AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 51 Monero

feat: harden spam detection for solana and evm (#3322)

Public commit record

What the developer wrote

Authored by David Adegoke

93/100 · Strong
feat: harden spam detection for solana and evm (#3322)

* feat: harden spam detection for solana and evm

* fix: guard scam/impersonator tokens from auto-enabling on EVM and Solana

* feat: enhance token property validation for scam detection
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit strengthens the wallet's automatic detection and handling of scam, spam, and impersonator tokens on Ethereum-compatible (EVM) chains and Solana. It adds checks for suspicious names/symbols (e.g., fake 'ETH', 'SOL', 'USDC', or tokens with 'airdrop', 'claim', URLs), prevents auto-enabling tokens that look like well-known coins but aren't verified, and uses Moralis API data such as price, value, verified-contract status, and security score to decide whether a discovered token should be shown as enabled. It also re-runs a one-time cleanup on existing tokens to reclassify any previously missed scams. There is no direct exploit fixed in the diff; rather, it is a defensive hardening change against social-engineering/token-spam attacks.

Recommended action

Treat as a security-hardening improvement and include in the next release. Review the new heuristics for false positives that could hide legitimate user-added tokens. Ensure the Moralis API key and pagination behavior handle rate limits. No emergency patch is indicated by the diff alone.

Security signals we found

01

Hardens token spam/scam classification for EVM and Solana

02

Adds Moralis security_score, usd_price, usd_value, verified_contract ingestion

03

Adds homoglyph normalization and symbol-impersonation detection

04

Prevents auto-enabling impersonator tokens that lack Moralis price or verified contract

05

One-time re-scan of existing tokens to reclassify missed scams

06

No direct exploit or key-leakage fix visible in diff

Risk score

Why this scored 51/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 9/15
Affected reach 11/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.