AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 45 Monero

v6.3.0 Release Candidate (#3414)

Public commit record

What the developer wrote

Authored by Omar Hatem

76/100 · Adequate
v6.3.0 Release Candidate (#3414)

* v6.3.0 Release Candidate
- the new transaction history
- Radar in Apps screen
- Zcash update
- Flutter update
- Parts of the Refactor
should improve how amounts are handled in the app and fix any issue with amounts
improve handling sending to aliases

- Improvements for Cake Pay mobile
- Bug fixes

* don't use memo for note/message values

* save message in QR locally in the notes field

* Make stealth addresses generated from silent payment, not reliant on output index (#3420)

* - fix swaps showing only on primary account
- switch tron default node
- privacy fixes

* - enlarge destination tag and make it copiable
- migrate users on hashvault
- minor fix
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This is a routine version-bump release candidate for Cake Wallet/Monero.com v6.3.0. The visible code changes include several privacy-related tweaks: Bitcoin transaction output ordering is now shuffled instead of fixed, a Tor/onion exchange provider now uses HTTPS instead of HTTP, default Tron and Monero nodes are switched/migrated away from TronGrid and HashVault, and a hardware-wallet passphrase field disables autocorrect. There are also UI fixes for destination tags and QR-code payment notes. The commit message itself mentions 'privacy fixes' but does not describe a specific vulnerability or disclose a security incident.

Recommended action

Treat this as a normal release-candidate review. The privacy fixes are worth highlighting in release notes, but there is no evidence of an exploitable vulnerability requiring an emergency advisory. Verify that the new default nodes (NOWNodes for Tron, Cake node for Monero) are trustworthy and that the HTTPS onion endpoint change does not break Tor-only users. Confirm the output-shuffle change does not interfere with hardware-wallet signing or transaction broadcast. Consider whether the silent-payment refactor needs additional regression tests for stealth-address display.

Security signals we found

01

Bitcoin output ordering changed from none to shuffle (privacy hardening)

02

Trocador exchange onion endpoint switched from HTTP to HTTPS (transport/privacy hardening)

03

Default Tron node migrated from TronGrid to NOWNodes; default Monero node migrated from HashVault to Cake node (trust-model change)

04

Hardware wallet passphrase input disables autocorrect/suggestions (input privacy hardening)

05

Silent payment stealth address derivation decoupled from output index (correctness/privacy)

06

Monero address iteration async bug fixed (forEach-async replaced with for loop)

07

Commit message mentions 'privacy fixes' without further detail

Risk score

Why this scored 45/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 6/15
Affected reach 10/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.