SW
← All projectsStack Wallet

Stack Wallet

Actively maintained multi-coin self-custody wallet with Monero support and on-device keys.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

1034 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

332security candidates400second-pass queue732AI analyses
62commits · 30 days
156commits · 60 days
602commits · 180 days
1013commits · 365 days
Backfill bands
Sep 27 → Mar 31404 seen73 candidatesComplete
Mar 31 → Jul 29463 seen238 candidatesComplete
Jul 29 → Aug 2887 seen8 candidatesComplete
Aug 28 → Sep 2753 seen6 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

51/100 average clarity
32Strong · 80–100
307Adequate · 60–79
505Thin · 40–59
190Opaque · 0–39
32security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Navid Rahimi1017154
sneurlax338158241062
julian347112269044
Julian18637134042
Dan Miller831525053
Reuben Yap20318052
julian-CStack222049
levoncrypto24121043
Tritonn204412052
cassandras-lies413048
NyanCatTW1111045
Cyrix126804045
Analysis record

Published AI watches

Last scanned 41 minutes ago

Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1361 from cypherstack/fix/305-multiline-transaction-notes

This commit lets users type multi-line notes when editing transaction and trade notes, and fixes the desktop layout so long notes scroll instead of breaking the screen. It also swaps the old `mounted` check for the newer `context.mounted` …

5172e63eby Julian+402−1113 files
No security note in commit
Low 32 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/305-multiline-transaction-notes

This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive h…

Added safe shutdown of Firo cache isolates/SQLite databases before reset exitNew integration tests verify desktop forgot-password reset deletes secrets and preserves backupsTest harness intercepts exit() and IOOverrides to observe reset side effects
21491edbby Julian+2352−319075 files
No security note in commit
Moderate 57 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1455 from cypherstack/fix/desktop-pw-reset

This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to clos…

Desktop password reset now closes Firo cache workers and SQLite databases before deleting app data, reducing the risk of data leakage or corruption during wipeNew integration tests assert that a successful reset removes password store (hive/desktopdata.hive), wallet key store (isar/desktopStore.isar), and wallet files while preserving backups and tor stateFailed reset scenario leaves a .reset-pending marker and removes password/key stores first, preventing the reset from being undone after partial deletion
055e6c6bby Julian+1077−297154 files
No security note in commit
Low 37 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into fix/desktop-pw-reset

This commit is a large merge that mainly adds a new 'prove you own a Spark address' feature to the Stack Wallet app, plus some related fixes. It also updates a dependency that handles SOCKS5 proxy connections and changes how the app decide…

New cryptographic signing path added: SparkInterface.signMessage now delegates to Spark ownership proof creation using the wallet's private key and spark derivation path.Ownership proof code rejects view-only wallets and blank messages, and searches a 100-address lookahead for the requested address before signing.Dependency upgrade: socks5_proxy 1.0.3+dev.3 -> 2.1.1, which may change SOCKS5/Tor proxy behavior; a new test verifies hostname/onion routing through a fake SOCKS server.
d9b5cc02by Julian+1275−21923 files
No security note in commit
Low 34 AI analysisMessage 83 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1439 from navidR/dev/navidr/spark-name-verification

This commit adds a new feature to Stack Wallet that lets users prove they own a Spark (privacy) address by generating a cryptographic ownership proof. It also improves the sign/verify screens so view-only wallets can still verify proofs, a…

New cryptographic proof generation using private key material (privateKeyHex, spendKeyIndex, diversifier) inside an isolateView-only wallet guard added for proof creation (throws if isViewOnly)Message whitespace now preserved for pasted/typed challenge messages, preventing proof/verification mismatches caused by silent trimming
a5411a50by Julian+1097−16616 files
No security note in commit
Low 39 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into dev/navidr/spark-name-verification

This commit merges several changes into a development branch. The most notable security-relevant change is a fix for how the Trocador exchange service routes traffic: it now automatically uses Tor (an anonymity network) when the user has T…

Trocador exchange API previously forced clearnet (`isOnion: false`) at every call site, bypassing Tor even when enabledNew `_useTor` getter centralizes Tor routing decision based on app feature flag and user preferenceOnion service address rotated to a new v3 .onion hostname
92955848by Julian+122−507 files
No security note in commit
Informational 24 AI analysisMessage 60 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Spark: add address ownership proof signing and verification

This commit adds a new feature to Stack Wallet that lets Spark (Firo privacy) address owners prove they control an address, and lets others verify that proof. It also fixes a few related UI issues: view-only wallets can now only verify (no…

New cryptographic signing/verification API integrated into walletView-only wallet restriction added to prevent signing with private keysWhitespace preservation in pasted messages reduces signature/verification mismatch risk
eb370258by Navid Rahimi+1097−16616 files
No security note in commit
Informational 20 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into feat/trocador-onion

This commit adds a small convenience feature in Stack Wallet: when a user scans or opens a Firo payment QR code that contains a 'message' field and the payment address is a Spark privacy address, the wallet now automatically copies that me…

Untrusted paymentData.message is copied into a transaction memo field without visible escaping/sanitizationRelies on SparkInterface.validateSparkAddress to gate memo population; correctness of that helper is not shown in the diffBehavior parity with firo-qt suggests a UX fix rather than a vulnerability fix
a0a72593by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1463 from cypherstack/fix/firo-uri-message-to-spark-memo

This commit fixes a small user-experience gap in the Stack Wallet app for Firo cryptocurrency users. When someone scans or opens a Firo payment link (URI) that includes a message and the payment is going to a Spark privacy address, the app…

No security-relevant signals detected in the diff.Change is a UI autofill feature for Firo Spark memos from payment URI messages.No input sanitization changes beyond existing address validation.
48d10009by Julian+20−02 files
No security note in commit
Informational 19 AI analysisMessage 85 · Strong
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

fix(firo): fill spark memo from payment URI message

This commit fixes a small user-experience bug in Stack Wallet for Firo cryptocurrency. When a user scanned or pasted a firo: payment link containing a message, the app previously put that message only in the local private note field. Now, …

No input sanitization on URI-derived memo before assigning to controllerBehavior aligned with firo-qt reference implementationNo changes to signing, encryption, address parsing, or network calls
60a6112dby sneurlax+20−02 files
No security note in commit
Low 30 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1452 from levoncrypto/masternode-operator-reward

This commit removes the user-facing 'operator reward' field from the Firo masternode registration screen and hard-codes that value to zero in the wallet logic. It is a feature removal rather than a fix for an active security flaw, but it d…

Removal of user-supplied numeric field that directly influenced on-chain transaction payload (nOperatorReward basis points)Elimination of locale-dependent decimal parsing and rounding path for a consensus-relevant valueHard-coding of a transaction field that previously had range/validation checks
7d9cba12by Julian+1−622 files
No security note in commit
Low 42 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit changes how a Firo cryptocurrency wallet picks a special 'owner address' when setting up a masternode. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also checks that t…

Address reuse prevention for masternode owner/payout rolesDefensive validation of derived addresses before useException raised when a suitable distinct address cannot be derived
e88cb980by Julian+9−81 file
No security note in commit
Low 42 AI analysisMessage 58 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1453 from levoncrypto/masternode-payout-ui

This change updates the Firo wallet's masternode owner address selection so that the chosen owner address is different from both the collateral address and the payout address. Previously, the code only ensured the owner address differed fr…

Defensive address-distinctness check added for masternode owner addressPrevents owner address from matching payout address, not just collateral addressError message updated to reflect new dual-distinctness requirement
fb70bccaby Julian+9−81 file
No security note in commit
Informational 19 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-payout-ui

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO across several app variants. It updates token lists, adds an icon, and includes a database migration so existing users automatically see the ne…

No security-relevant code changes observedNew asset and token configuration onlyDatabase migration is additive and idempotent (checks for existing contract before insert)
1324e37aby Julian+454−29520 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge branch 'staging' into masternode-operator-reward

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO, updates some app configuration scripts, refreshes a privacy-related Git dependency, and fills in missing API-key placeholders for exchange int…

Database migration inserts a hardcoded token contract if the app config includes it and the contract is not already presentExternal Git dependency mobile_app_privacy changed to a new commit; content of new commit not suppliedNew exchange API key placeholders added (Trocador, LetsExchange, CypherGoat) in test/prebuild scripts
8cc81383by Julian+500−30528 files
No security note in commit
Informational 19 AI analysisMessage 73 · Adequate
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge pull request #1448 from reubenyap/codex/rsfiro-app-config

This commit adds support for a new Ethereum token called rsFIRO and makes the list of default Ethereum tokens configurable for each app flavor (Stack Wallet, Stack Duo, Campfire). It also includes a database migration so existing users get…

Database migration inserts a hardcoded ERC-20 contract address into user data based on app configurationMigration checks for existing contract by case-insensitive address comparison before insertionToken icon rendering now branches on contract address equality, which is a presentation-layer change
6203aeaeby Julian+454−29520 files
No security note in commit
Informational 24 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

allow owner address to equal voting address

This small change relaxes a wallet rule for the Firo cryptocurrency. Previously, when setting up a masternode-like service, the wallet required the 'owner address' to be different from the 'voting address'. Now it allows them to be the sam…

Removal of address distinctness check between owner and voting addressesChange affects Firo masternode address derivation logicNo input validation, cryptographic, or memory-safety changes present
19add823by levoncrypto+3−41 file
No security note in commit
Moderate 59 AI analysisMessage 50 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

pick owner address distinct from payout and voting addresses

This change fixes how Stack Wallet picks a special 'owner address' for Firo masternode-related operations. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also ensures it differs fr…

Address reuse prevention across masternode rolesFiro masternode owner/payout/voting address separationPrivacy improvement by avoiding identical addresses for distinct transaction roles
86b9ec97by levoncrypto+10−81 file
No security note in commit
Informational 15 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

assets: clean rsFIRO SVGs with svgcleaner

This commit simply runs a cleanup tool on three SVG image files used for the rsFIRO cryptocurrency icon. It removes unnecessary formatting and metadata from the image files without changing their visual appearance. There is no security rel…

570e3e2aby Reuben Yap+3−333 files
No security note in commit
Informational 18 AI analysisMessage 45 · Thin
SW Stack WalletStack Wallet MoneroPrivacy protocolsSoftware wallets

Merge staging and keep the upstream CI workflow

This commit is a routine merge from a staging branch that mostly tidies up build scripts and CI. The only user-visible change is that the Firo wallet now groups 'revoked' and 'banned' masternodes together under a single red 'banned' label,…

Dependency version bump for mobile_app_privacy (git ref changed).gitignore relaxation for cs_monero build artifacts and diff filesCI/build scripts now auto-generate API key template with additional Trocador placeholders
2dbadce6by Reuben Yap+63−1610 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateMerge branch 'staging' into fix/305-multiline-transaction-notesby Julian · 21491edb · Oct 5, 2026 · 75 filesMessage 50 · ThinLow 32Details
Commit message · Julian

Merge branch 'staging' into fix/305-multiline-transaction-notes

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathauthentication pathmerge-commit duplicate discount
AI analysis · Low 32/100

This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive hardening for a data-wipe feature rather than an active security vulnerability. There is no clear exploit or malicious change in the diff, but the merge is broad and the actual production reset logic is only partially visible, so we cannot fully verify it is safe.

Security candidateMerge pull request #1455 from cypherstack/fix/desktop-pw-resetby Julian · 055e6c6b · Oct 5, 2026 · 54 filesMessage 73 · AdequateModerate 57Details
Commit message · Julian

Merge pull request #1455 from cypherstack/fix/desktop-pw-reset

fix(desktop): desktop forgot password flow and app startup process re…

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathauthentication pathmerge-commit duplicate discount
AI analysis · Moderate 57/100

This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to close cleanly during that wipe. The change is defensive: it makes sure databases and background workers shut down before files are deleted, so leftover data or crashed workers do not leave sensitive information behind.

Security candidateSpark: add address ownership proof signing and verificationby Navid Rahimi · eb370258 · Oct 5, 2026 · 16 filesMessage 60 · AdequateInformational 24Details
Commit message · Navid Rahimi

Spark: add address ownership proof signing and verification

60/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing boundarydefensive validationsigning or wallet path
AI analysis · Informational 24/100

This commit adds a new feature to Stack Wallet that lets Spark (Firo privacy) address owners prove they control an address, and lets others verify that proof. It also fixes a few related UI issues: view-only wallets can now only verify (not sign) Spark proofs, pasted messages keep exact spaces/newlines instead of being trimmed, and the signing/verification screens scroll properly on desktop. There is no direct evidence in the commit that this fixes an active security vulnerability; it reads as a feature addition with some hardening improvements.

Security candidateMerge branch 'staging' into masternode-payout-uiby Julian · 1324e37a · Sep 25, 2026 · 20 filesMessage 45 · ThinInformational 19Details
Commit message · Julian

Merge branch 'staging' into masternode-payout-ui

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathauthentication pathmerge-commit duplicate discount
AI analysis · Informational 19/100

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO across several app variants. It updates token lists, adds an icon, and includes a database migration so existing users automatically see the new token. There is no indication this change fixes a security vulnerability or introduces a known dangerous behavior.

Security candidateMerge branch 'staging' into masternode-operator-rewardby Julian · 8cc81383 · Sep 25, 2026 · 28 filesMessage 50 · ThinInformational 19Details
Commit message · Julian

Merge branch 'staging' into masternode-operator-reward

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathauthentication pathmerge-commit duplicate discount
AI analysis · Informational 19/100

This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO, updates some app configuration scripts, refreshes a privacy-related Git dependency, and fills in missing API-key placeholders for exchange integrations. There is no direct evidence in the diff of a security vulnerability, malicious code, or a fix for a disclosed security issue. The changes are mostly product/configuration plumbing.

Security candidateMerge pull request #1448 from reubenyap/codex/rsfiro-app-configby Julian · 6203aeae · Sep 25, 2026 · 20 filesMessage 73 · AdequateInformational 19Details
Commit message · Julian

Merge pull request #1448 from reubenyap/codex/rsfiro-app-config

feat: add rsFIRO with configurable Ethereum token defaults

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathauthentication pathmerge-commit duplicate discount
AI analysis · Informational 19/100

This commit adds support for a new Ethereum token called rsFIRO and makes the list of default Ethereum tokens configurable for each app flavor (Stack Wallet, Stack Duo, Campfire). It also includes a database migration so existing users get rsFIRO added automatically. There is no obvious security vulnerability in the changes, but the migration logic has a subtle edge case that could, in theory, affect token data consistency.

Security candidatefeat: generate per-app Ethereum token defaultsby Reuben Yap · 82f9fa6d · Sep 23, 2026 · 9 filesMessage 57 · ThinInformational 19Details
Commit message · Reuben Yap

feat: generate per-app Ethereum token defaults

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathauthentication path
AI analysis · Informational 19/100

This commit reorganizes how Stack Wallet and its related apps choose which Ethereum tokens appear by default. It does not fix a security bug and does not introduce an obvious vulnerability. The main change is moving the default token list from a single shared file into per-app configuration scripts, and adding a new rsFIRO token for the Campfire app. The token contract addresses shown in the diff match well-known public Ethereum addresses, so there is no direct evidence of malicious token substitution.

Security candidateMerge pull request #1437 from cypherstack/julian/various-fixes-contdby Julian · ae6a439d · Sep 19, 2026 · 234 filesMessage 58 · ThinLow 44Details
Commit message · Julian

Merge pull request #1437 from cypherstack/julian/various-fixes-contd

Julian/various fixes contd

58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathseed or entropy pathsigning or wallet pathauthentication pathmerge-commit duplicate discount
AI analysis · Low 44/100

This is a very large routine merge of 'various fixes' for the Stack Wallet Flutter app. The visible changes mostly update build tooling (Flutter 3.47.2, Android Gradle Plugin 9, Go/Rust versions), switch several crypto plugins from Git submodules to native-assets/prebuilt builds, reformat code, regenerate Isar database schema files, and fix a handful of UI/amount-handling bugs. There is no explicit security disclosure in the commit message or diff, and no single clearly exploitable vulnerability is introduced. The most security-relevant code-level changes are hardening touches: Android secure-storage options now disable reset-on-error and enable backup migration, ElectrumX ping now returns false on timeout instead of throwing, and MWEB peg-out UTXOs now enforce an extra maturity check before being considered spendable. However, the patch is huge (234 files, thousands of lines changed), so a complete security review is not possible from the supplied excerpt alone.

Security candidateformatting to make ci happyby Julian · bef9da69 · Sep 16, 2026 · 55 filesMessage 45 · ThinInformational 15Details
Commit message · Julian

formatting to make ci happy

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet pathauthentication path
AI analysis · Informational 15/100

This commit is purely a code-formatting cleanup. It changes whitespace, line breaks, and indentation across many Dart files so the project's automated style checks (CI) pass. No program logic, security behavior, or user-facing functionality was altered.

Security candidateepiccash submodule -> native assets migrationby Julian · cb88170a · Sep 15, 2026 · 9 filesMessage 45 · ThinLow 25Details
Commit message · Julian

epiccash submodule -> native assets migration

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Low 25/100

This commit changes how the Stack Wallet app pulls in its Epic Cash cryptocurrency library. Previously, the library was included as a local Git submodule inside the project. Now, the app fetches it directly from a specific Git commit on GitHub as a 'native asset' dependency. The commit also removes the user-facing display of the Epic Cash build commit hash from the About screen and deletes the code that checked whether that commit was the latest one. This is primarily a build-system and UI cleanup change; there is no direct evidence in the diff of a security vulnerability being fixed.

Security candidatefrostdart submodule -> native assets migrationby Julian · 2e20340f · Sep 14, 2026 · 4 filesMessage 45 · ThinInformational 15Details
Commit message · Julian

frostdart submodule -> native assets migration

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit changes how the app pulls in a supporting cryptography library called frostdart. Previously it was included as a local submodule; now it is fetched directly from its GitHub repository at a specific commit. There is nothing in the commit that fixes, introduces, or discusses a security vulnerability. It is a routine build/dependency plumbing change.

Security candidatemwc native assets package migration (removes need for submodule and fixes issue on macos)by Julian · 2509dd9e · Sep 11, 2026 · 11 filesMessage 50 · ThinInformational 18Details
Commit message · Julian

mwc native assets package migration (removes need for submodule and fixes issue on macos)

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 18/100

This commit changes how the Mimblewimblecoin (MWC) crypto library is bundled in the Stack Wallet app. It removes the old Git submodule setup and instead pulls the library directly from a specific Git commit. It also re-enables MWC support on macOS and removes some on-screen build-commit information for MWC. There is no obvious security vulnerability in the diff itself, but the change shifts trust to a pinned external Git reference and removes a visible transparency check.

Security candidateflutter 3.47 and dart 3.13 minimum and associated changesby Julian · 2dc2473b · Sep 9, 2026 · 20 filesMessage 50 · ThinInformational 18Details
Commit message · Julian

flutter 3.47 and dart 3.13 minimum and associated changes

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 18/100

This commit updates the Stack Wallet app to require newer Flutter and Dart versions. Most changes are routine housekeeping: reformatting code, removing the 'final' keyword from function parameters to match new language rules, updating iOS/macOS build files, and bumping dependency versions. There are a few small logic tweaks, such as adding null-assertions ('!') to some wallet scanning code and changing how the app detects iPads, but nothing in the diff clearly introduces or fixes a security vulnerability.

Security candidateserialize external amounts with locale-independent decimals and use standard monero family query parametersby Julian · c0f7e2f2 · Aug 26, 2026 · 4 filesMessage 50 · ThinLow 45Details
Commit message · Julian

serialize external amounts with locale-independent decimals and use standard monero family query parameters

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Low 45/100

This commit fixes how the wallet builds payment QR codes and web links so that the amount is written in a standard, locale-independent decimal format and uses the correct parameter names for Monero-family coins. Before, a user in a country that uses a comma as the decimal separator could generate a QR code with an amount another wallet might misread, and Monero-style URIs used non-standard fields. The change also adds input formatting and parsing helpers to keep the user's typed amount consistent with their locale while exporting a canonical decimal string.

Security candidatehandle mweb 6 required min confirmsby Julian · 143ae539 · Aug 19, 2026 · 6 filesMessage 45 · ThinLow 37Details
Commit message · Julian

handle mweb 6 required min confirms

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Low 37/100

This commit fixes a wallet bug where Litecoin MWEB peg-out transactions could be spent before they were actually valid on the network. MWEB peg-outs require six confirmations to mature, but Stack Wallet was treating them like normal transactions that only need one confirmation. The patch detects these special outputs and enforces the six-block wait, preventing users from accidentally creating invalid or rejected transactions.

Security candidateppc default fee rate updateby Julian · 696a54e5 · Aug 14, 2026 · 2 filesMessage 45 · ThinInformational 19Details
Commit message · Julian

ppc default fee rate update

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Informational 19/100

This commit increases the default Peercoin transaction fee rate from 5000 to 10000 satoshis per kilobyte and adds a test to verify the new value. It is a routine fee policy adjustment, not a security fix. The only code change besides the fee value is a minor formatting/indentation cleanup in an unrelated address derivation block.

Security candidatefix dash dust limitby Julian · a4ea73bf · Aug 14, 2026 · 2 filesMessage 28 · OpaqueLow 37Details
Commit message · Julian

fix dash dust limit

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Low 37/100

This commit fixes the minimum spendable amount ('dust limit') for Dash in the Stack Wallet app. It was incorrectly set to 0.01 DASH (1,000,000 satoshis), which is far above Dash's actual network rule of 546 satoshis. The change lowers the limit so users can send smaller valid Dash amounts. A test was added to prevent the value from drifting again.

Security candidatefix missing xelis stagenet caseby Julian · 53481873 · Aug 14, 2026 · 1 fileMessage 45 · ThinLow 26Details
Commit message · Julian

fix missing xelis stagenet case

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Low 26/100

A one-line fix in the Stack Wallet app changed the Xelis cryptocurrency network setup so that the 'stagenet' (a test-like network) uses the correct stagenet node address, instead of accidentally reusing the 'testnet' case. This appears to be a bug-fix for wallet network selection, not a security vulnerability. There is no evidence in the commit of malicious intent or a disclosed security issue.

Security candidatefix test with platform specific checkby Julian · 11c5bdfd · Aug 14, 2026 · 1 fileMessage 55 · ThinInformational 13Details
Commit message · Julian

fix test with platform specific check

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 13/100

This is a tiny change to a single automated test file. It makes the test expect different behavior on Linux versus other platforms when setting up a PIN, because Linux does not support the same biometric checks. There is no change to the actual wallet app code that users interact with, so this does not create or fix a security vulnerability.

Security candidatefiro fix segwit address validationby Julian · 0c74bbd9 · Aug 14, 2026 · 2 filesMessage 45 · ThinModerate 59Details
Commit message · Julian

firo fix segwit address validation

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet path
AI analysis · Moderate 59/100

This commit fixes a bug in the Stack Wallet app where Firo (a cryptocurrency) address validation was incorrectly accepting Bitcoin-style 'bc1' and 'tb1' addresses. Because Firo does not use SegWit/Bech32 addresses, treating these as valid could let a user accidentally send Firo funds to a Bitcoin address, likely resulting in permanent loss of money. The patch changes the wallet to reject Bitcoin Bech32 addresses and adds tests to make sure it does so.

Security candidatesib: remove full service arrangementby julian · 84436b7e · Jul 30, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · julian

sib: remove full service arrangement

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit simply removes one travel booking option ('Full Service') from a list of choices in the Stack Wallet app's ShopinBit travel form. It is a routine product or UI change, not a security fix.

Security candidateupdate for sib 1.0.7by Julian · 283a3678 · Jul 27, 2026 · 6 filesMessage 38 · OpaqueInformational 23Details
Commit message · Julian

update for sib 1.0.7

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 23/100

This commit updates the Stack Wallet app's ShopInBit payment flow to support a new version of the ShopInBit backend API (1.0.7). It mainly adds handling for expired and underpaid invoices, allowing users to refresh or retry invoices instead of being stuck. There is no clear security vulnerability in the diff itself; it appears to be a feature/bug-fix update for payment recovery.

Security candidatesib: fix key iconby julian · a8568469 · Jul 24, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · julian

sib: fix key icon

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 15/100

This commit is a purely cosmetic UI fix for a key icon in the ShopInBit settings screen. It wraps the existing SVG key icon in a rounded grey container and applies a black color filter. There is no security relevance in the code change.

Security candidatesib: more fixes and clean upby julian · d213b222 · Jul 23, 2026 · 7 filesMessage 45 · ThinInformational 19Details
Commit message · julian

sib: more fixes and clean up

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
authentication path
AI analysis · Informational 19/100

This commit updates the Stack Wallet app's integration with the ShopInBit service. It mainly adds a new 'delivery state/province' field to order requests, normalizes how US states and Canadian provinces are displayed, and fixes a small UI spacing issue. There is no clear security problem here; it looks like routine feature cleanup to make address information more complete and consistent.

Security candidateunreviewedby Julian · 40c4ac5b · Jul 23, 2026 · 6 filesMessage 0 · OpaqueInformational 24Details
Commit message · Julian

unreviewed

0/100 · OpaqueMessage clarity
! Very short subject! Too few words to establish purpose! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
authentication path
AI analysis · Informational 24/100

This commit is a large UI refactor of the Stack Wallet 'ShopInBit' payment flow. It extracts duplicated payment-method selection and QR-code dialogs into a shared widget, fixes some navigation bugs after a payment is sent, and tightens the USDT Ethereum-address detection. There is no obvious new security vulnerability in the diff, but the change is substantial and unreviewed, so it could contain subtle bugs.