Releases: EkuboProtocol/wallet
Release list
v1.8.4
Warning
Windows and Linux key-storage warning: The current builds use per-user credential services that do not isolate raw account keys or the database key to Ekubo Wallet. Same-user malware, including a prompt-injected local agent that can execute programs, can extract those keys and bypass wallet policy and review. Read the security model before installing.
Changes in 1.8.4:
- Serve shallow, non-recursive schemas for every recursive MCP tool type, so clients that reject recursive schemas (Muse Spark among them) can list tools and call them. The 1.8.3 fix covered only the
wallet_propose_policyinput; this completes it for the decode-plan inputs ofwallet_batch_eth_callandwallet_decode_abi_resultand the policy document inwallet_get_policyoutput. Validation is unchanged: deserialization into the real types remains the admission check, and the complete recursive schemas stay onwallet://schemas/policy.
v1.8.3
Warning
Windows and Linux key-storage warning: The current builds use per-user credential services that do not isolate raw account keys or the database key to Ekubo Wallet. Same-user malware, including a prompt-injected local agent that can execute programs, can extract those keys and bypass wallet policy and review. Read the security model before installing.
Changes in 1.8.3:
- Serve a shallow, non-recursive policy schema in the
wallet_propose_policytool input so MCP clients that cannot decode recursive $ref schemas (Muse Spark among them) can list tools and propose policies. The complete recursive rule and predicate schema remains atwallet://schemas/policy, and policy validation is unchanged.
v1.8.2
Warning
Windows and Linux key-storage warning: The current builds use per-user credential services that do not isolate raw account keys or the database key to Ekubo Wallet. Same-user malware, including a prompt-injected local agent that can execute programs, can extract those keys and bypass wallet policy and review. Read the security model before installing.
Changes in 1.8.2:
- Recover wallet access after the Linux credential service restarts, without restarting the wallet.
- Keep MCP startup and reconnection responsive, report connection failures clearly, and avoid replaying interrupted requests.
- Preserve transaction summaries for calldata-only requests and wrap long WalletConnect messages.
v1.8.1
Warning
Windows and Linux key-storage warning: The current builds use per-user credential services that do not isolate raw account keys or the database key to Ekubo Wallet. Same-user malware, including a prompt-injected local agent that can execute programs, can extract those keys and bypass wallet policy and review. Read the security model before installing.
Improvements
- Transaction cards now use the AI summary as their primary headline. Function-signature candidates, trusted token metadata, and recent simulation results help explain intent with concise summaries such as “Swap 1 ETH for 2400 USDG.”
- Better handling of deposits, wrapping, approvals, and ambiguous calls. Summaries preserve call order and stay within 100 characters; inference remains local.
- Clearer WalletConnect connection and waiting states, visible request-processing feedback, and more reliable activity opening from notifications.
- Modern MCP discovery and stateless bridge requests improve client compatibility.
- Explicit macOS disk-image capacity accommodates signed app bundles.
Transaction summaries remain advisory. Full transaction details and signing policy checks remain available in the review.
v1.8.0
Ekubo Wallet 1.8.0 adds fast, readable transaction summaries across complete execution plans. Exact transaction data and the existing approval checks remain available for review.
- Summaries cover multi-call plans, with an ABI-signature fallback when no clear-signing descriptor is available.
- Choose which hosted Ekubo MCP servers to configure for agents, with clearer sync results.
- Activity history distinguishes hidden testnet records from an empty list and explains what clearing history retains or deletes.
- Reviewed dependency updates and browser GPU compatibility checks.
Warning
Windows and Linux key-storage warning: The current builds use per-user credential services that do not isolate raw account keys or the database key to Ekubo Wallet. Same-user malware, including a prompt-injected local agent that can execute programs, can extract those keys and bypass wallet policy and review. Read the security model before installing.
v1.7.1
A patch release with one fix that matters: a request the wallet could not
simulate used to be a question nobody could answer. Each item links to its
commit, where the full reasoning lives.
-
A request stays reviewable when its chain cannot simulate.
28db8ce
A queued request was only ever shown to you once a fresh simulation had
produced a prepared transaction envelope. Where the endpoint cannot simulate
at all, that never happened — and the row was not merely un-approvable, it
could not be rejected either, because review failed before the screen was
reached. The only exit was for the agent to withdraw it, and anyone funded on
such a chain had no in-app route to move their money. The block was never the
transaction: every field of the envelope except one already comes from the
RPC, and the single missing input is the gas limit. That is all this restores,
frometh_estimateGas, bounded by the block gas limit read from the same
endpoint in the same breath and passed through the same ceiling, multiplier,
and intrinsic floor as before. Only a direct call is sized this way — a batch
would be estimated against a delegation the account does not hold yet. Nothing
is loosened: a request rescued this way can only ever reach a human and can
never sign on its own, and what you are shown still carries the simulation
findings, so you decide knowing the simulation did not run. A plan that
genuinely reverts still fails, and still reports its own failure rather than
an estimation error. -
Monad is no longer a default network.
c5d70c8
Its RPC does not implementeth_simulateV1without transaction validation —
the form the wallet sends, and the form the specification defaults to — so
nothing on Monad could be simulated, and therefore nothing could be signed.
Shipping it as a default offered a network the wallet could not transact on.
It stays in the registry under the same name and alias and can still be
configured for reads, and it becomes a default again as soon as an endpoint
answers the method.
Warning
Windows and Linux key-storage warning: The current builds use per-user credential services that do not isolate raw account keys or the database key to Ekubo Wallet. Same-user malware, including a prompt-injected local agent that can execute programs, can extract those keys and bypass wallet policy and review. Read the security model before installing.
v1.7.0
This release is about agents cleaning up after themselves, and about numbers on
the approval screen meaning what they look like they mean. Each item links to
its commit, where the full reasoning lives.
-
An agent can take back anything it asked you for.
a2cea0b
Nothing an agent puts in front of you expires on its own, so a request it
gave up on used to sit in your wallet staying approvable — a swap at a price
from an hour ago, a login for a session you had already closed, a proposal to
widen what signs automatically for work that had long finished. Agents can
now withdraw a transaction, a message or typed-data signature, or a policy,
network, or token proposal. Withdrawing is not the same as your rejecting
something: it records that the agent stopped asking, and the review simply
disappears from your wallet. It can only ever remove a question — nothing it
touches can sign, change a setting, or undo a decision you already made. -
Ekubo transactions read correctly.
94b35fd
Negative numbers were displayed through an unsigned conversion, so a
position's lower tick of -140 read as a 78-digit number, and an exact-output
swap's amount could read as an astronomical quantity of the token. Not
obviously wrong to look at, which is what made it worth fixing carefully: the
fix is in the rendering engine rather than worked around in the descriptions,
and those descriptions now conform to the ERC-7730 schema for the first time. -
Transactions say what they do.
877256d
A row in your activity list used to be titled "Transaction on Ethereum
Mainnet" — the one fact every row on the screen shares. It now says what the
plan does, like "Approve 1 USDC, swap on Ekubo", built only from sources you
or the wallet control and never from text the requester wrote. Eleven Ekubo
actions that showed only "Action for <id>" now name themselves too. -
Linux owner authentication states who is asking.
9d0bdc3
RUSTSEC-2026-0278
made a supplied user ID ineffective, leaving polkit to work the caller out
from/procby process ID — a lookup that races. The wallet now states its
own, read in a way that cannot be about a different process. The wallet
authenticates itself and stays running across the check, so this was
defence in depth rather than a break, but it is the gate in front of
everything that can widen what signs automatically. -
Every page draws inside a 120Hz frame.
4b45f3f
The Networks page was the worst at about 30fps and no longer slows down as
more networks are configured.
Note
This release upgrades your wallet database the first time it opens. The
upgrade is in place and refuses to run against anything it does not
recognise, so nothing is rewritten on a guess.
Warning
Windows and Linux key-storage warning: The current builds use per-user credential services that do not isolate raw account keys or the database key to Ekubo Wallet. Same-user malware, including a prompt-injected local agent that can execute programs, can extract those keys and bypass wallet policy and review. Read the security model before installing.
v1.6.0
This release fixes the ways agent connections could break and stay broken.
Each item links to its commit, where the full reasoning lives.
-
Updating the wallet no longer disconnects your agents.
6ed2e26
The bridge used to require the wallet to be the exact same build, so any
update cut off every connected agent — even updates that changed nothing the
bridge could see. It now checks a compatibility version that only moves when
the two actually need to change together. Note that this takes effect for
updates after 1.6.0; installing this release will still end sessions
started against 1.5.0. -
The wallet repairs its own agent helper.
c761fe4
If the small program your agent runs to reach the wallet was replaced by
another build, every agent silently stopped working and the only fix was
removing and re-adding the connector. The wallet now notices and puts the
right one back. -
Building from source no longer breaks your installed wallet.
87b6210
Running the test suite could overwrite that same helper with a development
copy, breaking agents on the machine until something replaced it. Only a
running wallet may touch it now. This affects contributors; installed
wallets were never the cause. -
Complexity limits in CI.
a5f0790
A guardrail against any single function quietly growing past the point where
it can be reviewed properly.
Warning
Windows and Linux key-storage warning: The current builds use per-user credential services that do not isolate raw account keys or the database key to Ekubo Wallet. Same-user malware, including a prompt-injected local agent that can execute programs, can extract those keys and bypass wallet policy and review. Read the security model before installing.
v1.5.0
Pool prices decoded from a float sqrt ratio were wrong, and this fixes them.
The ekubo.sqrt_ratio_float_to_q128 codec reimplemented the SqrtRatio layout
locally and split it at the wrong widths — a 7-bit exponent over an 89-bit
mantissa, shifted by exponent + 2, where the encoding is a 2-bit exponent over
a 94-bit mantissa shifted by 2 + 32 * exponent. The two agree only when
mantissa bits 89..=93 happen to be zero, so a pool that cleared them decoded
correctly and every other one returned a plausible but wrong number instead of
an error. On mainnet, USDC/USDG at tick -165 read as
22775868403039233396916548160160193078693462016 against an on-chain sqrt ratio
of 340254383154770049453632155902269194240. The layout now comes from
ekubo_sdk rather than a second copy of the arithmetic.
A fresh install now keeps every ranked RPC endpoint. default_networks
truncated each network's list to a single URL, so a configuration nobody had
tuned started with no failover: one public provider going down took the whole
network with it until the owner hand-edited the file. Networks are seeded with
the full ranked list from the vendored registry — six endpoints for Ethereum,
seven at most for any default — and an endpoint that cannot be built is now
dropped from the attempt order instead of failing the network outright.
Every address the wallet shows is in EIP-55 checksum case. The Accounts
page, transaction and signature reviews, receipt effects, automation dry-run
rows, and ERC-7730 token labels rendered bare lowercase hex while other screens
were already checksummed, so one account could read two ways in one session.
Agents get the same spelling through MCP — lowercasing a checksummed address is
free, recovering the checksum takes a keccak the agent may not have. Hashed
canonical forms, storage keys, and dapp-facing JSON-RPC payloads deliberately
keep their lowercase bytes, so no stored digest or in-flight approval changes.
Linux owner authentication installs itself. polkit reads action definitions
only from root-owned /usr/share/polkit-1/actions, which an AppImage cannot
write, so on a fresh install every owner operation — signing, key export,
account removal, policy widening — failed with one sentence naming a path to
copy by hand as root. Settings now carries an Owner authentication section
that offers to install the policy through polkit's own pkexec action, with the
definition streamed to install(1) over standard input so nothing depends on a
path root can read. Immutable distributions and NixOS, where that directory is
not writable or not there, are told which file their own tooling has to layer
rather than being handed a command that cannot work. The .deb maps the policy
into the actions directory at package install and needs no setup at all.
Also in this release: the third-party notices are regenerated for the current
dependency graph, and dependencies move up a point release.
Warning
Windows and Linux key-storage warning: The current builds use per-user credential services that do not isolate raw account keys or the database key to Ekubo Wallet. Same-user malware, including a prompt-injected local agent that can execute programs, can extract those keys and bypass wallet policy and review. Read the security model before installing.
v1.4.4
The Windows installer is signed. ekubo-wallet_1.4.4_x64-setup.exe carries an
Authenticode signature issued through Azure Trusted Signing to Ekubo, Inc.,
so Windows names that publisher in the install prompt instead of reporting an
unknown one. A certificate this new has no download reputation yet, so
SmartScreen can still interrupt the install; the publisher name in the prompt is
what distinguishes a genuine build, and every asset below also keeps the
detached updater signature and SHA-256 digest that earlier releases carried.
Nothing else changes. The one commit since 1.4.3 corrects a comment that
credited the wrong fix for a duplicate Dock tile, and no behavior moves with it.
The macOS and Linux artifacts are built, signed, and notarized exactly as they
were in 1.4.3, and an existing installation updates through the same signed
latest.json path.
Warning
Windows and Linux key-storage warning: The current builds use per-user credential services that do not isolate raw account keys or the database key to Ekubo Wallet. Same-user malware, including a prompt-injected local agent that can execute programs, can extract those keys and bypass wallet policy and review. Read the security model before installing.