Each control that leads to a signature or to the private key now has a test that it refuses a defective wallet before decrypting anything: Send on the main, address and token screens, Export Private Key, and both approval screens, as drawn and as clicked. Send on the confirmation screen had no such check. The Send buttons stand in front of it, but the popup reopens onto it from a saved view, so it now refuses the same way. The comments that said the wallet's key cannot be derived now say that getSignerForAddress refuses it, and the walletDefects module comment names both earlier import paths. Model: opus-5-5