What changed, and why it matters
This commit removes built-in 'clear signing' support for the 1inch decentralized exchange from Trezor Ethereum firmware. Clear signing makes complex crypto transactions easier to read and verify on the device screen. Removing it does not create a new security hole, but users interacting with 1inch will now see less human-readable transaction details, which can make it harder to spot malicious or mistaken transactions. It is a feature rollback, not a vulnerability fix.
No immediate security action required. If 1inch support is intended to return, review the reintroduced clear-signing definitions for correctness and ensure non-standard parameters are parsed safely rather than displayed as raw hex. Monitor Trezor communications for any stated reason for the removal.
Security signals we found
Removal of human-readable transaction decoding for a specific DeFi protocol
No changes to signature, validation, or access-control logic
No mention of vulnerability, bug, or security issue in commit message
No advisory or CVE references present in commit or supplied materials
Evidence from the diff
The patch deletes 1inch-specific DisplayFormat definitions and the RawBytesFormatter helper used to render non-standard 1inch calldata fields, plus corresponding test fixtures. The remaining clear-signing framework and other protocol definitions (e.g., LiFi) stay intact. There is no change to transaction validation, signing cryptography, or address checks. The commit message is a routine ‘chore’ with ‘[no changelog]’.
Changed components
core/src/apps/ethereum/clear_signing.pycore/src/apps/ethereum/clear_signing_definitions.pycommon/tests/fixtures/ethereum/sign_tx_clear_signing.jsonInspect captured patch +0 / −217
diff --git a/common/tests/fixtures/ethereum/sign_tx_clear_signing.json b/common/tests/fixtures/ethereum/sign_tx_clear_signing.json
index 5a285355..989941d3 100644
--- a/common/tests/fixtures/ethereum/sign_tx_clear_signing.json
+++ b/common/tests/fixtures/ethereum/sign_tx_clear_signing.json
@@ -4,66 +4,6 @@
"passphrase": ""
},
"tests": [
- {
- "name": "clear_sign_1inch_swap",
- "parameters": {
- "comment": "https://etherscan.io/tx/0x2c18175d5bf78e80892b21896b00eb27bf07ff5948b4be1e56038d8ba7266950",
- "data": "07ed2379000000000000000000000000990636ecb3ff04d33d92e970d3d588bf5cd8d086000000000000000000000000f0db65d17e30a966c2ae6a21f6bba71cea6e97540000000000000000000000002260fac5e5542a773aa44fbcfedf7c193bc2c599000000000000000000000000990636ecb3ff04d33d92e970d3d588bf5cd8d086000000000000000000000000459e213d8b5e79d706ab22b945e3af983d51bc4c000000000000000000000000000000000000000000000071003fa9d87dc2000000000000000000000000000000000000000000000000000000000000002de7410000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000012000000000000000000000000000000000000000000000000000000000000009f90000000000000000000000000000000000000009db0009ad00096300004e00a0744c8c09f0db65d17e30a966c2ae6a21f6bba71cea6e975490cbe4bdd538d6e9b379bff5fe72c3d67a521de500000000000000000000000000000000000000000000000005c9205756dc400000a098aed105000000000000000000000000000000007d007d000000000000000000000000000000000000000000000000000008dd00055200a007e5c0d200000000000000000000000000000000000000000000000000052e0002105120111111125421ca6dc452d289314280a0f8842a65f0db65d17e30a966c2ae6a21f6bba71cea6e97540124cc713a04811642c03b93bb3fe7905266a4a3c300713f97460272be5479f22777c211dc84000000000000000000000000bee3211ab312a8d065c4fef0247448e17a8da0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000dac17f958d2ee523a2206206994597c13d831ec7000000000000000000000000f0db65d17e30a966c2ae6a21f6bba71cea6e97540000000000000000000000000000000000000000000000000000000042b7e1d80000000000000000000000000000000000000000000000387d3b44c09372e00000000000000000000000000000000b2ddf0069ba7c5fe970d3d588bf5cd8d08600000000000000000000000000000000000000000000000000000000000001600000000000000000000000000000000000000000000000000000000000000000200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000414d00e9e0bed4d42074ef1786b2114d6a211ebe817c429c7da3c74105147d9a6b29dc0d7f1173a1fa5cb0460dc44b5b27946af164e156c5ec48d5d622d805a32b1c0000000000000000000000000000000000000000000000000000000000000000a098aed105000000000000000000000000000000001900e1000000000000000000000000000000000000000000000000000002e600028300a007e5c0d200000000000000000000000000000000000000000000000000025f0002105120111111125421ca6dc452d289314280a0f8842a65dac17f958d2ee523a2206206994597c13d831ec70124cc713a04688f385930a2a67070dc9b52a7b7ec4a955a110b038bd16cfe78e8806dfddd41000000000000000000000000bee3211ab312a8d065c4fef0247448e17a8da00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001f9840a85d5af5bf1d1762f925bdaddc4201f984000000000000000000000000dac17f958d2ee523a2206206994597c13d831ec700000000000000000000000000000000000000000000000de14077278f7ac8b1000000000000000000000000000000000000000000000000000000003c15454d00000000000000000000000000000b2ddd0069ba7c5fe970d3d588bf5cd8d0860000000000000000000000000000000000000000000000000000000000000160000000000000000000000000000000000000000000000000000000000000000020000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000041865a01e3afd96eb104a6d0017d9aa335a46fcc7a1f580b9155188c0176826a7a77c2be7695916dff5bf595519ee67a0966ab1769e792231b4482f5aa4dbd28b11b0000000000000000000000000000000000000000000000000000000000000002a00000000000000000000000000000000000000000000000000000000000148da1ee63c1e5018f0cb37cdff37e004e0088f563e5fe39e05ccc5b1f9840a85d5af5bf1d1762f925bdaddc4201f9840ca0dac17f958d2ee523a2206206994597c13d831ec7d343d5dba2fba55eef58189619c05e33cab95ca1c028b46d03d343d5dba2fba55eef58189619c05e33cab95ca100000000000000000000000000000000000000000000000000000000000248ad00a007e5c0d20000000000000000000000000000000000000000000000000003670002105120111111125421ca6dc452d289314280a0f8842a65f0db65d17e30a966c2ae6a21f6bba71cea6e97540124cc713a04cfca011b8564e7bcc6a9792b8226a4d16ef853e2c19b5f691e66ca8a51a1a8d8000000000000000000000000bee3211ab312a8d065c4fef0247448e17a8da0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000c02aaa39b223fe8d0a0e5c4f27ead9083c756cc2000000000000000000000000f0db65d17e30a966c2ae6a21f6bba71cea6e975400000000000000000000000000000000000000000000000006ab4ca90f5ac5130000000000000000000000000000000000000000000000387d3b44c09372e00000000000000000000000000000000b2ddc0069ba7c5fe970d3d588bf5cd8d08600000000000000000000000000000000000000000000000000000000000001600000000000000000000000000000000000000000000000000000000000000000200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000411413c544e6473def8c4117d32d94db118aae69af01206f12c03f5d246770f41f3ab0cd7a076365d405e4cc96314b7d51522995909055ede938bb3e3db82fb82b1b0000000000000000000000000000000000000000000000000000000000000000a0c9e75c4800000000000000000000000000000000004d001700000000000000000000000000000000000000000000000000011f00004f02a000000000000000000000000000000000000000000000000000000000000540abee63c1e500e6ff8b9a37b0fab776134636d9981aa778c4e718c02aaa39b223fe8d0a0e5c4f27ead9083c756cc251207f86bf177dd4f3494b841a37e810a34dd56c829bc02aaa39b223fe8d0a0e5c4f27ead9083c756cc20044394747c5000000000000000000000000000000000000000000000000000000000000000200000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000011953a000000000000000000000000000000000000000000000000000000000000000000a0f2fa6b662260fac5e5542a773aa44fbcfedf7c193bc2c59900000000000000000000000000000000000000000000000000000000002e224f00000000000000000000000000001a6380a06c4eca272260fac5e5542a773aa44fbcfedf7c193bc2c599111111125421ca6dc452d289314280a0f8842a6500000000000000d1f115cb",
- "path": "m/44'/60'/0'/0/1",
- "to_address": "0x111111125421cA6dc452d289314280a0f8842A65",
- "chain_id": 1,
- "nonce": "0x0",
- "gas_price": "0x14",
- "gas_limit": "0x14",
- "tx_type": null,
- "value": "0x0"
- },
- "result": {
- "sig_v": 38,
- "sig_r": "09a0efb1b7d948ec2be62ff43d9d9282df83d445060de95c44db5067cf9e81bd",
- "sig_s": "248ffd5f122ddb1eddd41331e28e86f171f2032bbe93ea5e75eaef2262c475d5"
- }
- },
- {
- "name": "clear_sign_1inch_unoswap",
- "parameters": {
- "comment": "https://etherscan.io/tx/0x772f2a3302ff43260dd22c69b740597c0de9434821ddcdce10e42c253815edf6",
- "data": "83800a8e000000000000000000000000c02aaa39b223fe8d0a0e5c4f27ead9083c756cc2000000000000000000000000000000000000000000000000016345785d8a000000000000000000000000000000000000000000000000017cff16da2c808f348e280000000000000000000000d3e9895230e8fb1460852f6cda3c4b926fbc29d8fb39cfb5",
- "path": "m/44'/60'/0'/0/1",
- "to_address": "0x111111125421cA6dc452d289314280a0f8842A65",
- "chain_id": 1,
- "nonce": "0x0",
- "gas_price": "0x14",
- "gas_limit": "0x14",
- "tx_type": null,
- "value": "0x0"
- },
- "result": {
- "sig_v": 38,
- "sig_r": "f39ecdd11c46c8743385f5a20051268b1a37a56e7a981a616b83264375a4bbf8",
- "sig_s": "35c18ed7ce660021551239b3b1746d1947acff335b89ee1c249835ebf732dc8f"
- }
- },
- {
- "name": "clear_sign_1inch_unoswapTo",
- "parameters": {
- "comment": "https://etherscan.io/tx/0xa3e7acb0c5702b9ae0ba93224ed9d51b4c827f3295c35c93b74e1d9b169dca6b",
- "data": "e2c95c82000000000000000000000000d862cdcfeb856c32b3c4f7563f4811d8ddfd42e2000000000000000000000000c02aaa39b223fe8d0a0e5c4f27ead9083c756cc20000000000000000000000000000000000000000000000000188932d0c201ca000000000000000000000000000000000000000000000000000c7c88c3b9a9b6d08000000000000003b6d03405c6919b79fac1c3555675ae59a9ac2484f3972f51e6abebb",
- "path": "m/44'/60'/0'/0/1",
- "to_address": "0x111111125421cA6dc452d289314280a0f8842A65",
- "chain_id": 1,
- "nonce": "0x0",
- "gas_price": "0x14",
- "gas_limit": "0x14",
- "tx_type": null,
- "value": "0x0"
- },
- "result": {
- "sig_v": 37,
- "sig_r": "d827ffec9e1ed6ee3c256b8e8ba1528d317f5f4005df46c7aae142862184f10c",
- "sig_s": "377c9b3df8b23f30e8e8fad1bd4fb12a0972b35da9ab9a3460873fa02afc7d7f"
- }
- },
{
"name": "clear_sign_lifi_swapTokensMultipleV3ERC20ToERC20",
"parameters": {
diff --git a/core/src/apps/ethereum/clear_signing.py b/core/src/apps/ethereum/clear_signing.py
index dc3ccd25..c3e6dc90 100644
--- a/core/src/apps/ethereum/clear_signing.py
+++ b/core/src/apps/ethereum/clear_signing.py
@@ -278,27 +278,6 @@ class UnitFormatter(FieldFormatter):
return f"{significand:g}{prefix_symbol}{self.base}", None, None
-class RawBytesFormatter(FieldFormatter):
- """HACK: this is currently used to just dump some parameters
- that encode more information in non-standard ways (see unoswap and unoswapTo from 1inch).
- """
-
- def format(
- self,
- raw_value: AnyValue,
- _definitions: Definitions,
- _token: EthereumTokenInfo,
- _path_Walker: PathWalker,
- ) -> tuple[str | None, EthereumTokenInfo | None, bytes | None]:
- if raw_value is None:
- return None, None, None
- else:
- if not isinstance(raw_value, bytes):
- raise InvalidFormatDefinition
-
- return hexlify(raw_value).decode(), None, None
-
-
# https://eips.ethereum.org/EIPS/eip-7730#context-section
diff --git a/core/src/apps/ethereum/clear_signing_definitions.py b/core/src/apps/ethereum/clear_signing_definitions.py
index 3c8fec38..1ee6336b 100644
--- a/core/src/apps/ethereum/clear_signing_definitions.py
+++ b/core/src/apps/ethereum/clear_signing_definitions.py
@@ -13,7 +13,6 @@ from .clear_signing import (
DisplayFormat,
Dynamic,
FieldDefinition,
- RawBytesFormatter,
Struct,
TokenAmountFormatter,
UnitFormatter,
@@ -85,141 +84,6 @@ ONEINCH_CHAINS = [
]
ONEINCH_OWNER = "1inch Aggregation Router V6"
-# https://github.com/LedgerHQ/clear-signing-erc7730-registry/blob/master/registry/1inch/calldata-AggregationRouterV5.json
-
-ONEINCH_CONTEXT = BindingContext(
- [(chain, ONEINCH_ADDRESS) for chain in ONEINCH_CHAINS],
-)
-
-ALL_DISPLAY_FORMATS.extend(
- [
- DisplayFormat(
- binding_context=ONEINCH_CONTEXT,
- func_sig=unhexlify(
- "07ed2379"
- ), # swap(address executor, (address srcToken, address dstToken, address srcReceiver, address dstReceiver, uint256 amount, uint256 minReturnAmount, uint256 flags) desc, bytes permit, bytes data)
- intent="Swap",
- parameter_definitions=[
- Atomic(parse_address), # executor
- Struct(
- (
- parse_address, # srcToken
- parse_address, # dstToken
- parse_address, # srcReceiver
- parse_address, # dstReceiver
- parse_uint256, # amount
- parse_uint256, # minReturnAmount
- parse_uint256, # flags
- ),
- is_dynamic=False,
- ), # desc
- Dynamic(parse_bytes), # permit
- Dynamic(parse_bytes), # data
- ],
- field_definitions=[
- FieldDefinition(
- (1, 4), # desc.amount
- "Amount to Send",
- TokenAmountFormatter(
- token_path=(1, 0), # desc.srcToken
- ),
- ),
- FieldDefinition(
- (1, 5), # desc.minReturnAmount
- "Minimum to Receive",
- TokenAmountFormatter(
- token_path=(1, 1), # desc.dstToken
- ),
- ),
- FieldDefinition(
- (1, 3), "Beneficiary", AddressNameFormatter # desc.dstReceiver
- ),
- ],
- ),
- DisplayFormat(
- binding_context=ONEINCH_CONTEXT,
- func_sig=unhexlify(
- "83800a8e"
- ), # unoswap(address srcToken, uint256 amount, uint256 minReturn, bytes pools)
- intent="Swap",
- parameter_definitions=[
- Atomic(parse_address), # srcToken
- Atomic(parse_uint256), # amount
- Atomic(parse_uint256), # minReturn
- Atomic(parse_bytes), # pools
- ],
- field_definitions=[
- FieldDefinition(
- (1,), # amount
- "Amount to Send",
- TokenAmountFormatter(
- token_path=(0,), # srcToken
- ),
- ),
- FieldDefinition(
- (2,), # minReturn
- "Minimum to Receive",
- TokenAmountFormatter,
- ),
- FieldDefinition(
- ContainerPath.From, # @.from
- "Beneficiary",
- AddressNameFormatter,
- ),
- FieldDefinition(
- (3,), # pools
- "Pools (hex)",
- # HACK: this parameter encodes data in a non-standard way
- # in order to extract human readable data from it,
- # we would need to parse this further
- RawBytesFormatter,
- ),
- ],
- ),
- DisplayFormat(
- binding_context=ONEINCH_CONTEXT,
- func_sig=unhexlify(
- "e2c95c82"
- ), # unoswapTo(address recipient, address srcToken, uint256 amount, uint256 minReturn, bytes pools)
- intent="Swap",
- parameter_definitions=[
- Atomic(parse_address), # recipient
- Atomic(parse_address), # srcToken
- Atomic(parse_uint256), # amount
- Atomic(parse_uint256), # minReturn
- Atomic(parse_bytes), # pools
- ],
- field_definitions=[
- FieldDefinition(
- (2,), # amount
- "Amount to Send",
- TokenAmountFormatter(
- token_path=(1,), # srcToken
- ),
- ),
- FieldDefinition(
- (3,), # minReturn
- "Minimum to Receive",
- TokenAmountFormatter,
- ),
- FieldDefinition(
- (0,), # recipient
- "Beneficiary",
- AddressNameFormatter,
- ),
- FieldDefinition(
- (4,), # pools
- "Pools (hex)",
- # HACK: this parameter encodes data in a non-standard way
- # in order to extract human readable data from it,
- # we would need to parse this further
- RawBytesFormatter,
- ),
- ],
- ),
- ]
-)
-
# https://github.com/LedgerHQ/clear-signing-erc7730-registry/blob/master/registry/lifi/calldata-LIFIDiamond.json
LIFI_ADDRESS = unhexlify("1231DEB6f5749EF6cE6943a275A1D3E7486F4EaE")
LIFI_CHAINS = [
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.