potentially restoring a node with the wrong security/privacy settings. The patch introduces a single, tested helper that consistently interprets those fields across old and new backup formats, and also preserves a previously-missing 'node API secret' field during restore.

AI review queuedfix btc frost priceby Julian · 9685de56 · Aug 15, 2026 · 2 filesMessage 28 · OpaqueInformational 17Details
Commit message · Julian

fix btc frost price

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 17/100

This commit fixes a bug in how the Stack Wallet app fetches cryptocurrency prices from CoinGecko. Previously, the app tried to match coins by their display name (e.g., 'Bitcoin'), which caused 'Bitcoin Frost' to be missed because its name differs. The change now matches coins by their unique CoinGecko ID instead, so both regular Bitcoin and Bitcoin Frost get correct price data. There is no security vulnerability here—it's a functional bug fix for price display accuracy.

AI review queuedfix swap rate sortingby Julian · f9182524 · Aug 15, 2026 · 2 filesMessage 28 · OpaqueInformational 24Details
Commit message · Julian

fix swap rate sorting

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 24/100

This commit fixes a bug in how Stack Wallet sorts cryptocurrency exchange rate estimates. Previously, the sorting logic was broken: it could place failed/null estimates incorrectly and did not reliably show the best (highest) rate first. The fix ensures better rates appear at the top and failed providers are pushed to the bottom. It is a UI/ordering bug, not a direct theft-of-funds vulnerability, but it could mislead a user into picking a worse exchange rate.

Lower-prioritytighten up payment uri parsingby Julian · f5bfe88b · Aug 15, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Julian

tighten up payment uri parsing

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedtighten up amount parsingby Julian · f32a921e · Aug 15, 2026 · 5 filesMessage 35 · OpaqueModerate 51Details
Commit message · Julian

tighten up amount parsing

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Moderate 51/100

This commit tightens how the wallet parses amounts typed or pasted by users. It now rejects strings that contain plus/minus signs or hidden whitespace characters (like tabs and newlines), and it turns on 'strict' parsing in more places so that spaces inside an amount are not silently ignored. The change is defensive: it reduces the chance that a cleverly crafted amount string could be misread, potentially leading to a wrong payment amount or an unexpected transaction.

AI review queuedhandle zero restore chain heightby Julian · e0dbdb8f · Aug 14, 2026 · 4 filesMessage 45 · ThinInformational 19Details
Commit message · Julian

handle zero restore chain height

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit fixes a simple math bug that could occur when a cryptocurrency wallet tries to show how far along a restore/sync is, but the current blockchain height is reported as zero. Previously, dividing by zero could produce an invalid result (infinity or 'not a number'). The change makes the progress show 0% until a real chain height is known. It is a robustness fix, not a security vulnerability that an attacker can exploit.

Lower-priorityfix address copy button valueby Julian · a6531a98 · Aug 14, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Julian

fix address copy button value

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityfix double decoding which can cause weird issuesby Julian · 68b206bb · Aug 14, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Julian

fix double decoding which can cause weird issues

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Security candidateppc default fee rate updateby Julian · 696a54e5 · Aug 14, 2026 · 2 filesMessage 45 · ThinInformational 19Details
Commit message · Julian

ppc default fee rate update

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 19/100

This commit increases the default Peercoin transaction fee rate from 5000 to 10000 satoshis per kilobyte and adds a test to verify the new value. It is a routine fee policy adjustment, not a security fix. The only code change besides the fee value is a minor formatting/indentation cleanup in an unrelated address derivation block.

Security candidatefix dash dust limitby Julian · a4ea73bf · Aug 14, 2026 · 2 filesMessage 28 · OpaqueLow 37Details
Commit message · Julian

fix dash dust limit

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Low 37/100

This commit fixes the minimum spendable amount ('dust limit') for Dash in the Stack Wallet app. It was incorrectly set to 0.01 DASH (1,000,000 satoshis), which is far above Dash's actual network rule of 546 satoshis. The change lowers the limit so users can send smaller valid Dash amounts. A test was added to prevent the value from drifting again.

AI review queuedadd paynym notif tx input checkby Julian · c12e533d · Aug 14, 2026 · 2 filesMessage 45 · ThinLow 42Details
Commit message · Julian

add paynym notif tx input check

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 42/100

This commit adds a safety check to prevent a Bitcoin PayNym notification transaction from being built using only Taproot (BIP86) inputs. The new code throws an error if the first input is Taproot, while allowing mixed or non-Taproot inputs. PayNym notification transactions have specific protocol requirements, and using an all-Taproot input set could lead to an invalid or incompatible notification that another wallet might not recognize, potentially causing loss of privacy or failed payments. The change is defensive and includes a unit test.

AI review queuedupdate mocksby Julian · ea722de8 · Aug 14, 2026 · 6 filesMessage 18 · OpaqueInformational 15Details
Commit message · Julian

update mocks

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only updates automatically generated test mock files so they match a new method signature for a network health-check ('ping') call. No real application code, user data, or wallet security behavior changed. It is a routine test-maintenance change with no security relevance.

Lower-priorityfix duplicate trade details dialog appearing on desktopby Julian · 75d0e18d · Aug 14, 2026 · 2 filesMessage 50 · ThinTriage 0Details
Commit message · Julian

fix duplicate trade details dialog appearing on desktop

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedfix sorting to match commentby Julian · e1354a89 · Aug 14, 2026 · 2 filesMessage 45 · ThinLow 34Details
Commit message · Julian

fix sorting to match comment

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 34/100

This commit fixes a sorting bug in how the wallet chooses which coins (UTXOs) to use when sending a BIP47/Paynym notification transaction. The code's comment said taproot coins should be used last and the oldest non-taproot coins first, but the actual sort was doing the opposite for age (newest first). The fix makes the code match the comment. Because notification transactions are special (they reveal a payment code to the recipient), using the wrong coin order could cause the wallet to select a taproot coin when a non-taproot one was available, potentially breaking notification parsing for the receiver or causing the wallet to fall back to a less desirable coin selection.

Lower-priorityreturn false on ping timeoutby Julian · 97ddbfba · Aug 14, 2026 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · Julian

return false on ping timeout

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Security candidatefix missing xelis stagenet caseby Julian · 53481873 · Aug 14, 2026 · 1 fileMessage 45 · ThinLow 26Details
Commit message · Julian

fix missing xelis stagenet case

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Low 26/100

A one-line fix in the Stack Wallet app changed the Xelis cryptocurrency network setup so that the 'stagenet' (a test-like network) uses the correct stagenet node address, instead of accidentally reusing the 'testnet' case. This appears to be a bug-fix for wallet network selection, not a security vulnerability. There is no evidence in the commit of malicious intent or a disclosed security issue.

AI review queuedclean up epicbox/http/https checkby Julian · 598898ae · Aug 14, 2026 · 2 filesMessage 45 · ThinLow 29Details
Commit message · Julian

clean up epicbox/http/https check

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 29/100

This commit fixes a logic bug in how Stack Wallet decides whether to use an Epicbox server or an HTTP/HTTPS receiver when sending Epic Cash transactions. The old code used OR instead of AND when checking for HTTP/HTTPS prefixes, which meant every receiver address was treated as needing an Epicbox check. The new code cleanly separates the two paths and adds a unit test to confirm HTTP/HTTPS addresses bypass Epicbox while email-style Epicbox addresses use it.

AI review queuedfix mweb fee providerby Julian · 9cd17dbd · Aug 14, 2026 · 1 fileMessage 28 · OpaqueLow 26Details
Commit message · Julian

fix mweb fee provider

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 26/100

This commit fixes a small but meaningful mix-up in the mobile wallet's send screen. The code was reading the desktop fee-rate setting when preparing a Litecoin MWEB (privacy) transaction, instead of reading the mobile fee-rate setting. If the two settings differ, the user could end up paying an unexpected fee, or the transaction might not be built with the fee they actually selected on their phone. There is no direct evidence in the commit of funds being stolen or a remote attacker being able to exploit this.

AI review queuedfix exchange refund gatingby Julian · 3b57511d · Aug 14, 2026 · 1 fileMessage 35 · OpaqueModerate 50Details
Commit message · Julian

fix exchange refund gating

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Moderate 50/100

This commit fixes a single-character bug in the Stack Wallet exchange flow. A double negation (!!) was accidentally used where a single negation (!) was intended. The bug caused the app to require a refund address even from exchanges that do not support one, which could block legitimate transactions. The fix changes the logic so that a refund address is only required when the exchange actually supports it. There is no direct evidence in the commit that this was a security vulnerability, but a mis-gated refund flow could in theory lead to user confusion or funds being sent to an unsupported/invalid refund path.

AI review queuedfix checkTrades early returnby Julian · c6f639c8 · Aug 14, 2026 · 1 fileMessage 35 · OpaqueLow 33Details
Commit message · Julian

fix checkTrades early return

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 33/100

This commit fixes a bug in the wallet's notification service where checking one trade could accidentally stop all remaining trade checks. The function now correctly continues to the next trade instead of returning early. It also makes the trade-check function properly asynchronous so the periodic timer doesn't wait on it. This is a reliability/bug-fix change with minor security relevance: a stuck or failing trade check could have delayed or suppressed status updates for other trades, potentially hiding problems from the user.

AI review queuedensure marked used UTXOs do not get included in frost txnby Julian · f372d522 · Aug 14, 2026 · 1 fileMessage 50 · ThinModerate 58Details
Commit message · Julian

ensure marked used UTXOs do not get included in frost txn

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 58/100

This commit fixes a bug in Stack Wallet's Bitcoin FROST wallet where coins that had already been spent (marked as 'used') could still be selected for new transactions. This could cause the wallet to attempt to spend the same coin twice, leading to failed or invalid transactions. The fix adds a filter to exclude any UTXOs that are marked as used or have an unclear used status.

Security candidatefix test with platform specific checkby Julian · 11c5bdfd · Aug 14, 2026 · 1 fileMessage 55 · ThinInformational 13Details
Commit message · Julian

fix test with platform specific check

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 13/100

This is a tiny change to a single automated test file. It makes the test expect different behavior on Linux versus other platforms when setting up a PIN, because Linux does not support the same biometric checks. There is no change to the actual wallet app code that users interact with, so this does not create or fix a security vulnerability.

AI review queuedfix frost prev keys issueby Julian · 9c37a8f0 · Aug 14, 2026 · 2 filesMessage 45 · ThinInformational 20Details
Commit message · Julian

fix frost prev keys issue

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100

This commit fixes a UI bug in Stack Wallet's desktop FROST wallet key popup. The previous version accidentally displayed the current FROST keys/config in the section meant to show the previous generation's keys/config. The patch corrects which data is shown in each section and adds a widget test to verify the fix. There is no direct evidence in the commit that this was a security vulnerability, but mislabeling sensitive key material could confuse users.

AI review queuedfix mwc first blockby Julian · 0e56467c · Aug 14, 2026 · 1 fileMessage 28 · OpaqueInformational 17Details
Commit message · Julian

fix mwc first block

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 17/100

This commit changes a single constant used to estimate the first block time for the Mimblewimblecoin (MWC) cryptocurrency when restoring a wallet from a date. The old value was too early, which could cause wallet restores to scan blocks that did not exist yet. The new value is later and more accurate. There is no direct security vulnerability here; it is a correctness fix that may affect user experience and restore accuracy.

Lower-priorityclean up isar wallet data deleteby Julian · 467f6103 · Aug 14, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · Julian

clean up isar wallet data delete

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body