AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 24 Bitcoin

fix(ethereum): Remove hardcoded names for registry known addresses

Public commit record

What the developer wrote

Authored by PrisionMike

62/100 · Adequate
fix(ethereum): Remove hardcoded names for registry known addresses

[no changelog]
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
The short version

What changed, and why it matters

This commit removes a long list of hardcoded friendly names (like 'Lido', 'Morpho', 'WalletConnect') that Trezor devices previously showed when signing Ethereum transactions to certain smart contracts. After the change, only a few built-in names remain (mainly 'WETH' and a test address), and most contracts will be shown to the user as raw addresses instead of recognizable labels. The change is framed as a cleanup to rely on an external registry rather than hardcoded names. It is not a direct security fix for a vulnerability, but it reduces the risk that a wrong or misleading hardcoded label could trick a user into trusting a malicious contract.

Recommended action

Treat as a hardening/cleanup change rather than an urgent vulnerability patch. Review whether the external ERC-7730 registry is now correctly populated with the removed names so users do not lose helpful context. Verify the translation signature update is legitimate and that no stale translation keys remain. Continue monitoring for the follow-up PR mentioned in the TODO to remove the remaining hardcoded WETH and Uniswap entries.

Security signals we found

01

Removal of hardcoded trust labels reduces attack surface for label-spoofing or stale-name confusion

02

User-visible display changes from friendly names to raw addresses for many DeFi contracts

03

No cryptographic, parsing, or memory-safety changes in the diff

04

TODO comment indicates remaining hardcoded entries are still planned for removal

05

Translations signature updated, suggesting the change affected user-facing strings

Risk score

Why this scored 24/100

Our methodology →
Potential impact 3/30
Exploitability 2/25
Stealth signal 4/15
Affected reach 5/15
Confidence 7/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.