spark.exposed

The exit

Cake describes a one-transaction exit that its audited integration did not expose

Cake v6.4.4 and the current source now pin Breez Flutter 0.23.0, so the old SDK-version objection is obsolete. The inspected Lightning adapter still contains no exit-state export or complete operatorless recovery flow. Cake’s article describes a protocol mechanism; it does not explicitly promise an exit button. 345

5 sourcesEvidence reviewed through September 11, 2026

Fresh source, release metadata, APK-surface and public-documentation review on September 11. Source and release versions are distinguished; no funded wallet runtime or operator-outage execution was performed.

What the evidence shows

Technical and product details

  1. First-party claim

    Cake says a recipient can “simply publish a pre-signed Bitcoin transaction” to perform a trustless unilateral exit. 1

    Supporting material shown on this page

  2. Current integration

    Cake v6.4.4 and the current source pin Breez Flutter 0.23.0. The earlier statement that this wallet still used 0.14.0 is obsolete. The reviewed Lightning adapter calls ordinary SDK payments and deposit refunds, but no current exit-state export or complete operatorless recovery workflow was found. 34

    Supporting material shown on this page

    September 11 Cake WalletPinned source code · github.com · checked 2026-09-11
    Relevant lines from the pinned source · open raw file
    77  breez_sdk_spark_flutter:
    78    git:
    79      url: https://github.com/breez/breez-sdk-spark-flutter
    80      ref: v0.23.0
  3. SDK correction

    Breez’s mobile construction and export/import APIs exist. The current limitation is the missing application recovery workflow, not absence of a mobile SDK API. 35

    Supporting material shown on this page

    September 11 Cake WalletPinned source code · github.com · checked 2026-09-11
    Relevant lines from the pinned source · open raw file
    77  breez_sdk_spark_flutter:
    78    git:
    79      url: https://github.com/breez/breez-sdk-spark-flutter
    80      ref: v0.23.0
  4. Published case study

    Blink's published 100,000-sat wallet had a complete 22-leaf graph of 253 packages. The selected four-leaf recovery still required roughly 24 pre-refund package confirmations, later refund broadcasts, and final sweeps rather than one transaction. 2

    Supporting material shown on this page

    Blink case studyPinned source code · github.com · checked 2026-07-14
    Relevant lines from the pinned source · open raw file
    1# Case study: a real Spark unilateral exit on Bitcoin mainnet

Product-level detail

What the reviewed Cake Wallet integration exposed

The conclusions below are reproduced here so the reader does not need to open the separate implementation review. Each result remains limited to the named source snapshot, published binary, or public product surface.

Cake Wallet

Surface reviewed: public mobile source

Cake v6.4.4 and the current source pin Breez Flutter 0.23.0. The earlier statement that this wallet still used 0.14.0 is obsolete. The reviewed Lightning adapter calls ordinary SDK payments and deposit refunds, but no current exit-state export or complete operatorless recovery workflow was found.

Capabilities that were present: mnemonic or seed initialization; Spark, Lightning, and cooperative Bitcoin-address payments; upgraded Breez 0.23.0 dependency with SDK exit construction and state export/import capabilities.

The public Cake article describes a protocol-level response to an attack; it does not expressly claim that the audited UI contains an exit button.

See versions, search method, artifact hashes, and full review limits.

Scope control

What this does not establish

  • This is a static review of Cake’s v6.4.4 release source and current default branch. The app binary was not executed. The protocol article is not treated as an explicit claim that the audited UI has an exit button. 345

Sources and excerpts

Primary sources

The relevant details and available source-code excerpts appear alongside the claims above. This list preserves the complete original-source trail for independent verification.

1

Cake's Lightning article

Web source · blog.cakewallet.com · Live source · checked 2026-07-14

Open original source
2

Blink case study

Pinned source code · github.com · Pinned or archival · checked 2026-07-14

Open original source
3

September 11 Cake Wallet

Pinned source code · github.com · Pinned or archival · checked 2026-09-11

Open original source
4

Current Cake Lightning adapter

Pinned source code · github.com · Pinned or archival · checked 2026-09-11

Open original source
5

September 11 wallet audit

Reproducible audit manifest · Review of Spark's trust model · Pinned or archival · checked 2026-09-11

Open original source

How sources, absence findings, and limitations were evaluated