AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 36 Bitcoin

feat(ethereum): Unknown vaults fetch relevant token defintion from host

Public commit record

What the developer wrote

Authored by PrisionMike

62/100 · Adequate
feat(ethereum): Unknown vaults fetch relevant token defintion from host
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
The short version

What changed, and why it matters

This commit changes how Trezor handles Ethereum 'vault' transactions (like deposits and withdrawals from yield-bearing token vaults). Previously, the device only supported a fixed list of known vaults and rejected or blindly signed unknown ones. Now, for unknown vaults, it asks the connected computer (host) for token and display definitions so it can show clearer signing information. The change also removes a hard safety check that rejected transactions where the receiver or owner did not match the signer for known vaults, and instead lets the UI display the receiver/owner explicitly. This is a feature addition, but it introduces new trust in host-provided data and relaxes a previously strict safety rule.

Recommended action

Review the new host-provided definition handling paths for input validation and ensure that malicious or malformed ERC-7730 display formats and token definitions cannot cause incorrect amount formatting, token misidentification, or UI spoofing. Re-assess whether removing the hard `_is_vault_tx_safe` check for known vaults is acceptable given the new UI warnings, and verify that the UI actually requires user confirmation of non-matching receiver/owner addresses before signing.

Security signals we found

01

Removal of `_is_vault_tx_safe` strict signer/receiver/owner equality check for known vaults

02

Introduction of host-fetched token and display definitions for unknown vaults (`request_definitions`, `find_display_format`)

03

New parsing of external display format to extract `const_token_address` for asset token resolution

04

UI now surfaces receiver and owner addresses when they differ from sender, rather than hard-failing

05

Type narrowing from `AnyBytes` to `bytes` in several function signatures

Risk score

Why this scored 36/100

Our methodology →
Potential impact 8/30
Exploitability 7/25
Stealth signal 6/15
Affected reach 7/15
Confidence 5/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.