What changed, and why it matters
This is a routine release-candidate commit for Cake Wallet/Monero.com version 6.5.0. It bumps the Monero core library version, adds a new Robinhood Chain wallet, enables price charts and Bitcoin accounts, reverts a database table that was intended to store deprecated wallet seeds, disables the Exolix swap provider, and fixes an Alchemy API key fallback. None of these changes are explicitly described by the vendor as security fixes, and there is no direct evidence in the diff of an exploitable vulnerability. The most notable security-adjacent change is the removal of the DeprecatedWalletSeeds table, which suggests a deliberate reduction of seed-storage surface area, but the commit does not frame it as a security patch.
Treat this as a normal release-candidate review. Verify the monero_c commit 33671871de3d51696b66ffb3bd94f744e26974f6 for any upstream security fixes, confirm the DeprecatedWalletSeeds table removal does not break seed recovery or migration for existing users, and ensure the empty Alchemy API key fallback is intentional and documented. No emergency action is indicated by the diff alone.
Security signals we found
Database schema reverts creation of DeprecatedWalletSeeds table, reducing persistent seed storage surface
Alchemy API key fallback hardcoded to empty string, preventing unintended use of a bundled/secret key for Alchemy RPC endpoints
monero_c dependency updated to a newer commit, which may include upstream Monero fixes, but the specific changes are not shown in this diff
Exolix exchange provider disabled via feature flag
Evidence from the diff
The commit is a release candidate merge (PR #3674) containing version bumps and feature work. Key changes: (1) monero_c updated from cd4fe366 to 33671871 across cw_monero, cw_wownero, cw_zano, pubspec_overrides.yaml, and scripts/prepare_moneroc.sh; (2) app version bumped to 6.5.0 on Android/iOS/Linux/macOS/Windows; (3) cw_core/lib/db/sqlite.dart reverts db version from 15 to 14 and removes _createDeprecatedWalletSeedTable, so the DeprecatedWalletSeeds table is no longer created or migrated to; (4) cw_evm/lib/clients/evm_chain_client.dart changes Alchemy API key fallback from secrets.alchemyApiKey to an empty string, which means Alchemy nodes without a configured key will fail to connect rather than use a built-in key; (5) lib/exchange/provider/swaptrade_exchange_provider.dart expands supported network mappings; (6) lib/utils/feature_flag.dart disables Exolix; (7) UI/changelog assets updated for Monero.com branding. No CVE, advisory, or vendor security disclosure is present in the supplied materials.
Changed components
cw_core SQLite database migration (DeprecatedWalletSeeds table)cw_evm EVM chain client Alchemy node handlingcw_monero/cw_wownero/cw_zano monero_c dependencylib/exchange/provider/swaptrade_exchange_provider.dartlib/utils/feature_flag.dart (Exolix)Cake Wallet/Monero.com release packaging and versioningInspect captured patch +111 / −62
### assets/images/monerocom_logo.svg
@@ -0,0 +1,25 @@
+<svg width="650" height="650" viewBox="187 187 650 650" fill="none" xmlns="http://www.w3.org/2000/svg">
+<g clip-path="url(#clip0_3163_103)">
+<path d="M760.715 378.625C802.842 378.625 837.031 412.781 837.031 454.937V760.812C837.031 802.906 802.905 837.031 760.809 837.031H263.222C221.127 837.031 187 802.906 187 760.812V454.937C187 412.812 221.158 378.625 263.316 378.625H265.066C283.005 379.062 300.255 385.75 313.756 397.656L457.513 524.25C473.076 537.969 492.546 544.812 512.016 544.812C531.485 544.812 550.924 537.938 566.518 524.25L710.275 397.656C724.213 385.375 742.12 378.625 760.715 378.625Z" fill="url(#paint0_linear_3163_103)"/>
+<path d="M760.809 187C802.905 187 837.031 221.125 837.031 263.219V278.375C817.155 259.531 790.31 247.938 760.809 247.938H263.222C233.721 247.938 206.876 259.5 187 278.344V263.219C187 221.125 221.127 187 263.222 187H760.809Z" fill="url(#paint1_linear_3163_103)"/>
+<path d="M760.809 282.593H263.222C221.127 282.593 187.031 316.718 187.031 358.812V374.405C206.907 355.53 233.784 343.937 263.316 343.937C289.505 343.937 314.756 353.155 334.757 369.968L481.264 498.937C489.858 506.187 500.765 510.155 512.016 510.155C523.266 510.155 534.173 506.187 542.767 498.937L689.274 369.968C709.275 353.155 734.526 343.937 760.715 343.937C790.248 343.937 817.124 355.53 837 374.405V358.812C837 316.718 802.905 282.593 760.809 282.593Z" fill="url(#paint2_linear_3163_103)"/>
+</g>
+<defs>
+<linearGradient id="paint0_linear_3163_103" x1="512.016" y1="378.625" x2="512.016" y2="837.031" gradientUnits="userSpaceOnUse">
+<stop offset="0.00646752" stop-color="#403649"/>
+<stop offset="1" stop-color="#312938"/>
+</linearGradient>
+<linearGradient id="paint1_linear_3163_103" x1="496.415" y1="186.913" x2="487.404" y2="266.57" gradientUnits="userSpaceOnUse">
+<stop stop-color="#61C5FF"/>
+<stop offset="0.924264" stop-color="#2A92FA"/>
+</linearGradient>
+<linearGradient id="paint2_linear_3163_103" x1="512.016" y1="282.593" x2="512.016" y2="510.155" gradientUnits="userSpaceOnUse">
+<stop stop-color="#FF7D38"/>
+<stop offset="0.612828" stop-color="#FE6412"/>
+<stop offset="1" stop-color="#F25400"/>
+</linearGradient>
+<clipPath id="clip0_3163_103">
+<rect width="650" height="650" fill="white" transform="translate(187 187)"/>
+</clipPath>
+</defs>
+</svg>
### assets/new-ui/changelog/text/changelog_en.json
@@ -1,10 +1,18 @@
[
{
- "title": "Monero improvements",
- "description": "Sync progress keeps moving while your wallet warms up, so you always know where it stands"
+ "title": "Robinhood Chain",
+ "description": "Create Robinhood Chain wallets to send, receive and swap, with USDG and more tokens built in"
},
{
- "title": "Bug fixes",
- "description": "Contact syncing, node selection, Cake Pay sign-in and more, all squashed"
+ "title": "Price Charts",
+ "description": "A new Charts tab to keep an eye on the prices of your assets"
+ },
+ {
+ "title": "Bitcoin Accounts & Faster Sync",
+ "description": "Split your Bitcoin wallet into multiple accounts, and get up to date faster while history loads in the background"
+ },
+ {
+ "title": "Bug fixes & improvements",
+ "description": "Lightning amounts in sats, more Tor nodes, Monero core update, smoother Bitcoin wallets and more"
}
-]
+]
\ No newline at end of file
### assets/new-ui/changelog/text/monerocom_changelog_en.json
@@ -0,0 +1,14 @@
+[
+ {
+ "title": "Safer sends",
+ "description": "Payments that would be split into several transactions are now stopped before sending"
+ },
+ {
+ "title": "Price Charts",
+ "description": "A new Charts tab to keep an eye on prices"
+ },
+ {
+ "title": "Bug fixes & improvements",
+ "description": "New Cake Tor node, restore height filled in on Rescan, and more"
+ }
+]
### cw_core/lib/db/sqlite.dart
@@ -66,7 +66,7 @@ Future<void> _initDb({String? pathOverride}) async {
await db?.close();
db = await openDatabase(
dbFile.path,
- version: 15,
+ version: 14,
onUpgrade: (db, oldVersion, newVersion) async {
printV("migrating: $oldVersion, $newVersion");
if (oldVersion <= 1) {
@@ -193,9 +193,6 @@ CREATE TABLE IF NOT EXISTS BalanceCardStyleSettings (
await _migrateBitcoinCardStylesForAccounts(db);
}
- if(oldVersion <= 14) {
- await _createDeprecatedWalletSeedTable(db);
- }
},
onCreate: (Database db, int version) async {
await db.execute('''
@@ -302,8 +299,6 @@ CREATE TABLE BalanceCardStyleSettings (
await _createTronTokenTable(db);
await _createImportedNFTTable(db);
await _createWalletInfoAccountTable(db);
- await _createDeprecatedWalletSeedTable(db);
-
},
);
}
@@ -594,15 +589,3 @@ isDefault BOOLEAN DEFAULT FALSE
);
""");
}
-
-
-Future<void> _createDeprecatedWalletSeedTable(Database db) async {
- await db.execute("""
-CREATE TABLE DeprecatedWalletSeeds (
-walletInfoId INTEGER PRIMARY KEY,
-seed TEXT NOT NULL,
-passphrase TEXT NOT NULL,
-FOREIGN KEY (walletInfoId) REFERENCES WalletInfo(walletInfoId)
-);
-""");
-}
### cw_evm/lib/clients/evm_chain_client.dart
@@ -192,7 +192,7 @@ class EVMChainClient {
} else if (nodeHost.endsWith(".g.alchemy.com") &&
(pathSegments.isEmpty || (pathSegments.length == 1 && pathSegments.first == "v2"))) {
isModifiedNodeUri = true;
- String alchemyApiKey = secrets.alchemyApiKey;
+ String alchemyApiKey = "";
if (alchemyApiKey.isEmpty) {
printV("Alchemy API key is empty, cannot connect to ${node.uriRaw}");
### cw_monero/pubspec.yaml
@@ -26,7 +26,7 @@ dependencies:
monero:
git:
url: https://github.com/mrcyjanek/monero_c.git
- ref: cd4fe366cc8d3c188c91de279f43b29c0e044b15
+ ref: 33671871de3d51696b66ffb3bd94f744e26974f6
path: impls/monero.dart
mutex: ^3.1.0
ledger_flutter_plus: ^1.4.1
### cw_wownero/pubspec.yaml
@@ -24,7 +24,7 @@ dependencies:
monero:
git:
url: https://github.com/mrcyjanek/monero_c.git
- ref: cd4fe366cc8d3c188c91de279f43b29c0e044b15
+ ref: 33671871de3d51696b66ffb3bd94f744e26974f6
path: impls/monero.dart
mutex: ^3.1.0
### cw_zano/pubspec.yaml
@@ -27,7 +27,7 @@ dependencies:
monero:
git:
url: https://github.com/mrcyjanek/monero_c.git
- ref: cd4fe366cc8d3c188c91de279f43b29c0e044b15
+ ref: 33671871de3d51696b66ffb3bd94f744e26974f6
path: impls/monero.dart
dev_dependencies:
flutter_test:
### lib/bitcoin/cw_bitcoin.dart
@@ -924,7 +924,7 @@ class CWBitcoin extends Bitcoin {
}
@override
- ElectrumBalance balanceForAccount(Object wallet, int accountIndex) {
+ Balance balanceForAccount(Object wallet, int accountIndex) {
final bitcoinWallet = wallet as ElectrumWallet;
return bitcoinWallet.balanceForAccount(accountIndex);
}
### lib/entities/default_settings_migration.dart
@@ -2,10 +2,7 @@ import 'dart:convert';
import 'dart:io' show Directory, File, Platform;
import 'package:cake_wallet/bitcoin/bitcoin.dart';
-import "package:cake_wallet/core/key_service.dart";
import 'package:cake_wallet/core/secure_storage.dart';
-import "package:cake_wallet/decred/decred.dart";
-import "package:cake_wallet/di.dart";
import 'package:cake_wallet/entities/balance_display_mode.dart';
import 'package:cake_wallet/entities/contact.dart';
import 'package:cake_wallet/entities/exchange_api_mode.dart';
@@ -17,9 +14,6 @@ import 'package:cake_wallet/entities/preferences_key.dart';
import 'package:cake_wallet/entities/secret_store_key.dart';
import 'package:cake_wallet/monero/monero.dart';
import 'package:cake_wallet/new-ui/model/charts/charts_asset.dart';
-import "package:cake_wallet/store/settings_store.dart";
-import "package:cake_wallet/zano/zano.dart";
-import "package:cw_core/cake_hive.dart";
import 'package:cake_wallet/wownero/wownero.dart';
import 'package:collection/collection.dart';
import 'package:cw_core/crypto_currency.dart';
@@ -29,10 +23,8 @@ import 'package:cw_core/node_list.dart';
import 'package:cw_core/pathForWallet.dart';
import 'package:cw_core/root_dir.dart';
import 'package:cw_core/spl_token.dart';
-import "package:cw_core/unspent_coins_info.dart";
import 'package:cw_core/utils/print_verbose.dart';
import 'package:cw_core/wallet_info.dart';
-import "package:cw_core/wallet_service.dart";
import 'package:cw_core/wallet_type.dart';
import 'package:encrypt/encrypt.dart' as encrypt;
import 'package:hive/hive.dart';
### lib/exchange/provider/swaptrade_exchange_provider.dart
@@ -415,13 +415,26 @@ class SwapTradeExchangeProvider extends ExchangeProvider {
bool _isPairSupported(CryptoCurrency from, CryptoCurrency to) =>
_networkFor(from) != null && _networkFor(to) != null;
- String? _networkFor(CryptoCurrency currency) =>
- switch ((currency.title.toUpperCase(), currency.tag?.toUpperCase())) {
- ("BNB", "BSC") => "BNB_BSC",
- ("USDT", "ETH") => "USDT_ERC20",
- ("USDT", "TRX") => "TRX_USDT_S2UZ",
- ("USDT", "BSC") => "USDT_BSC",
- (final title, null) => title,
- _ => null,
- };
+ String? _networkFor(CryptoCurrency currency) {
+ final network = switch (currency) {
+ CryptoCurrency.eth => 'ETH',
+ CryptoCurrency.bnb => 'BNB_BSC',
+ CryptoCurrency.baseEth => 'BASE',
+ CryptoCurrency.robEth => 'ROB',
+ CryptoCurrency.arb => 'ARB',
+ CryptoCurrency.arbEth => 'ARB',
+ CryptoCurrency.usdterc20 => 'USDT_ERC20',
+ CryptoCurrency.usdttrc20 => 'TRX_USDT_S2UZ',
+ CryptoCurrency.usdtbsc => 'USDT_BSC',
+ CryptoCurrency.sol => 'SOL',
+ CryptoCurrency.btc => 'BTC',
+ CryptoCurrency.xmr => 'XMR',
+ CryptoCurrency.ltc => 'LTC',
+ CryptoCurrency.ada => 'ADA',
+ CryptoCurrency.bch => 'BCH',
+ CryptoCurrency.zec => 'ZEC',
+ _ => currency.tag?.toUpperCase(),
+ };
+ return network;
+ }
}
### lib/new-ui/widgets/changelog_modal.dart
@@ -5,6 +5,7 @@ import 'package:cake_wallet/generated/i18n.dart';
import 'package:cake_wallet/new-ui/widgets/new_primary_button.dart';
import 'package:cake_wallet/new-ui/widgets/receive_page/receive_top_bar.dart';
import 'package:cake_wallet/src/widgets/cake_image_widget.dart';
+import 'package:cake_wallet/wallet_type_utils.dart';
import 'package:flutter/material.dart';
import 'package:flutter/services.dart';
import 'package:flutter_svg/flutter_svg.dart';
@@ -40,15 +41,16 @@ class _ChangelogModalState extends State<ChangelogModal> {
}
void loadChangelog() async {
+ final fileName = isMoneroOnly ? "monerocom_changelog" : "changelog";
String lang = WidgetsBinding.instance.platformDispatcher.locale.languageCode;
if (lang == "und" ||
lang.isEmpty ||
- !(await File("$changelogTextLocation/changelog_$lang.json").exists())) {
+ !(await File("$changelogTextLocation/${fileName}_$lang.json").exists())) {
lang = "en";
}
final List<dynamic> changelog =
- jsonDecode(await rootBundle.loadString("$changelogTextLocation/changelog_$lang.json"))
+ jsonDecode(await rootBundle.loadString("$changelogTextLocation/${fileName}_$lang.json"))
as List<dynamic>;
for (final item in changelog) {
@@ -146,7 +148,9 @@ class VersionNumberHeader extends StatelessWidget {
mainAxisSize: MainAxisSize.min,
children: [
CakeImageWidget(
- imageUrl: "assets/images/cake_logo_dark.svg",
+ imageUrl: isMoneroOnly
+ ? "assets/images/monerocom_logo.svg"
+ : "assets/images/cake_logo_dark.svg",
height: 32,
width: 32,
colorFilter:
### lib/utils/feature_flag.dart
@@ -6,7 +6,7 @@ class FeatureFlag {
static const bool isCakePayEnabled = false;
static const bool isCakePayPurchaseSimulationEnabled = true;
static const bool isCakePayRedemptionFlowEnabled = false;
- static const bool isExolixEnabled = true;
+ static const bool isExolixEnabled = false;
static const bool isBackgroundSyncEnabled = true;
static bool get isInAppTorEnabled => CakeTor.instance is! CakeTorDisabled;
static const int verificationWordsCount = kDebugMode || kProfileMode ? 0 : 2;
### pubspec_overrides.yaml
@@ -960,7 +960,7 @@ dependency_overrides:
monero:
git:
url: https://github.com/mrcyjanek/monero_c.git
- ref: cd4fe366cc8d3c188c91de279f43b29c0e044b15
+ ref: 33671871de3d51696b66ffb3bd94f744e26974f6
path: ./impls/monero.dart
msgpack_dart:
git:
### scripts/android/app_env.sh
@@ -14,14 +14,14 @@ TYPES=($MONERO_COM $CAKEWALLET)
APP_ANDROID_TYPE=$1
MONERO_COM_NAME="Monero.com"
-MONERO_COM_VERSION="6.4.6"
+MONERO_COM_VERSION="6.5.0"
MONERO_COM_BUILD_NUMBER=4170
MONERO_COM_BUNDLE_ID="com.monero.app"
MONERO_COM_PACKAGE="com.monero.app"
MONERO_COM_SCHEME="monero.com"
CAKEWALLET_NAME="Cake Wallet"
-CAKEWALLET_VERSION="6.4.6"
+CAKEWALLET_VERSION="6.5.0"
CAKEWALLET_BUILD_NUMBER=4426
CAKEWALLET_BUNDLE_ID="com.cakewallet.cake_wallet"
CAKEWALLET_PACKAGE="com.cakewallet.cake_wallet"
### scripts/android/docker/Dockerfile.monero
@@ -1,10 +1,19 @@
ARG BASE_IMAGE
FROM --platform=linux/amd64 ${BASE_IMAGE} AS build
-RUN mkdir -p /w/scripts/android
COPY scripts/functions.sh /w/scripts/functions.sh
COPY scripts/prepare_moneroc.sh /w/scripts/prepare_moneroc.sh
COPY scripts/android/build_monero_all.sh /w/scripts/android/build_monero_all.sh
+
+ARG UID=10001
+ARG GID=10001
+ARG USER=builder
+RUN groupadd -g "$GID" "$USER" && \
+ useradd -m -u "$UID" -g "$GID" -s /bin/bash "$USER"
+
+RUN sudo chown $UID:$GID -R /w /root
+USER builder
+
ARG COIN
ARG TARGET
ENV COIN=$COIN
### scripts/ios/app_env.sh
@@ -12,12 +12,12 @@ TYPES=($MONERO_COM $CAKEWALLET)
APP_IOS_TYPE=$1
MONERO_COM_NAME="Monero.com"
-MONERO_COM_VERSION="6.4.6"
+MONERO_COM_VERSION="6.5.0"
MONERO_COM_BUILD_NUMBER=177
MONERO_COM_BUNDLE_ID="com.cakewallet.monero"
CAKEWALLET_NAME="Cake Wallet"
-CAKEWALLET_VERSION="6.4.6"
+CAKEWALLET_VERSION="6.5.0"
CAKEWALLET_BUILD_NUMBER=446
CAKEWALLET_BUNDLE_ID="com.fotolockr.cakewallet"
### scripts/linux/app_env.sh
@@ -14,7 +14,7 @@ if [ -n "$1" ]; then
fi
CAKEWALLET_NAME="Cake Wallet"
-CAKEWALLET_VERSION="6.4.6"
+CAKEWALLET_VERSION="6.5.0"
CAKEWALLET_BUILD_NUMBER=83
if ! [[ " ${TYPES[*]} " =~ " ${APP_LINUX_TYPE} " ]]; then
### scripts/macos/app_env.sh
@@ -16,12 +16,12 @@ if [ -n "$1" ]; then
fi
MONERO_COM_NAME="Monero.com"
-MONERO_COM_VERSION="6.4.6"
+MONERO_COM_VERSION="6.5.0"
MONERO_COM_BUILD_NUMBER=86
MONERO_COM_BUNDLE_ID="com.cakewallet.monero"
CAKEWALLET_NAME="Cake Wallet"
-CAKEWALLET_VERSION="6.4.6"
+CAKEWALLET_VERSION="6.5.0"
CAKEWALLET_BUILD_NUMBER=154
CAKEWALLET_BUNDLE_ID="com.fotolockr.cakewallet"
### scripts/prepare_moneroc.sh
@@ -16,7 +16,7 @@ fi
# NOTE: Make sure to update monero_c prebuilds link in workflow files
# https://github.com/MrCyjaneK/monero_c/releases/download/v0.18.4.6-RC2/release-bundle.zip
git fetch -a
-git checkout cd4fe366cc8d3c188c91de279f43b29c0e044b15
+git checkout 33671871de3d51696b66ffb3bd94f744e26974f6
git reset --hard
git submodule update --init --force --recursive
### scripts/windows/build_exe_installer.iss
@@ -1,5 +1,5 @@
#define MyAppName "Cake Wallet"
-#define MyAppVersion "6.4.1"
+#define MyAppVersion "6.5.0"
#define MyAppPublisher "Cake Labs LLC"
#define MyAppURL "https://cakewallet.com/"
#define MyAppExeName "CakeWallet.exe"
### tool/configure.dart
@@ -106,7 +106,6 @@ import 'dart:typed_data';
import 'package:bitcoin_base/bitcoin_base.dart';
import 'package:cake_wallet/view_model/hardware_wallet/ledger_view_model.dart';
import 'package:cake_wallet/view_model/send/output.dart';
-import 'package:cw_bitcoin/electrum_balance.dart';
import "package:cw_core/account.dart";
import 'package:cw_core/amount/money.dart';
import 'package:cw_core/hardware/hardware_account_data.dart';
@@ -124,6 +123,7 @@ import 'package:cw_core/unspent_transaction_output.dart';
import 'package:cw_core/wallet_base.dart';
import 'package:cw_core/wallet_credentials.dart';
import 'package:cw_core/wallet_info.dart';
+import "package:cw_core/balance.dart";
import 'package:cw_core/wallet_service.dart';
import 'package:cw_core/wallet_type.dart';
import 'package:cw_core/utils/print_verbose.dart';
@@ -164,6 +164,7 @@ import 'package:cw_bitcoin/hardware/litecoin_ledger_service.dart';
import 'package:cw_bitcoin/hardware/bitbox_service.dart';
import 'package:cw_bitcoin/hardware/litecoin_trezor_service.dart';
import 'package:cw_bitcoin/hardware/trezor_service.dart';
+import 'package:cw_bitcoin/electrum_balance.dart';
import 'package:mobx/mobx.dart';
import "package:breez_sdk_spark_flutter/src/rust/errors.dart";
""";
@@ -307,7 +308,7 @@ abstract class Bitcoin {
Future<String?> getLightningInvoice(Object wallet, BigInt amount);
String? getBreezSdkError(Object exception);
Future<Account> getCurrentAccount(Object wallet);
- ElectrumBalance balanceForAccount(Object wallet, int accountIndex);
+ Balance balanceForAccount(Object wallet, int accountIndex);
Map<int, Object> accountBalancesSnapshot(Object wallet);
Future<void> setCurrentAccount(Object wallet, int accountIndex);
List<TransactionInfo> getCurrentAccountBitcoinTransactions(Object wallet);Why this scored 24/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.