harden: a holders_count that is not plain digits is unknown, not read in part (closes #251)
parseHoldersCount used parseInt, which reads "1,000" as 1, "0x10" as 0 and "1e3" as 1: a reported low count, which hides the token in the transaction history and the send-screen token selector. It now accepts only a whole number of zero or more, or a string of digits alone, no larger than Number.MAX_SAFE_INTEGER, and returns null for anything else. The balance list's holders !== null check did nothing, since null >= 1000 is already false, and is dropped. README.md and docs/README.md say how each filter treats an unknown count and that the token screen then leaves out its Holders row; README.md lists src/shared/holders.js. Model: opus-5-5
This commit was merged in pull request #445.
This commit is contained in:
@@ -695,6 +695,7 @@ src/
|
||||
balances.js — ETH + ERC-20 balance fetching via RPC + Blockscout
|
||||
constants.js — chain IDs, default RPC endpoint, ERC-20 ABI
|
||||
ens.js — ENS forward/reverse resolution (popup only)
|
||||
holders.js — holder-count parsing and the low-holder rule
|
||||
prices.js — ETH/USD and token/USD via CoinDesk API
|
||||
scamlist.js — known fraud contract addresses
|
||||
state.js — persisted state (extension storage)
|
||||
@@ -1123,13 +1124,18 @@ claiming a symbol that belongs to the native asset and therefore has no
|
||||
legitimate contract at all (`"ETH"`, and every network's `nativeCurrency`, such
|
||||
as `"SepoliaETH"`, on every network). That filter is unconditional — the "Hide
|
||||
tokens with fewer than 1,000 holders" setting governs the transaction history
|
||||
and the send-screen token selector, not this list. `fetchTokenBalances()` stores
|
||||
every nonzero holding of a token it admits, however small, but a holding below
|
||||
0.000001 is left out of the balance lists, the send-screen token selector, the
|
||||
address total and the remove-address warning (`isBelowOneMillionth()` in
|
||||
`src/shared/amountDisplay.js`). The Send and confirmation screens show it when
|
||||
its token is the one being sent. Tracked tokens with a zero balance are listed
|
||||
as well while "Show tracked tokens with zero balance" is on.
|
||||
and the send-screen token selector, not this list. A token's holder count is
|
||||
unknown when the explorer reports none, or reports anything other than a whole
|
||||
number written in digits alone, such as `1,000` or `1e3` (`parseHoldersCount()`
|
||||
in `src/shared/holders.js`). This list does not take an unknown count as 1,000
|
||||
or more, so such a token is shown only when it is on the bundled list or
|
||||
tracked. `fetchTokenBalances()` stores every nonzero holding of a token it
|
||||
admits, however small, but a holding below 0.000001 is left out of the balance
|
||||
lists, the send-screen token selector, the address total and the remove-address
|
||||
warning (`isBelowOneMillionth()` in `src/shared/amountDisplay.js`). The Send and
|
||||
confirmation screens show it when its token is the one being sent. Tracked
|
||||
tokens with a zero balance are listed as well while "Show tracked tokens with
|
||||
zero balance" is on.
|
||||
|
||||
#### Stored state and its version
|
||||
|
||||
@@ -1438,7 +1444,9 @@ view would leave a wallet one click from deletion.
|
||||
- Send / Receive buttons
|
||||
- Token contract well (ERC-20 only): full contract address (tap to copy,
|
||||
etherscan link) plus name, symbol, decimals, holder count and project
|
||||
website where known
|
||||
website where known. The "Holders:" row is left out, not shown as 0, when
|
||||
the token's balance-list entry has no holder count: the explorer did not
|
||||
report a readable one, or the token is not in the balance list
|
||||
- Token-filtered transaction list (only this token's transfers)
|
||||
- **Transitions**:
|
||||
- "Send" → **Send** (token locked: the dropdown is replaced by a static
|
||||
@@ -2389,7 +2397,8 @@ indexes it as a real token transfer.
|
||||
fewer than 1,000 holders are hidden from transaction history by default.
|
||||
Legitimate tokens have substantial holder counts; poisoning tokens typically
|
||||
have zero. This catches new poisoning contracts that use novel symbols not in
|
||||
the known token list.
|
||||
the known token list. A transfer whose token's holder count is unknown (see
|
||||
Data Model) is kept: only a reported count below 1,000 hides it.
|
||||
|
||||
- **Fraud contract blocklist**: AutistMask maintains a local list of known fraud
|
||||
contract addresses. Token transfers involving these contracts are filtered
|
||||
@@ -2399,7 +2408,9 @@ indexes it as a real token transfer.
|
||||
- **Send-side token filtering**: Tokens with fewer than 1,000 holders are
|
||||
excluded from the token selector on the send screen. This prevents users from
|
||||
accidentally interacting with a spoofed token that appeared in their balance
|
||||
via a fake Transfer event.
|
||||
via a fake Transfer event. A token whose holder count is unknown is kept in
|
||||
the selector. The selector offers only tokens in the balance list, so such a
|
||||
token is one on the bundled list or one the user tracks.
|
||||
|
||||
- **Dust transaction filtering**: A second wave of the same attack used real
|
||||
native ETH transfers instead of fake tokens. Transaction
|
||||
@@ -2423,8 +2434,9 @@ indexes it as a real token transfer.
|
||||
both cases identically to the history. The fraud contract blocklist is applied
|
||||
unconditionally on that selector and is not consulted by the balance list at
|
||||
all. The low-holder setting also gates the send selector, while the balance
|
||||
list's own 1,000-holder floor is unconditional (see Data Model). The dust
|
||||
threshold applies to the transaction history alone.
|
||||
list's own 1,000-holder floor is unconditional (see Data Model). An unknown
|
||||
holder count passes the history and send-selector filters but not that floor.
|
||||
The dust threshold applies to the transaction history alone.
|
||||
|
||||
#### Phishing Domain Protection
|
||||
|
||||
|
||||
Reference in New Issue
Block a user