Skip to content

v1.7.0

Choose a tag to compare

@github-actions github-actions released this 06 Sep 23:24
· 39 commits to main since this release
v1.7.0
b13d395

This release is about agents cleaning up after themselves, and about numbers on
the approval screen meaning what they look like they mean. Each item links to
its commit, where the full reasoning lives.

  • An agent can take back anything it asked you for.
    a2cea0b
    Nothing an agent puts in front of you expires on its own, so a request it
    gave up on used to sit in your wallet staying approvable — a swap at a price
    from an hour ago, a login for a session you had already closed, a proposal to
    widen what signs automatically for work that had long finished. Agents can
    now withdraw a transaction, a message or typed-data signature, or a policy,
    network, or token proposal. Withdrawing is not the same as your rejecting
    something: it records that the agent stopped asking, and the review simply
    disappears from your wallet. It can only ever remove a question — nothing it
    touches can sign, change a setting, or undo a decision you already made.

  • Ekubo transactions read correctly.
    94b35fd
    Negative numbers were displayed through an unsigned conversion, so a
    position's lower tick of -140 read as a 78-digit number, and an exact-output
    swap's amount could read as an astronomical quantity of the token. Not
    obviously wrong to look at, which is what made it worth fixing carefully: the
    fix is in the rendering engine rather than worked around in the descriptions,
    and those descriptions now conform to the ERC-7730 schema for the first time.

  • Transactions say what they do.
    877256d
    A row in your activity list used to be titled "Transaction on Ethereum
    Mainnet" — the one fact every row on the screen shares. It now says what the
    plan does, like "Approve 1 USDC, swap on Ekubo", built only from sources you
    or the wallet control and never from text the requester wrote. Eleven Ekubo
    actions that showed only "Action for <id>" now name themselves too.

  • Linux owner authentication states who is asking.
    9d0bdc3
    RUSTSEC-2026-0278
    made a supplied user ID ineffective, leaving polkit to work the caller out
    from /proc by process ID — a lookup that races. The wallet now states its
    own, read in a way that cannot be about a different process. The wallet
    authenticates itself and stays running across the check, so this was
    defence in depth rather than a break, but it is the gate in front of
    everything that can widen what signs automatically.

  • Every page draws inside a 120Hz frame.
    4b45f3f
    The Networks page was the worst at about 30fps and no longer slows down as
    more networks are configured.

Note

This release upgrades your wallet database the first time it opens. The
upgrade is in place and refuses to run against anything it does not
recognise, so nothing is rewritten on a guess.

Warning

Windows and Linux key-storage warning: The current builds use per-user credential services that do not isolate raw account keys or the database key to Ekubo Wallet. Same-user malware, including a prompt-injected local agent that can execute programs, can extract those keys and bypass wallet policy and review. Read the security model before installing.