AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 50 Monero

CW-1228: Automatically detect wallet tokens for EVM chains (#2827)

Public commit record

What the developer wrote

Authored by David Adegoke

81/100 · Strong
CW-1228: Automatically detect wallet tokens for EVM chains (#2827)

* feat: Automatically detect wallet tokens for EVM chains

* feat: Disable potential tg scam tokens by default

* feat: Add homoglyph normalization to detect spoofing attacks in token symbols

* refactor: Improve scam token detection and apply to automatically fetched EVM tokens

* refactor: Enhance scam detection for automatically detected tokens in evm wallets

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Enable whitelisted tokens with balance when importing wallet tokens
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit adds a feature that automatically finds and lists Ethereum-compatible tokens a user owns, then tries to protect them from scam tokens. It fetches token data from an external service (Moralis), marks tokens as suspicious if their names/symbols contain scammy keywords or mimic well-known coins using look-alike letters (like Cyrillic or Greek characters), and disables tokens that fail a fiat price check. The change is primarily a defensive security improvement, but it also introduces new code paths that handle external data and user balances, which carry some risk if the checks can be bypassed or the external service is untrusted.

Recommended action

Review the Moralis API response handling for robust validation and error paths; ensure the homoglyph map covers additional confusable Unicode characters; verify that fiat-price failures cannot be abused to hide legitimate tokens; consider adding user-visible warnings rather than silently disabling tokens; and audit the whitelisted-token auto-enable logic to confirm it cannot be triggered by contract-address collisions or chain-specific address reuse.

Security signals we found

01

New external API integration (Moralis) for token metadata and balances

02

New homoglyph normalization to detect spoofed token symbols

03

Heuristic scam detection based on symbol/name keywords and base-currency collision

04

Fiat price check used as a spam/scam signal

05

Automatic enabling of whitelisted tokens with non-zero balance

06

Potential for false positives/negatives in scam detection heuristics

Risk score

Why this scored 50/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 9/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.