v1.7.1
A patch release with one fix that matters: a request the wallet could not
simulate used to be a question nobody could answer. Each item links to its
commit, where the full reasoning lives.
-
A request stays reviewable when its chain cannot simulate.
28db8ce
A queued request was only ever shown to you once a fresh simulation had
produced a prepared transaction envelope. Where the endpoint cannot simulate
at all, that never happened — and the row was not merely un-approvable, it
could not be rejected either, because review failed before the screen was
reached. The only exit was for the agent to withdraw it, and anyone funded on
such a chain had no in-app route to move their money. The block was never the
transaction: every field of the envelope except one already comes from the
RPC, and the single missing input is the gas limit. That is all this restores,
frometh_estimateGas, bounded by the block gas limit read from the same
endpoint in the same breath and passed through the same ceiling, multiplier,
and intrinsic floor as before. Only a direct call is sized this way — a batch
would be estimated against a delegation the account does not hold yet. Nothing
is loosened: a request rescued this way can only ever reach a human and can
never sign on its own, and what you are shown still carries the simulation
findings, so you decide knowing the simulation did not run. A plan that
genuinely reverts still fails, and still reports its own failure rather than
an estimation error. -
Monad is no longer a default network.
c5d70c8
Its RPC does not implementeth_simulateV1without transaction validation —
the form the wallet sends, and the form the specification defaults to — so
nothing on Monad could be simulated, and therefore nothing could be signed.
Shipping it as a default offered a network the wallet could not transact on.
It stays in the registry under the same name and alias and can still be
configured for reads, and it becomes a default again as soon as an endpoint
answers the method.
Warning
Windows and Linux key-storage warning: The current builds use per-user credential services that do not isolate raw account keys or the database key to Ekubo Wallet. Same-user malware, including a prompt-injected local agent that can execute programs, can extract those keys and bypass wallet policy and review. Read the security model before installing.