AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 53 Monero

CW-1228: Automatically Fetch All Tokens (#2869)

Public commit record

What the developer wrote

Authored by David Adegoke

76/100 · Adequate
CW-1228: Automatically Fetch All Tokens (#2869)

* feat: Automatically detect wallet tokens for EVM chains

* feat: Disable potential tg scam tokens by default

* feat: Add homoglyph normalization to detect spoofing attacks in token symbols

* refactor: Improve scam token detection and apply to automatically fetched EVM tokens

* refactor: Enhance scam detection for automatically detected tokens in evm wallets

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Enable whitelisted tokens with balance when importing wallet tokens

* feat: Disable imported tokens with balance less than 0.1 usd

* feat: Disable imported tokens with balance less than 0.1 usd
- Update configure file
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit changes how Cake Wallet automatically finds and displays Ethereum-compatible tokens in a user's wallet. Previously, the app likely added discovered tokens more readily. Now it applies several safety filters: tokens flagged as possible spam by the data provider, tokens with suspicious properties, tokens without a valid USD price, and tokens worth less than about 10 cents are disabled by default. The change also fixes a chain-name label for BNB Smart Chain and adds a helper that carries token balances through the discovery process so the app can check the dollar value. Overall this is a defensive, anti-scam improvement rather than a vulnerability fix.

Recommended action

No urgent action required. This is a defensive improvement. Users and auditors should verify that the existing isTokenPropertiesSuspicious heuristics and the $0.10 threshold behave as intended across chains, and that the Moralis 'possibleSpam' flag is not overly aggressive for legitimate low-cap tokens.

Security signals we found

01

Anti-scam hardening: automatically disables tokens flagged as possible spam by Moralis

02

Anti-scam hardening: disables tokens whose on-chain/name/symbol properties are deemed suspicious by existing wallet heuristics

03

Anti-scam hardening: disables tokens for which no positive USD fiat price can be fetched

04

Anti-scam hardening: disables tokens with a computed USD balance below 0.1 USD

05

Homoglyph/spoofing detection in token symbols is referenced in commit message but not visible in the provided diff

06

BSC chain symbol corrected from 'BNB' to 'BSC' for Moralis API queries

Risk score

Why this scored 53/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 10/15
Affected reach 12/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.