Review of Spark's trust model

Unilateral-exit readiness

Cake describes a one-transaction exit that its audited integration did not expose

Cake Wallet describes unilateral exit as publishing a pre-signed transaction. In the reviewed Cake snapshot, the pinned Breez version had not shipped its public mobile exit API and no complete recovery-bundle or unilateral-exit product flow was found. 1234

5 sourcesEvidence reviewed through July 14, 2026

What the evidence shows

Technical and product details

  1. First-party claim

    Cake says a recipient can “simply publish a pre-signed Bitcoin transaction” to perform a trustless unilateral exit. 1

    Supporting material shown on this page

  2. Shipped integration

    The audited Cake tree pins Breez Spark Flutter 0.14.0 and contains no unilateral-exit or recovery-bundle flow. 23

    Supporting material shown on this page

    Cake sourceRepository record · github.com · checked 2026-07-14
    Cake Breez dependencyPinned source code · github.com · checked 2026-07-14
    Relevant lines from the pinned source · open raw file
    72  breez_sdk_spark_flutter:
    73    git:
    74      url: https://github.com/breez/breez-sdk-spark-flutter
    75      ref: v0.14.0
  3. API fact

    Breez targeted its public exit API for 0.14.0 but did not ship it; issue 374 remains open. 34

    Supporting material shown on this page

    Cake Breez dependencyPinned source code · github.com · checked 2026-07-14
    Relevant lines from the pinned source · open raw file
    72  breez_sdk_spark_flutter:
    73    git:
    74      url: https://github.com/breez/breez-sdk-spark-flutter
    75      ref: v0.14.0
  4. Published case study

    Blink's published 100,000-sat wallet had a complete 22-leaf graph of 253 packages. The selected four-leaf recovery still required roughly 24 pre-refund package confirmations, later refund broadcasts, and final sweeps rather than one transaction. 5

    Supporting material shown on this page

    Blink case studyPinned source code · github.com · checked 2026-07-14
    Relevant lines from the pinned source · open raw file
    1# Case study: a real Spark unilateral exit on Bitcoin mainnet

Product-level detail

What the reviewed Cake Wallet integration exposed

The conclusions below are reproduced here so the reader does not need to open the separate implementation review. Each result remains limited to the named source snapshot, published binary, or public product surface.

Cake Wallet

Surface reviewed: public mobile source

No recovery-bundle handling or complete unilateral-exit product flow was found at the pinned snapshot. Breez's public mobile exit API targeted for this dependency generation had not shipped.

Capabilities that were present: mnemonic or seed initialization; Spark, Lightning, and cooperative Bitcoin-address payments.

The public Cake article describes a protocol-level response to an attack; it does not expressly claim that the audited UI contains an exit button.

See versions, search method, artifact hashes, and full review limits.

Scope control

What this does not establish

  • Cake's article is a protocol-level attack sketch; it does not explicitly say that the current Cake UI contains an exit button. The product finding is limited to the pinned Cake source and its pinned Breez 0.14.0 dependency. 1234

Sources and excerpts

Primary sources

The relevant details and available source-code excerpts appear alongside the claims above. This list preserves the complete original-source trail for independent verification.

1

Cake's Lightning article

Web source · blog.cakewallet.com · Live source · checked 2026-07-14

Open original source
2

Cake source

Repository record · github.com · Pinned or archival · checked 2026-07-14

Open original source
3

Cake Breez dependency

Pinned source code · github.com · Pinned or archival · checked 2026-07-14

Open original source
4

Breez issue 374

Repository record · github.com · Live source · checked 2026-07-14

Open original source
5

Blink case study

Pinned source code · github.com · Pinned or archival · checked 2026-07-14

Open original source

How sources, absence findings, and limitations were evaluated