AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 63 Monero

Generic Token Fixes (#2873)

Public commit record

What the developer wrote

Authored by David Adegoke

71/100 · Adequate
Generic Token Fixes (#2873)

* feat: Automatically detect wallet tokens for EVM chains

* feat: Disable potential tg scam tokens by default

* feat: Add homoglyph normalization to detect spoofing attacks in token symbols

* refactor: Improve scam token detection and apply to automatically fetched EVM tokens

* refactor: Enhance scam detection for automatically detected tokens in evm wallets

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Add fiat check to scam checks on automatically imported token and disable tokens that fail the check

* feat: Enable whitelisted tokens with balance when importing wallet tokens

* feat: Disable imported tokens with balance less than 0.1 usd

* feat: Disable imported tokens with balance less than 0.1 usd
- Update configure file

* fixes:
- default tokens marked as potential scam
- ui overflow for token name on balance page
- add more filters for spam tokens
✓ Descriptive subject✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit improves protections in Cake Wallet against scam or fake tokens on EVM blockchains. It tightens how the app decides a token looks suspicious, adds more spam keywords (like 'reward', 'claim', 'airdrop'), checks whether a token is pretending to be the chain's native coin (e.g., a fake 'ETH' on Ethereum), and disables low-value or suspicious tokens when wallets are imported. It also fixes a minor screen layout issue where long token names could overflow.

Recommended action

Review the full PR #2873 diff and any related tests to confirm the additional protections described in the commit message (homoglyph normalization, fiat-value thresholds, whitelist behavior) are implemented correctly. Validate that the native-symbol check does not produce false positives for legitimate wrapped/bridged tokens and that the suspicious-string list does not over-flag legitimate airdrop or reward tokens.

Security signals we found

01

Token impersonation / spoofing detection (symbol matching native currency)

02

Expansion of suspicious keyword filters for scam tokens

03

Automatic marking of suspicious ERC-20 tokens on add/import

04

UI overflow fix for long token names (non-security hardening)

05

Commit message references additional anti-scam measures (homoglyph normalization, fiat balance checks, auto-detected tokens) not present in supplied diff

Risk score

Why this scored 63/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 10/15
Affected reach 12/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.