Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
51/100 average clarity
32Strong · 80–100
307Adequate · 60–79
505Thin · 40–59
190Opaque · 0–39
32security candidates with opaque commit messaging
This commit lets users type multi-line notes when editing transaction and trade notes, and fixes the desktop layout so long notes scroll instead of breaking the screen. It also swaps the old `mounted` check for the newer `context.mounted` …
This commit is a large merge that mainly removes old integration tests and adds new desktop 'forgot password' reset tests. It also adds a safe-shutdown path for background Firo cache workers and databases. The changes look like defensive h…
Added safe shutdown of Firo cache isolates/SQLite databases before reset exitNew integration tests verify desktop forgot-password reset deletes secrets and preserves backupsTest harness intercepts exit() and IOOverrides to observe reset side effects
This commit fixes the desktop "forgot password" reset flow in Stack Wallet. It adds integration tests that verify the app can securely wipe its own data when a user forgets the desktop password, and it updates the Firo cache worker to clos…
Desktop password reset now closes Firo cache workers and SQLite databases before deleting app data, reducing the risk of data leakage or corruption during wipeNew integration tests assert that a successful reset removes password store (hive/desktopdata.hive), wallet key store (isar/desktopStore.isar), and wallet files while preserving backups and tor stateFailed reset scenario leaves a .reset-pending marker and removes password/key stores first, preventing the reset from being undone after partial deletion
This commit is a large merge that mainly adds a new 'prove you own a Spark address' feature to the Stack Wallet app, plus some related fixes. It also updates a dependency that handles SOCKS5 proxy connections and changes how the app decide…
New cryptographic signing path added: SparkInterface.signMessage now delegates to Spark ownership proof creation using the wallet's private key and spark derivation path.Ownership proof code rejects view-only wallets and blank messages, and searches a 100-address lookahead for the requested address before signing.Dependency upgrade: socks5_proxy 1.0.3+dev.3 -> 2.1.1, which may change SOCKS5/Tor proxy behavior; a new test verifies hostname/onion routing through a fake SOCKS server.
This commit adds a new feature to Stack Wallet that lets users prove they own a Spark (privacy) address by generating a cryptographic ownership proof. It also improves the sign/verify screens so view-only wallets can still verify proofs, a…
New cryptographic proof generation using private key material (privateKeyHex, spendKeyIndex, diversifier) inside an isolateView-only wallet guard added for proof creation (throws if isViewOnly)Message whitespace now preserved for pasted/typed challenge messages, preventing proof/verification mismatches caused by silent trimming
This commit merges several changes into a development branch. The most notable security-relevant change is a fix for how the Trocador exchange service routes traffic: it now automatically uses Tor (an anonymity network) when the user has T…
Trocador exchange API previously forced clearnet (`isOnion: false`) at every call site, bypassing Tor even when enabledNew `_useTor` getter centralizes Tor routing decision based on app feature flag and user preferenceOnion service address rotated to a new v3 .onion hostname
This commit adds a new feature to Stack Wallet that lets Spark (Firo privacy) address owners prove they control an address, and lets others verify that proof. It also fixes a few related UI issues: view-only wallets can now only verify (no…
New cryptographic signing/verification API integrated into walletView-only wallet restriction added to prevent signing with private keysWhitespace preservation in pasted messages reduces signature/verification mismatch risk
This commit adds a small convenience feature in Stack Wallet: when a user scans or opens a Firo payment QR code that contains a 'message' field and the payment address is a Spark privacy address, the wallet now automatically copies that me…
Untrusted paymentData.message is copied into a transaction memo field without visible escaping/sanitizationRelies on SparkInterface.validateSparkAddress to gate memo population; correctness of that helper is not shown in the diffBehavior parity with firo-qt suggests a UX fix rather than a vulnerability fix
This commit fixes a small user-experience gap in the Stack Wallet app for Firo cryptocurrency users. When someone scans or opens a Firo payment link (URI) that includes a message and the payment is going to a Spark privacy address, the app…
No security-relevant signals detected in the diff.Change is a UI autofill feature for Firo Spark memos from payment URI messages.No input sanitization changes beyond existing address validation.
This commit fixes a small user-experience bug in Stack Wallet for Firo cryptocurrency. When a user scanned or pasted a firo: payment link containing a message, the app previously put that message only in the local private note field. Now, …
No input sanitization on URI-derived memo before assigning to controllerBehavior aligned with firo-qt reference implementationNo changes to signing, encryption, address parsing, or network calls
This commit removes the user-facing 'operator reward' field from the Firo masternode registration screen and hard-codes that value to zero in the wallet logic. It is a feature removal rather than a fix for an active security flaw, but it d…
Removal of user-supplied numeric field that directly influenced on-chain transaction payload (nOperatorReward basis points)Elimination of locale-dependent decimal parsing and rounding path for a consensus-relevant valueHard-coding of a transaction field that previously had range/validation checks
This commit changes how a Firo cryptocurrency wallet picks a special 'owner address' when setting up a masternode. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also checks that t…
Address reuse prevention for masternode owner/payout rolesDefensive validation of derived addresses before useException raised when a suitable distinct address cannot be derived
This change updates the Firo wallet's masternode owner address selection so that the chosen owner address is different from both the collateral address and the payout address. Previously, the code only ensured the owner address differed fr…
Defensive address-distinctness check added for masternode owner addressPrevents owner address from matching payout address, not just collateral addressError message updated to reflect new dual-distinctness requirement
This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO across several app variants. It updates token lists, adds an icon, and includes a database migration so existing users automatically see the ne…
No security-relevant code changes observedNew asset and token configuration onlyDatabase migration is additive and idempotent (checks for existing contract before insert)
This commit is a routine feature merge that adds support for a new Ethereum token called rsFIRO, updates some app configuration scripts, refreshes a privacy-related Git dependency, and fills in missing API-key placeholders for exchange int…
Database migration inserts a hardcoded token contract if the app config includes it and the contract is not already presentExternal Git dependency mobile_app_privacy changed to a new commit; content of new commit not suppliedNew exchange API key placeholders added (Trocador, LetsExchange, CypherGoat) in test/prebuild scripts
This commit adds support for a new Ethereum token called rsFIRO and makes the list of default Ethereum tokens configurable for each app flavor (Stack Wallet, Stack Duo, Campfire). It also includes a database migration so existing users get…
Database migration inserts a hardcoded ERC-20 contract address into user data based on app configurationMigration checks for existing contract by case-insensitive address comparison before insertionToken icon rendering now branches on contract address equality, which is a presentation-layer change
This small change relaxes a wallet rule for the Firo cryptocurrency. Previously, when setting up a masternode-like service, the wallet required the 'owner address' to be different from the 'voting address'. Now it allows them to be the sam…
Removal of address distinctness check between owner and voting addressesChange affects Firo masternode address derivation logicNo input validation, cryptographic, or memory-safety changes present
This change fixes how Stack Wallet picks a special 'owner address' for Firo masternode-related operations. Previously, the wallet only made sure the owner address was different from the collateral address. Now it also ensures it differs fr…
Address reuse prevention across masternode rolesFiro masternode owner/payout/voting address separationPrivacy improvement by avoiding identical addresses for distinct transaction roles
This commit simply runs a cleanup tool on three SVG image files used for the rsFIRO cryptocurrency icon. It removes unnecessary formatting and metadata from the image files without changing their visual appearance. There is no security rel…
This commit is a routine merge from a staging branch that mostly tidies up build scripts and CI. The only user-visible change is that the Firo wallet now groups 'revoked' and 'banned' masternodes together under a single red 'banned' label,…
Dependency version bump for mobile_app_privacy (git ref changed).gitignore relaxation for cs_monero build artifacts and diff filesCI/build scripts now auto-generate API key template with additional Trocador placeholders
Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.
AI review queuedupdate deps and generated files to make the machines happyby Julian · 6988214e · Sep 15, 2026 · 26 filesMessage 50 · ThinInformational 17Details
Commit message · Julian
update deps and generated files to make the machines happy
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: unusually broad changesecond-pass: security-sensitive path
AI analysis · Informational 17/100
This commit updates several software building blocks (dependencies) and the automatically generated code that matches them. The main change is moving the Isar database library from a pre-release test version (3.3.0-dev.2) to a stable release (3.3.2), along with related tools like build_runner, analyzer, hive_ce, and mockito. It also removes a workaround that pinned an older analyzer version. There is no direct evidence in the commit of a security vulnerability being fixed; it reads as routine maintenance to keep the project compatible with newer tooling.
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 14/100
This commit updates the Stack Wallet app to use a newer version of its Tor privacy plugin and switches to prebuilt native assets downloaded from GitHub. There is no direct evidence in the commit of a security vulnerability, but changing how sensitive privacy components are fetched and built is a security-relevant configuration change.
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 17/100
This commit updates dependency versions for Xelis cryptocurrency support in Stack Wallet. It switches from the upstream xelis-flutter-ffi library to a fork maintained by Cypher Stack (the same organization as the wallet), and bumps flutter_rust_bridge from 2.12.0 to 2.13.0. The commit title says 'xelis native assets,' suggesting feature work rather than a security fix. There is no direct evidence in the diff or commit message of a vulnerability or security issue.
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 25/100
This commit simply updates the version of an external library called 'epiccash' used by the Stack Wallet app. It changes which exact code snapshot and prebuilt download the app will use, but the commit message gives no details about why the update was made or whether it fixes any security problem. Without seeing the actual changes inside the epiccash library, we cannot tell if this is a routine update or a security patch.
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 6/100
This commit simply updates the version of an internal backup library (stack_wallet_backup) used by the Stack Wallet app. The change points the app to a newer commit of that library and bumps its declared version from 0.0.1 to 0.1.0. There is no information in the commit itself about what changed in the backup library or whether any of those changes relate to security.
AI review queuedDoes what https://github.com/cypherstack/stack_wallet/pull/1442/ intended but without the negative side effectsby Julian · 04694bc5 · Sep 15, 2026 · 2 filesMessage 58 · ThinInformational 19Details
Commit message · Julian
Does what https://github.com/cypherstack/stack_wallet/pull/1442/ intended but without the negative side effects
58/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100
This commit adjusts two on-screen selection sheets in the Stack Wallet mobile app so they respect the phone's safe area (notch, gesture bar, etc.) and fixes some padding. It also removes a duplicate spacer in one sheet. There is no indication this fixes a security vulnerability; it appears to be a UI/UX follow-up to an earlier pull request.
AI review queuedclean up build scriptsby Julian · 5cfeb9b9 · Sep 15, 2026 · 22 filesMessage 28 · OpaqueInformational 15Details
Commit message · Julian
clean up build scripts
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
This commit is a routine cleanup of build scripts. It removes old shell scripts that manually compiled cryptocurrency plugin libraries and updates the build instructions to rely on Flutter's newer native-assets system. There is no indication of a security fix, vulnerability, or malicious change.
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 3/100
This commit simply updates a dependency reference for libmwc (a Mimblewimble Coin library) from one Git commit hash to another. There is no description of what changed in the library, no mention of security fixes, and no diff showing actual code changes in Stack Wallet itself. On its own, this commit does not demonstrate any security issue.
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 35/100
This commit updates the SQLite-related Dart/Flutter packages used by the Stack Wallet app. It bumps versions of the database library (drift), the underlying SQLite bindings (sqlite3), and related tooling. The change also removes the direct dependency on sqlite3_flutter_libs and adds sqlcipher_flutter_libs as a transitive dependency. The commit message gives no reason for the update, so we cannot tell from the diff alone whether it fixes a security bug, a compatibility issue, or something else. Updating dependencies is a routine maintenance action, but because this touches the encrypted local database layer of a cryptocurrency wallet, any underlying vulnerability could have high impact.
AI review queuedfix test importby Julian · 97cfbd96 · Sep 4, 2026 · 1 fileMessage 38 · OpaqueInformational 15Details
Commit message · Julian
fix test import
38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Informational 15/100
This is a one-line fix in a test file that updates an import path from an old package name ('paymint') to the current package name ('stackwallet'). It does not change any production code, user-facing behavior, or security logic. It simply allows a unit test to compile and run correctly.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 28/100
This commit updates the Stack Wallet app so it can correctly identify a newer kind of Firo cryptocurrency transaction (Spark V2 spends). Previously, the wallet only recognized one transaction type as a Spark spend; now it also recognizes type 11. This is a small correctness fix that helps the wallet display balances and transaction history accurately for Firo users. There is no direct evidence in the commit that this is a security vulnerability or that it was exploited.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 23/100
This commit updates the Stack Wallet app so it can correctly identify a newer kind of Firo cryptocurrency transaction (Spark V2 spends, type 11) in addition to the older Spark V1 spends (type 9). Before this change, the wallet only recognized type 9 as a spend, so a type-11 spend might have been misclassified or mishandled in the user's transaction history and balance calculations. There is no direct evidence in the commit that this misclassification could be exploited by an attacker to steal funds, but it is a correctness fix that could affect balance display and user trust.
AI review queuedfix send to spark name gray screen (nav error)by Julian · 04ee6496 · Sep 1, 2026 · 1 fileMessage 45 · ThinInformational 20Details
Commit message · Julian
fix send to spark name gray screen (nav error)
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 20/100
This commit fixes a UI crash (gray screen) that occurred when confirming a transaction sent to a Spark name. The crash happened because the code tried to read the first recipient address from an empty list. The fix safely checks whether a recipient exists before reading its address, falling back to Spark-specific recipient data when needed. There is no indication this is a security vulnerability; it is a robustness fix for a user-facing navigation/display error.
AI review queuedpartial revert of SIST in prep for h2 forkby Julian · 27d00b05 · Sep 1, 2026 · 9 filesMessage 45 · ThinLow 31Details
Commit message · Julian
partial revert of SIST in prep for h2 fork
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 31/100
This commit re-enables sending private Firo (Spark) funds to exchange addresses, which had been temporarily blocked. It also upgrades the wallet to support a newer Spark transaction format (Chaum V2) that allows multiple inputs, and it adds safety checks to prevent broadcasting insecure multi-input transactions using the older format. The change is described by the developer as a 'partial revert' ahead of a network fork, not as a security fix.
AI review queuedflutter_libsparkmobile dependency updateby Julian · d458a426 · Aug 31, 2026 · 6 filesMessage 35 · OpaqueInformational 23Details
Commit message · Julian
flutter_libsparkmobile dependency update
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
This commit updates the Stack Wallet app's integration with the Firo Spark privacy library. It adds support for a new Spark transaction version ("H2" / Chaum V2) that activates on mainnet at block 1,371,000, while keeping older behavior on test networks. The change is a dependency and protocol upgrade, not a clear security fix, but it touches sensitive code that creates private transactions and could affect whether coins are spendable after the network upgrade.
AI review queuedupdate windows mwebdby Julian · abbe566a · Aug 28, 2026 · 3 filesMessage 28 · OpaqueInformational 24Details
Commit message · Julian
update windows mwebd
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 24/100
This commit updates the Windows build pipeline for a small helper program called mwebd, which Stack Wallet uses for Litecoin MWEB privacy features. It bumps the mwebd version from v0.1.8 to v0.1.19, switches to a newer Go compiler, removes an old workaround that disabled part of the upstream plugin, and fixes a checksum comparison bug caused by Windows file paths. There is no direct evidence in the commit that this fixes a security vulnerability, but updating dependencies and removing workarounds can have security side effects.
AI review queuedci test image goby Julian · c2443f27 · Aug 28, 2026 · 1 fileMessage 38 · OpaqueInformational 21Details
Commit message · Julian
ci test image go
38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 21/100
This commit updates the project's Docker build image to install the Go programming language toolchain. It downloads Go 1.24.13 from the official Go website, verifies the file's integrity using a published SHA-256 checksum, extracts it, and adds it to the container's system PATH. The change appears to be a routine CI/build environment update rather than a security fix or vulnerability patch. There is no direct evidence in the commit that this addresses a security issue.
AI review queuedupdate mweb fee logicby Julian · d70c03d4 · Aug 28, 2026 · 4 filesMessage 28 · OpaqueLow 32Details
Commit message · Julian
update mweb fee logic
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 32/100
This commit rewrites how Stack Wallet calculates fees for MWEB (a privacy feature in Litecoin). It introduces a new helper module that reconciles the estimated fee against what the transaction actually pays, and loops up to 10 times to fix mismatches. The change appears to be a bug-fix/refactor of fee arithmetic rather than a new feature or an obvious security patch. There is no vendor statement that this fixes a security vulnerability.
AI review queuedfix frost input retryby Julian · c3cc7961 · Aug 28, 2026 · 1 fileMessage 28 · OpaqueLow 31Details
Commit message · Julian
fix frost input retry
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 31/100
This commit fixes a bug in the FROST Bitcoin wallet's coin-selection retry logic. Previously, when the first attempt to build a transaction didn't have enough funds, the code tried to add extra UTXOs but used a Set (which ignores duplicates and has no guaranteed order) and also accidentally included the current UTXO again instead of only the remaining ones. The fix switches to an ordered List and correctly picks/removes the next UTXO. This could have caused transaction building to fail, loop incorrectly, or select the wrong inputs.
AI review queuedupdate flutter_mwebdby Julian · f8f407a5 · Aug 28, 2026 · 2 filesMessage 18 · OpaqueLow 25Details
Commit message · Julian
update flutter_mwebd
18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Low 25/100
This commit updates a single Flutter package dependency called flutter_mwebd from version 0.0.1-pre.11 to 0.0.1-pre.12. The change is routine maintenance: it bumps the version number in the project's lock file and in a template used to generate package configuration. The commit message gives no details about what changed in the new version or whether it fixes any security issue. Without access to the upstream package's changelog, we cannot determine if this update addresses a vulnerability.
AI review queuedupdate min flutter versionby Julian · e631414c · Aug 28, 2026 · 4 filesMessage 35 · OpaqueInformational 15Details
Commit message · Julian
update min flutter version
35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit simply bumps the minimum Flutter version from 3.44.8 to 3.44.9 across build configuration files, a Dockerfile, and a dependency lock file. It is a routine tooling/maintenance update with no visible security relevance.
AI review queuedautoformat to satisfy ciby Julian · 25c93dac · Aug 27, 2026 · 4 filesMessage 28 · OpaqueInformational 15Details
Commit message · Julian
autoformat to satisfy ci
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100
This commit is purely a code-style reformat. It changes whitespace, line breaks, and indentation in four Dart files to satisfy the project's continuous integration (CI) formatter. No program logic, behavior, or security-sensitive code was altered.
AI review queuedmweb custom fee fixby Julian · 35d7595b · Aug 27, 2026 · 2 filesMessage 28 · OpaqueLow 46Details
Commit message · Julian
mweb custom fee fix
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: opaque commit messagesecond-pass: security-sensitive path
AI analysis · Low 46/100
This commit fixes how custom transaction fees are calculated for MWEB (a privacy feature in Litecoin) in Stack Wallet. Previously, when a user set a custom fee in 'satoshis per virtual byte' (sats/vByte), the app sometimes used the wrong fee rate or mixed up per-byte and per-kilobyte units. The fix makes the code consistently convert sats/vByte to a per-kilobyte rate before sending it to the MWEB library. A new test confirms that a custom sats/vByte setting now overrides the default per-kilobyte rate. This is a correctness bug that could cause users to overpay or underpay fees, and underpayment could potentially delay or stall transactions.
AI review queuedreplace error-prone refresh mutex/lock with wallet state coordination for xelis to start out withby Julian · c38227f0 · Aug 27, 2026 · 7 filesMessage 50 · ThinLow 35Details
Commit message · Julian
replace error-prone refresh mutex/lock with wallet state coordination for xelis to start out with
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 35/100
This commit rewrites how Stack Wallet's Xelis wallet handles background synchronization. It replaces a single refresh lock with a new 'operation coordinator' and an 'event batcher' that groups rapid blockchain notifications before acting on them. The stated goal is to fix race conditions and inconsistent state caused by the old mutex-based design. The change is defensive refactoring rather than a patch for a known exploit, but concurrency bugs in wallet code can historically lead to incorrect balances, missed transactions, or crashes.
AI review queuedclean up replaced eth transactionsby Julian · 6b853a9a · Aug 27, 2026 · 3 filesMessage 45 · ThinLow 34Details
Commit message · Julian
clean up replaced eth transactions
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 34/100
This commit adds a cleanup routine for Ethereum transactions that were replaced by another transaction with the same nonce. In Ethereum, if you send a second transaction with the same sequence number (nonce) but a higher fee, the first one can be dropped by the network. Stack Wallet previously kept these dropped transactions visible as 'pending' forever. The new code detects them by checking the blockchain and removes them from the local transaction list. It is a bug-fix/quality improvement rather than an active remote hack vulnerability.