chore(ethereum): add owner address string for vault transactions
What changed, and why it matters
This commit adds a new on-screen label, 'Owner address,' for Ethereum vault transactions on Trezor hardware wallets. It also updates test comments and adds new test cases for situations where the vault transaction's owner or receiver differs from the wallet's own address. The change appears to be a user-interface improvement that makes previously hidden address details visible during transaction confirmation, rather than falling back to 'blind signing.' It is not obviously a security fix, but it improves transparency and may reduce the risk of users approving misleading transactions.
Review the companion implementation commit that actually uses the new 'Owner address' label to confirm owner/receiver addresses are now displayed during vault transaction signing. Verify that the display logic correctly extracts and compares the owner and receiver addresses against the signer's address, and that no blind-signing fallback remains for these cases.
Security signals we found
UI transparency improvement for ERC-4626 vault transactions
Previously mismatched owner/receiver addresses may have been hidden from user confirmation
Test comments explicitly describe prior behavior as falling through to blind signing
No cryptographic, parsing, or access-control code modified in this commit
Evidence from the diff
The patch introduces a translation key ethereum__vault_owner_address (‘Owner address’) across the Rust translation tables, Python mocks, and English translation files. It updates test fixtures for ERC-4626 vault deposit/redeem/withdraw transactions on unknown vaults, changing comments from ‘unsafe calldata on unknown vault falls through to blind signing’ to ‘mismatched address shown for confirmation,’ and adds combined receiver-and-owner mismatch cases. No signing logic, parser, or access-control code is changed in this commit; only strings and tests are touched. The translation signature file is also refreshed.
Changed components
Trezor Ethereum transaction signing UIcore/embed/rust translation systemcommon/tests/fixtures/ethereum/sign_tx.json test fixturescore/translations English strings and signaturesInspect captured patch +91 / −9
### common/tests/fixtures/ethereum/sign_tx.json
@@ -325,7 +325,7 @@
"name": "redeem_unknown_vault_receiver_mismatch",
"skip_models": ["t1"],
"parameters": {
- "comment": "ERC-4626 redeem from unknown vault with receiver != sender - unsafe calldata on unknown vault falls through to blind signing",
+ "comment": "ERC-4626 redeem from unknown vault with receiver != sender - mismatched address shown for confirmation",
"data": "ba0876520000000000000000000000000000000000000000000000000de0b6b3a764000000000000000000000000000018db8b43dda9c5ea96b8ab07648f3f910e86bf2a0000000000000000000000004f4f1488acb1ae1b46146ceff804f591dfe660ac",
"path": "m/44'/60'/0'/0/1",
"to_address": "0xDDdDddDdDdddDDddDDddDDDDdDdDDdDDdDDDDDDd",
@@ -346,7 +346,7 @@
"name": "redeem_unknown_vault_owner_mismatch",
"skip_models": ["t1"],
"parameters": {
- "comment": "ERC-4626 redeem from unknown vault with owner != sender - unsafe calldata on unknown vault falls through to blind signing",
+ "comment": "ERC-4626 redeem from unknown vault with owner != sender - mismatched address shown for confirmation",
"data": "ba0876520000000000000000000000000000000000000000000000000de0b6b3a76400000000000000000000000000004f4f1488acb1ae1b46146ceff804f591dfe660ac00000000000000000000000018db8b43dda9c5ea96b8ab07648f3f910e86bf2a",
"path": "m/44'/60'/0'/0/1",
"to_address": "0xDDdDddDdDdddDDddDDddDDDDdDdDDdDDdDDDDDDd",
@@ -363,11 +363,32 @@
"sig_s": "57abaa201ad7cf8f58b48f411b4f10ce7a4ca273146ffc8dcc49719c99ca885d"
}
},
+ {
+ "name": "redeem_unknown_vault_receiver_and_owner_mismatch",
+ "skip_models": ["t1"],
+ "parameters": {
+ "comment": "ERC-4626 redeem from unknown vault with receiver != sender and owner != sender (distinct addresses) - both shown for confirmation",
+ "data": "ba0876520000000000000000000000000000000000000000000000000de0b6b3a764000000000000000000000000000018db8b43dda9c5ea96b8ab07648f3f910e86bf2a0000000000000000000000001e6e3708a059aea1241a81c7aae84b6cdbc54d59",
+ "path": "m/44'/60'/0'/0/1",
+ "to_address": "0xDDdDddDdDdddDDddDDddDDDDdDdDDdDDdDDDDDDd",
+ "chain_id": 1,
+ "nonce": "0x0",
+ "gas_price": "0x14",
+ "gas_limit": "0x14",
+ "tx_type": null,
+ "value": "0x0"
+ },
+ "result": {
+ "sig_v": 37,
+ "sig_r": "7f3cb75b67b4df381b9ea4b33150b70b823269a7383b46cf1abe5dc1a7ae0023",
+ "sig_s": "69e401b8f7b5475f77b5b7ec332291d056c6b7b6455daf6b743db6ee96389991"
+ }
+ },
{
"name": "deposit_unknown_vault_receiver_mismatch",
"skip_models": ["t1"],
"parameters": {
- "comment": "ERC-4626 deposit into unknown vault with receiver != sender - unsafe calldata on unknown vault falls through to blind signing",
+ "comment": "ERC-4626 deposit into unknown vault with receiver != sender - mismatched address shown for confirmation",
"data": "6e553f650000000000000000000000000000000000000000000000000000000005f5e10000000000000000000000000018db8b43dda9c5ea96b8ab07648f3f910e86bf2a",
"path": "m/44'/60'/0'/0/1",
"to_address": "0xDDdDddDdDdddDDddDDddDDDDdDdDDdDDdDDDDDDd",
@@ -388,7 +409,7 @@
"name": "withdraw_unknown_vault_receiver_mismatch",
"skip_models": ["t1"],
"parameters": {
- "comment": "ERC-4626 withdraw from unknown vault with receiver != sender - unsafe calldata on unknown vault falls through to blind signing",
+ "comment": "ERC-4626 withdraw from unknown vault with receiver != sender - mismatched address shown for confirmation",
"data": "b460af940000000000000000000000000000000000000000000000000000000005f5e10000000000000000000000000018db8b43dda9c5ea96b8ab07648f3f910e86bf2a0000000000000000000000004f4f1488acb1ae1b46146ceff804f591dfe660ac",
"path": "m/44'/60'/0'/0/1",
"to_address": "0xDDdDddDdDdddDDddDDddDDDDdDdDDdDDdDDDDDDd",
@@ -409,7 +430,7 @@
"name": "withdraw_unknown_vault_owner_mismatch",
"skip_models": ["t1"],
"parameters": {
- "comment": "ERC-4626 withdraw from unknown vault with owner != sender - unsafe calldata on unknown vault falls through to blind signing",
+ "comment": "ERC-4626 withdraw from unknown vault with owner != sender - mismatched address shown for confirmation",
"data": "b460af940000000000000000000000000000000000000000000000000000000005f5e1000000000000000000000000004f4f1488acb1ae1b46146ceff804f591dfe660ac00000000000000000000000018db8b43dda9c5ea96b8ab07648f3f910e86bf2a",
"path": "m/44'/60'/0'/0/1",
"to_address": "0xDDdDddDdDdddDDddDDddDDDDdDdDDdDDdDDDDDDd",
@@ -426,6 +447,27 @@
"sig_s": "3f8a9b3d39317d1e8f1a282b165c16a498124589cdd23131eb8f4d87127541ea"
}
},
+ {
+ "name": "withdraw_unknown_vault_receiver_and_owner_mismatch",
+ "skip_models": ["t1"],
+ "parameters": {
+ "comment": "ERC-4626 withdraw from unknown vault with receiver != sender and owner != sender (distinct addresses) - both shown for confirmation",
+ "data": "b460af940000000000000000000000000000000000000000000000000000000005f5e10000000000000000000000000018db8b43dda9c5ea96b8ab07648f3f910e86bf2a0000000000000000000000001e6e3708a059aea1241a81c7aae84b6cdbc54d59",
+ "path": "m/44'/60'/0'/0/1",
+ "to_address": "0xDDdDddDdDdddDDddDDddDDDDdDdDDdDDdDDDDDDd",
+ "chain_id": 1,
+ "nonce": "0x0",
+ "gas_price": "0x14",
+ "gas_limit": "0x14",
+ "tx_type": null,
+ "value": "0x0"
+ },
+ "result": {
+ "sig_v": 37,
+ "sig_r": "aa0f72bacdcc233d7c9add5ef2b3d85f2dce218f4e38f3b754c3ffecfd7873c5",
+ "sig_s": "36c9cfb86512fb4217d7f1b4aea4a78c18348f0c386fabe47d368a22c00dea8c"
+ }
+ },
{
"name": "vault_deposit_trailing_bytes",
"skip_models": ["t1"],
### core/embed/rust/librust_qstr.h
@@ -1350,6 +1350,7 @@ static void _librust_qstrs(void) {
MP_QSTR_ethereum__vault_claim_intro;
MP_QSTR_ethereum__vault_claim_to;
MP_QSTR_ethereum__vault_deposit_intro;
+ MP_QSTR_ethereum__vault_owner_address;
MP_QSTR_ethereum__vault_redeem_intro;
MP_QSTR_ethereum__vault_redeem_to;
MP_QSTR_ethereum__vault_withdraw_intro;
### core/embed/rust/src/translations/generated/translated_string.rs
@@ -1680,6 +1680,8 @@ pub enum TranslatedString {
stellar__deploy_contract = 1297, // "Deploy contract"
#[cfg(feature = "universal_fw")]
stellar__wasm_hash = 1298, // "Wasm hash"
+ #[cfg(feature = "universal_fw")]
+ ethereum__vault_owner_address = 1299, // "Owner address"
}
impl TranslatedString {
@@ -2986,6 +2988,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(feature = "debug", feature = "universal_fw"))]
@@ -4290,6 +4293,7 @@ impl TranslatedString {
19041,
19056,
19065,
+ 19078,
];
#[cfg(all(feature = "debug", not(feature = "universal_fw")))]
@@ -5593,6 +5597,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(feature = "debug", not(feature = "universal_fw")))]
@@ -6897,6 +6902,7 @@ impl TranslatedString {
19041,
19056,
19065,
+ 19078,
];
#[cfg(all(not(feature = "debug"), feature = "universal_fw"))]
@@ -8200,6 +8206,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(not(feature = "debug"), feature = "universal_fw"))]
@@ -9504,6 +9511,7 @@ impl TranslatedString {
19041,
19056,
19065,
+ 19078,
];
#[cfg(all(not(feature = "debug"), not(feature = "universal_fw")))]
@@ -10807,6 +10815,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(not(feature = "debug"), not(feature = "universal_fw")))]
@@ -12111,6 +12120,7 @@ impl TranslatedString {
19041,
19056,
19065,
+ 19078,
];
} else if #[cfg(feature = "layout_caesar")] {
@@ -13415,6 +13425,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(feature = "debug", feature = "universal_fw"))]
@@ -14719,6 +14730,7 @@ impl TranslatedString {
16913,
16928,
16937,
+ 16950,
];
#[cfg(all(feature = "debug", not(feature = "universal_fw")))]
@@ -16022,6 +16034,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(feature = "debug", not(feature = "universal_fw")))]
@@ -17326,6 +17339,7 @@ impl TranslatedString {
16913,
16928,
16937,
+ 16950,
];
#[cfg(all(not(feature = "debug"), feature = "universal_fw"))]
@@ -18629,6 +18643,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(not(feature = "debug"), feature = "universal_fw"))]
@@ -19933,6 +19948,7 @@ impl TranslatedString {
16913,
16928,
16937,
+ 16950,
];
#[cfg(all(not(feature = "debug"), not(feature = "universal_fw")))]
@@ -21236,6 +21252,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(not(feature = "debug"), not(feature = "universal_fw")))]
@@ -22540,6 +22557,7 @@ impl TranslatedString {
16913,
16928,
16937,
+ 16950,
];
} else if #[cfg(feature = "layout_delizia")] {
@@ -23844,6 +23862,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(feature = "debug", feature = "universal_fw"))]
@@ -25148,6 +25167,7 @@ impl TranslatedString {
18894,
18909,
18918,
+ 18931,
];
#[cfg(all(feature = "debug", not(feature = "universal_fw")))]
@@ -26451,6 +26471,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(feature = "debug", not(feature = "universal_fw")))]
@@ -27755,6 +27776,7 @@ impl TranslatedString {
18894,
18909,
18918,
+ 18931,
];
#[cfg(all(not(feature = "debug"), feature = "universal_fw"))]
@@ -29058,6 +29080,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(not(feature = "debug"), feature = "universal_fw"))]
@@ -30362,6 +30385,7 @@ impl TranslatedString {
18894,
18909,
18918,
+ 18931,
];
#[cfg(all(not(feature = "debug"), not(feature = "universal_fw")))]
@@ -31665,6 +31689,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(not(feature = "debug"), not(feature = "universal_fw")))]
@@ -32969,6 +32994,7 @@ impl TranslatedString {
18894,
18909,
18918,
+ 18931,
];
} else if #[cfg(feature = "layout_eckhart")] {
@@ -34273,6 +34299,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(feature = "debug", feature = "universal_fw"))]
@@ -35577,6 +35604,7 @@ impl TranslatedString {
20365,
20380,
20389,
+ 20402,
];
#[cfg(all(feature = "debug", not(feature = "universal_fw")))]
@@ -36880,6 +36908,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(feature = "debug", not(feature = "universal_fw")))]
@@ -38184,6 +38213,7 @@ impl TranslatedString {
20365,
20380,
20389,
+ 20402,
];
#[cfg(all(not(feature = "debug"), feature = "universal_fw"))]
@@ -39487,6 +39517,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(not(feature = "debug"), feature = "universal_fw"))]
@@ -40791,6 +40822,7 @@ impl TranslatedString {
20365,
20380,
20389,
+ 20402,
];
#[cfg(all(not(feature = "debug"), not(feature = "universal_fw")))]
@@ -42094,6 +42126,7 @@ impl TranslatedString {
"Multisig XPUB #{0} ",
"Deploy contract",
"Wasm hash",
+ "Owner address",
);
#[cfg(all(not(feature = "debug"), not(feature = "universal_fw")))]
@@ -43398,6 +43431,7 @@ impl TranslatedString {
20365,
20380,
20389,
+ 20402,
];
}
@@ -44047,6 +44081,8 @@ impl TranslatedString {
#[cfg(feature = "universal_fw")]
(Qstr::MP_QSTR_ethereum__vault_deposit_intro, Self::ethereum__vault_deposit_intro),
#[cfg(feature = "universal_fw")]
+ (Qstr::MP_QSTR_ethereum__vault_owner_address, Self::ethereum__vault_owner_address),
+ #[cfg(feature = "universal_fw")]
(Qstr::MP_QSTR_ethereum__vault_redeem_intro, Self::ethereum__vault_redeem_intro),
#[cfg(feature = "universal_fw")]
(Qstr::MP_QSTR_ethereum__vault_redeem_to, Self::ethereum__vault_redeem_to),
### core/mocks/trezortranslate_keys.pyi
@@ -408,6 +408,7 @@ class TR:
ethereum__vault_claim_intro: str = "Claim rewards from Merkl.xyz"
ethereum__vault_claim_to: str = "Claim to"
ethereum__vault_deposit_intro: str = "Review details to deposit to vault."
+ ethereum__vault_owner_address: str = "Owner address"
ethereum__vault_redeem_intro: str = "Review details to redeem from vault."
ethereum__vault_redeem_to: str = "Redeem to"
ethereum__vault_withdraw_intro: str = "Review details to withdraw from vault."
### core/translations/en.json
@@ -960,6 +960,7 @@
"ethereum__vault_claim_intro": "Claim rewards from Merkl.xyz",
"ethereum__vault_claim_to": "Claim to",
"ethereum__vault_deposit_intro": "Review details to deposit to vault.",
+ "ethereum__vault_owner_address": "Owner address",
"ethereum__vault_redeem_intro": "Review details to redeem from vault.",
"ethereum__vault_redeem_to": "Redeem to",
"ethereum__vault_withdraw_intro": "Review details to withdraw from vault.",
### core/translations/order.json
@@ -1297,5 +1297,6 @@
"1295": "buttons__cancel_sign",
"1296": "address__title_multisig_xpub_template",
"1297": "stellar__deploy_contract",
- "1298": "stellar__wasm_hash"
+ "1298": "stellar__wasm_hash",
+ "1299": "ethereum__vault_owner_address"
}
### core/translations/signatures.json
@@ -1,8 +1,8 @@
{
"current": {
- "merkle_root": "fcb37dfc8f6fd7cd1d20bd003cfa4383880a9fc64bbb8d24f5aa17fa1e20efb1",
- "datetime": "2026-09-30T18:11:48.431502+00:00",
- "commit": "88c6eb7f73a9859b8cb131b282b52be7acf1fc70"
+ "merkle_root": "06431c5f85cc0b9a8e54393132e669dfce62ee3e5ce2734872d9dfed89db2669",
+ "datetime": "2026-09-30T19:23:41.943784+00:00",
+ "commit": "8fd79fd12a79c0f0910a1e5a9ce14faced73002d"
},
"history": [
{Why this scored 26/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.