Original release notes
4.16.0
Minor Changes
- #20278
3d24a89Thanks @gre-ledger! - Drop the@ledgerhq/errorsdependency, completing the errors sunset (LIVE-32915).
The @ledgerhq/errors package is removed from the monorepo: no workspace source imported it anymore, every error class it held now lives in the package that owns it (@ledgerhq/ledger-wallet-framework/errors for the ones shared across coin modules). createCustomErrorClass and the serializeError / deserializeError stack are gone with it - define errors as native classes and branch on error.name.
@ledgerhq/errors@6.37.0 stays on npm for external consumers, but is no longer published from this repo.
- #20280
9fcbe39Thanks @gre-ledger! - Stop depending on@ledgerhq/errors(LIVE-32915).
No workspace package declares it anymore, and none may again: enforce-boundaries now fails CI on any manifest that does. The classes it held live in the package that owns them, with @ledgerhq/ledger-wallet-framework/errors as the shared home below the coin layer.
The package itself stays in the repo so it keeps being published for external consumers, and is bridged to the external coin packages that still peer-depend on it via pnpm.packageExtensions using workspace:* (which reuses the single in-repo copy, so the dependency graph keeps exactly the physical copies it had before). LedgerHQ/coin-modules#752 removes that peerDependency upstream; once it is released the bridge can be dropped, but the package still needs publishing.
- #20315
4b73f81Thanks @RobinVncnt! - Portfolio upsell banner and Braze content cards can now coexist on Portfolio (Mobile: shared carousel; Desktop: side-by-side grid when Braze placement is enabled, otherwise upsell stacked above the Braze carousel).
- #20404
0f89b44Thanks @liviuciulinaru! - Replace the legacy Pay Card placeholders with the shared authentication flow on desktop and mobile
- #20633
67b2d83Thanks @tonykhaov! - Stop auto-opening the mobile product tour; open only from hub, deeplink, or debug
- #20585
feaf2fcThanks @claudiiafg! - Require signer confirmation before opening address delete confirmation in Contacts.
- #20423
44694e5Thanks @gre-ledger! - Complete the WalletSync DDD extraction: apps now compose the DDD slices directly
@ledgerhq/live-wallet no longer owns sync infrastructure. src/cloudsync/, src/walletsync/, src/accountName.ts and src/store.ts are removed in favour of @shared/cloud-sync, @shared/wallet-sync, @features/platform-wallet-sync, @domain/entity-account-name and @domain/entity-recent-addresses. What remains is the account list sync module (src/accounts/) plus src/walletSyncComposition.ts, which assembles the sync modules into the wallet-sync schema.
Desktop and mobile replace the monolithic wallet reducer with a combineReducers of the entity slices (accountNames, starredAccountIds, walletSync, recentAddresses, nonImportedAccountInfos) and wire the watch loop and trustchain lifecycle from @features/platform-wallet-sync at bootstrap. @ledgerhq/live-common drops its @ledgerhq/live-wallet runtime dependency: the wallet-api, platform and CSV-export helpers now take an AccountNamesState instead of the whole WalletState.
- #20595
43bf6d8Thanks @ysitbon! - Make every new-architecture barrel a pure regrouping point, and enforce it.
An index.* under shared/, domain/ or features/ may now contain only export * from "./x" lines, plus an optional default re-export. Having to sort in the export (export { a, b } from "./x") proved the target file mixed public and private code; an index.* holding actual code proved it more loudly. A new nx plugin infers a lint:structure target on each of the 49 packages and fails on both, along with two related rules: a barrel may not re-export a private internals location, and it may not re-export another workspace package.
That last rule removes the proxies. A package that re-exported a neighbour gave the same symbol two import paths and hid who actually provided it. Consumers now import the original provider and declare the dependency, which is why the two apps gain @features/flow-contacts-add-contact and the desktop app gains @features/platform-contacts.
Renamed or relocated, with the import specifier unchanged for consumers in every case except where noted:
@domain/entity-account-nameno longer exports thesetAccountNamesalias; use
bulkSetAccountNames, the name the slice actually defines.
@shared/cloud-syncexportsgetCloudSyncApias a named export from its api module instead of
re-exporting a default under a different name.
Five packages are left untouched behind temporary exclusions, each recording how to remove it:
@shared/env, the facade over the legacy@ledgerhq/live-env, which carries the wrapping in its
barrel.
- the
@ledgerhq/engagementand@ledgerhq/ptxpackages (flow-analytics-consent,
flow-large-screen-upsell, flow-lazy-onboarding-banner, flow-pay-card-auth), so each owning team lands the change on its own schedule. Conformant barrels were prepared and verified for them before being reverted, so the work is deferred rather than open.
- #20627
7af726bThanks @YazhuEth! - Explain the higher network fees when sending to an address that does not exist yet. EIP-8037 charges account creation substantially more gas, and nothing in the send flow told the user why the fee jumped. The gas we send is unchanged:eth_estimateGasremains the only source.
- #20207
aee0e64Thanks @lysyi3m! - Add Internet Computer (ICP) neuron staking to the coin module: create and top up neurons, start/stop dissolving, disburse, set/increase dissolve delay, follow, split, spawn, stake maturity, and add/remove hot keys, plus neuron listing. Governance operations are routed through the NNS governance canister via the device's update-call signing, alongside the existing ledger transfer path, and account synchronization now carries neuron data. Adds theSTAKE_NEURONandTOP_UP_NEURONoperation types, with matching icons and labels in the desktop and mobile operation history. (LIVE-28469)
- #20290
9708010Thanks @sarneijim! - Add the shared lazy onboarding banner flow, its Mobile portfolio view and configurable Shop link feature flag.
- #20456
a0f13a2Thanks @sarneijim! - Use fixed legacy onboarding date for backfill instead of app-open date
- #20458
9876163Thanks @sarneijim! - Use legacy onboarding date fallback in large-screen upsell eligibility
- #19169
92b70efThanks @OlivierFreyssinet! - Preserve installed apps in Device Intent Executor last seen device info.
- #20409
91a2953Thanks @claudiiafg! - Wire mobile contact address detail send, edit, and delete actions with confirmation sheets.
- #20559
c904346Thanks @claudiiafg! - Render Mobile Contacts address edit signer mismatch error and extract shared address detail action labels and UI state mapping.
- #20539
60b4626Thanks @gre-ledger! - Scope@ledgerhq/live-walletdown to wallet sync only
The package now exposes ./accounts and ./walletSyncComposition and nothing else. ordering.ts and addAccounts.ts move to @ledgerhq/live-common/account/*, and accountRawToAccountUserData joins live-common/account/serialization next to fromAccountRaw. The liveqr/ folder is gone: importAccounts.ts and accountToAccountData were unreachable, and accountDataToAccount - whose only callers rehydrated a wallet-sync descriptor - becomes accounts/descriptorToAccount. live-common no longer depends on live-wallet.
- #20510
a1bd49eThanks @claudiiafg! - Model Me as the default self contact with shared display-name formatting, external address counts, and a Ledger Wallet accounts intent.
- #18764
d266e13Thanks @philipptpunkt! - Migrate the swapfetchQuoteshelper from axios to an RTK Query endpoint (swapQuotesApi). The aggregator/quoterequest now flows through the Redux data layer, and the rawQuotes/providerErrors split is unchanged. Desktop and mobile register the new API and inject their store dispatch at startup viasetSwapQuotesStore; wallet-cli, which has no app store, sets up a standalone one.
The endpoint itself now lives in the new @domain/api-swap-quotes package; live-common re-exports it, so existing call sites are unchanged.
Two behaviour changes to be aware of:
/quotenow goes through the authenticated base query, where the legacy axios call sent no credentials. Both apps already register an auth provider on their store'sextra, so whether a request carries anAuthorizationheader is controlled entirely by thelwdAuth/lwmAuthfeature flags. They are disabled by default; enabling either one makes/quotesend the user's bearer token to the aggregator, and makes a 401/403 trigger the adapter's refresh-and-retry.- An aggregator HTTP error (4xx/5xx) now resolves to an empty result, so the caller surfaces the
noQuotesglobal. Previously the shared axios error interceptor turned these intoLedgerAPI4xx/LedgerAPI5xx, which propagated to the live app as an error. Only transport failures (no HTTP response) still reject, now with aSwapQuotesRequestFailederror rather than a bare RTK Query error object.
- #20642
a61f702Thanks @mcayuelas-ledger! - Persist the pay card hero balance filter across app restarts
- #20536
a5cf9e5Thanks @mcayuelas-ledger! - Wire the Card / Pay debug tool (@devtools/pay-card) into the mobile DevTools host, surfacing it alongside feature flags with native-platform overrides (LIVE-35498).

