Compare commits

..

1 Commits

Author SHA1 Message Date
user
34c23bdc01 feat: warn when sending to address with zero tx history (#82)
All checks were successful
check / check (push) Successful in 9s
On the confirm-tx screen, asynchronously check the recipient address
via Blockscout API. If the address has never sent or received any
transactions, display a prominent red warning banner.

Closes #82
2026-02-28 14:55:00 -08:00
2 changed files with 47 additions and 43 deletions

View File

@@ -25,7 +25,7 @@ const { decryptWithPassword } = require("../../shared/vault");
const { formatUsd, getPrice } = require("../../shared/prices"); const { formatUsd, getPrice } = require("../../shared/prices");
const { getProvider } = require("../../shared/balances"); const { getProvider } = require("../../shared/balances");
const { isScamAddress } = require("../../shared/scamlist"); const { isScamAddress } = require("../../shared/scamlist");
const { hasZeroTransactionHistory } = require("../../shared/transactions"); const { hasTransactionHistory } = require("../../shared/transactions");
const { ERC20_ABI } = require("../../shared/constants"); const { ERC20_ABI } = require("../../shared/constants");
const { log } = require("../../shared/log"); const { log } = require("../../shared/log");
const makeBlockie = require("ethereum-blockies-base64"); const makeBlockie = require("ethereum-blockies-base64");
@@ -289,20 +289,28 @@ async function estimateGas(txInfo) {
} }
async function checkRecipientHistory(txInfo) { async function checkRecipientHistory(txInfo) {
const isNew = await hasZeroTransactionHistory( try {
const hasHistory = await hasTransactionHistory(
txInfo.to, txInfo.to,
state.blockscoutUrl, state.blockscoutUrl,
); );
if (!isNew) return; if (hasHistory === false) {
const warningsEl = $("confirm-warnings"); const warningsEl = $("confirm-warnings");
const warningHtml = const warningDiv = document.createElement("div");
`<div class="border border-red-500 border-dashed p-2 mb-1 text-xs font-bold text-red-500">` + warningDiv.className =
`WARNING: This address has ZERO transaction history. ` + "border border-dashed p-2 mb-1 text-xs font-bold";
`It has never sent or received any funds. ` + warningDiv.style.color = "#dc2626";
`Double-check the address before sending.</div>`; warningDiv.style.borderColor = "#dc2626";
warningsEl.innerHTML = warningHtml + warningsEl.innerHTML; warningDiv.textContent =
"WARNING: This address has ZERO transaction history on-chain. " +
"It has never sent or received any transactions. " +
"Double-check the address before sending.";
warningsEl.appendChild(warningDiv);
warningsEl.classList.remove("hidden"); warningsEl.classList.remove("hidden");
}
} catch (e) {
log.errorf("recipient history check failed:", e.message);
}
} }
function init(ctx) { function init(ctx) {

View File

@@ -251,40 +251,36 @@ function filterTransactions(txs, filters = {}) {
return { transactions: filtered, newFraudContracts: newFraud }; return { transactions: filtered, newFraudContracts: newFraud };
} }
/** async function hasTransactionHistory(address, blockscoutUrl) {
* Check whether an address has any on-chain transaction history.
* Returns true if the address has zero normal transactions AND zero
* token transfers on the configured Blockscout instance.
* Returns false on network errors (fail-open: don't block sends).
*/
async function hasZeroTransactionHistory(address, blockscoutUrl) {
try { try {
const resp = await debugFetch( const resp = await debugFetch(blockscoutUrl + "/addresses/" + address);
blockscoutUrl + "/addresses/" + address + "/transactions?limit=1", if (!resp.ok) {
// If Blockscout returns 404, the address has never been seen on-chain.
if (resp.status === 404) return false;
log.errorf(
"blockscout address check:",
resp.status,
resp.statusText,
); );
if (!resp.ok) return false; return null; // unknown
const json = await resp.json(); }
if ((json.items || []).length > 0) return false; const data = await resp.json();
// Blockscout v2 address endpoint returns tx counts.
// Also check token transfers — an address may have only received // An address with no history may still exist (e.g. received ETH once
// ERC-20 tokens without any native ETH transactions. // but shows 0 outgoing). We check both transactions_count and
const ttResp = await debugFetch( // token_transfers_count to be thorough.
blockscoutUrl + const txCount =
"/addresses/" + (parseInt(data.transactions_count, 10) || 0) +
address + (parseInt(data.token_transfers_count, 10) || 0);
"/token-transfers?type=ERC-20&limit=1", return txCount > 0;
);
if (!ttResp.ok) return false;
const ttJson = await ttResp.json();
return (ttJson.items || []).length === 0;
} catch (e) { } catch (e) {
log.errorf("hasZeroTransactionHistory check failed:", e.message); log.errorf("hasTransactionHistory error:", e.message);
return false; return null; // unknown, don't block the user
} }
} }
module.exports = { module.exports = {
fetchRecentTransactions, fetchRecentTransactions,
filterTransactions, filterTransactions,
hasZeroTransactionHistory, hasTransactionHistory,
}; };