AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 26 Monero

feat(spl): custom tokens with validation and error handling

Public commit record

What the developer wrote

Authored by sneurlax

62/100 · Adequate
feat(spl): custom tokens with validation and error handling
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
The short version

What changed, and why it matters

This commit adds a new screen that lets users manually add custom Solana SPL tokens to their Stack Wallet. It checks the mint address format, tries to fetch token details from an API, and lets the user type in details if the API has no record. The change also replaces the old fixed list of Solana tokens with this custom-add flow. There is no clear security bug in the diff, but the new code trusts user-supplied token metadata and does not verify on-chain that the token really exists or that the wallet holds it, which could let a user be tricked into adding a fake or misleading token.

Recommended action

Treat this as a feature review rather than a confirmed vulnerability. If the project wants to reduce spoofing risk, add on-chain validation that the mint address is an initialized SPL Token mint, optionally verify the wallet's associated token account, and warn users when metadata is user-supplied. Also consider requiring a known source (e.g., token-list registry) before allowing a token to be added, or visually distinguishing custom/unverified tokens in the UI.

Security signals we found

01

User-controlled token metadata accepted when API returns no data

02

Mint address format validation only; no on-chain mint account verification shown

03

No shown verification that token is a real SPL token or that wallet holds associated token account

04

Potential UI spoofing: a malicious actor could instruct a user to add a fake token with a legitimate-looking name/symbol

05

Custom token list merged with default token list, so fake tokens appear alongside real ones

06

Debug logging of token ownership check present but not shown to block addition

Risk score

Why this scored 26/100

Our methodology →
Potential impact 4/30
Exploitability 5/25
Stealth signal 3/15
Affected reach 6/15
Confidence 5/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.