AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 34 Monero

v5.8.0 Release Candidate (#2815)

Public commit record

What the developer wrote

Authored by Omar Hatem

76/100 · Adequate
v5.8.0 Release Candidate (#2815)

* v5.8.0 Release Candidate

Add Arbitrum
EVM chains enhancements
Integrate Jupiter swaps for Solana
Bug fixes

* Exclude transparent address from unified address

* fix hiddenAddresses getting discarded [skip ci]

* pump zcash order [skip ci]

* CW-1372: zcash improvements and missing features second iteration (#2818)

* fix: remove hidden addresses from usable address list
fix: getBlockHeightByTime fallback to offline calculation
fix: remove NewWalletTypeViewModel to fix groups working without restart

* fix: rotate T addresses in exchanges

* fix: builds without --zcash config (linux)

* fix: update address after trade

* Add zcash.me

* printv [skip ci]

---------

Co-authored-by: cyan <cyjan@mrcyjanek.net>
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This is a routine version-bump release candidate (v5.8.0) for the Cake Wallet family of apps. Most changes are feature work: adding Arbitrum, improving EVM chains, integrating Jupiter swaps for Solana, and fixing several Zcash wallet bugs. The Zcash fixes include making sure hidden/used transparent addresses are not reused for exchanges, falling back to an offline formula if the server cannot provide a block height from a date, and removing a stale view-model that was breaking wallet-group functionality. There is no vendor statement that this commit fixes a security vulnerability, and the changes read like ordinary bug fixes rather than a security patch.

Recommended action

Treat this as a normal release-candidate review. Validate the Zcash address-rotation logic with hidden/used address sets, confirm the offline block-height interpolation matches Zcash consensus parameters, and review the zcash.me resolver for SSRF/redirect and regex correctness. No emergency security response is indicated by the supplied materials.

Security signals we found

01

Zcash transparent address rotation now filters out hidden/used addresses before selecting an exchange/receive address

02

Zcash block-height-by-date gains an offline fallback, reducing reliance on an external API

03

zcash.me address resolver added, which fetches a clearnet profile page and parses an address with a regex

04

Removal of NewWalletTypeViewModel changes DI timing and may affect wallet-group behavior

05

No vendor-authored security disclosure or CVE reference present in commit or supplied materials

Risk score

Why this scored 34/100

Our methodology →
Potential impact 8/30
Exploitability 6/25
Stealth signal 5/15
Affected reach 7/15
Confidence 5/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.