feat: add trezor send - #1187
Conversation
Greptile SummaryThe PR integrates paired Trezor wallets into on-chain send and receive flows and strengthens session recovery and hardware-activity reconciliation.
Confidence Score: 3/5The PR should not merge until multi-wallet receive selection and restart-safe preservation of newly broadcast hardware activities are addressed. Global Receive silently loses Trezor access for users with multiple paired identities, and process-local snapshot protection can delete a newly created hardware-send activity and its contact metadata after an app restart. Files Needing Attention: app/src/main/java/to/bitkit/ui/screens/wallets/receive/ReceiveSheet.kt; app/src/main/java/to/bitkit/services/CoreService.kt
|
| Filename | Overview |
|---|---|
| app/src/main/java/to/bitkit/ui/screens/wallets/receive/ReceiveSheet.kt | Wires hardware address loading and verification into Receive, but removes the hardware option from global Receive when multiple paired wallets require selection. |
| app/src/main/java/to/bitkit/services/CoreService.kt | Preserves locally created sends during watcher lag only through process-local state, allowing restart-time deletion and contact loss. |
| app/src/main/java/to/bitkit/ui/screens/wallets/send/HwSendViewModel.kt | Adds a guarded sign-and-broadcast state machine with signed-transaction reuse for connectivity retries and wallet-scoped result persistence. |
| app/src/main/java/to/bitkit/repositories/HwWalletRepo.kt | Adds offline receive derivation, device verification, fee estimation, maximum calculation, and more targeted stale-session cleanup. |
| app/src/main/java/to/bitkit/viewmodels/AppViewModel.kt | Extends request validation, amount limits, fee preparation, source switching, contact preparation, and success handling for hardware-funded sends. |
| app/src/main/java/to/bitkit/repositories/ActivityRepo.kt | Scopes hardware activity lookup and contact mutation to the selected external wallet identity. |
Flowchart
%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Select paired Trezor] --> B[Enter on-chain request]
B --> C[Estimate fee from stored xpub]
C --> D[Review payment]
D --> E[Reconnect matching wallet identity]
E --> F[Sign on Trezor]
F --> G[Broadcast signed transaction]
G --> H[Create wallet-scoped activity]
H --> I[Reconcile watcher snapshot]
J[Open Trezor Receive] --> K[Derive unused address from xpub]
K --> L[Display QR and address]
L --> M[Reconnect matching identity]
M --> N[Verify address on device]
Reviews (1): Last reviewed commit: "feat: add trezor send and receive" | Re-trigger Greptile
This comment was marked as outdated.
This comment was marked as outdated.
eeed080 to
4afba39
Compare
4afba39 to
3182a99
Compare
|
Done — #1187 is now Send-only and conflict-free. Receive is split into the stacked #1189. iOS is split the same way: Send in synonymdev/bitkit-ios#688 and Receive in synonymdev/bitkit-ios#693. |
This comment was marked as outdated.
This comment was marked as outdated.
This comment was marked as resolved.
This comment was marked as resolved.
5ef1318 to
80d47e3
Compare
ovitrif
left a comment
There was a problem hiding this comment.
Code LGTM, found some UI nits during testing:
1. Available (Savings) text
This was either updated in figma long ago or only in v62, but since we're here we could remove the (Savings) part as it's no longer there and a bit redundant (button already says and means the same thing, while when showing trezor funds, it disappears).
2. Funding source switch lag
when switching to/between HWWs there is an unexpected delay.
Could we add a loading spinner while switching? Button text could fade out while spinner fades in, or even without transition, the UX would feel more snappy, less clumsy?
| Amount | Confirm |
|---|---|
hwDelayAmt.mp4 |
hwSendConfirmSwitch.mp4 |
I don't see this delay that much on confirm for some reason, but there's a small strangeness if tapping continuously multiple times on the button, just a FYI, don't think it's in scope of this PR to over optimize all small details.
QA Notes
Tested on a Pixel 9a emulator using regtest:
- Sent from the standard Trezor through source selection, amount entry, duplicate-preparation protection, confirmation, device signing, broadcast, and success.
- Verified the hardware-wallet transaction appeared once in recent activity.
- Exercised source switching across Savings and multiple named Trezor identities; balances updated correctly, with the non-blocking delay noted above.
Approve.
|
Addressed both UI notes in 0cf15db. The amount screen now uses Available for Savings. Source switching shows a spinner, ignores repeated taps, cancels stale fee refreshes, and disables Continue and confirmation until the selected source is ready. |
|
Testing... |
piotr-iohk
left a comment
There was a problem hiding this comment.
LGTM
Tested on emulator + Trezor emu, and on a Samsung S22 with a real Trezor 7 over BLE. Standard HW send, passphrase HW send, tags, and cancel-during-sign all worked. S22 logs look fine on that path.
Nit: Android never shows the hourglass on pending on-chain txs (HW or software) — still the send/transfer arrow. Figma uses HourglassSimple on the activity list (this and this). iOS already has the hourglass. Would be good to add it on Android in general, and use blue for pending HW sends so it matches the rest of the hardware styling.
|
Note: conflicts appeared after recen merges to master I guess. |
0cf15db to
7ca35a3
Compare
a968811 to
de7fb9f
Compare
|
fyi I'm polishing a bit the UI/UX of the new components, there's a few issues with 0cf15db, non-blocking though IMO. I'll either open a stacked PR targeting this or a new one if this gets merged. |
|
Starting review... |
|
This is probably an issue, on scrcpy.2026-08-28.000212.mp4Note that the UI changes to the funding source button and the fee cell are because the recording is from my local WIP polish, but the swiper issue was there already and I didn't touch it. |
There was a problem hiding this comment.
Approved
I still see the issue I flagged earlier, that was supposed to be fixed after the last commit (#1187 (comment)).
| Expected | Actual |
|---|---|
![]() |
![]() |
I'll fix it together with the other polishing changes.
|
@ben-kaufman can you resign the commits:
I can't merge otherwise 🙏🏻 |
9484f78 to
93cda1b
Compare


Description
This PR:
The Send UI follows the Bitkit Wallet design.
Receive support will follow in a separate stacked PR.
Linked Issues/Tasks
N/A
Screenshot / Video
QA Notes
Manual Tests
regression:Send → switch between Savings, Spending, and Trezor: available balance and fee-aware maximum update for each source.regression:cancel or disconnect during signing → retry: Bitkit reconnects without creating or broadcasting a duplicate transaction.Automated Checks
HwFundingSignerTest.ktandTrezorSessionFailureTest.kt: cover source coordination, timeouts, stale-session retry, retained signed transactions, and failure classification.HwWalletRepoTest.kt: cover pending sent activity and contact preservation during watcher reconciliation.ShopPaymentRequestTest.kt: cover hardware-wallet on-chain-only scan handling.