Skip to content

[Bug]: Security: Metamask incorrectly converts funds into fiat on third-party networks to USD #17233

Open
@kladkogex

Description

@kladkogex

Describe the bug

We started seeing it a couple of months ago. Now it is happening all the time.

When you add a network to Metamask, metamask will interpret its native currency as mainnet ETH and start showing currency conversion into fiat.

I think it can be a pretty security vulnerability, since uses may be tricked into believing that hey have real fiat currency, where they really dont.

image

image

Steps to reproduce

  1. Create a custom blockchain with a custom chainID.

  2. Create an account on this blockchain with non-zero native native ETH value

  3. Import the account into Metamask. Metamask will start intertpreting

Error messages or log output

No response

Version

MetaMask Version 10.23.2

Build type

None

Browser

Chrome

Operating system

Ubuntu Linux 18/20/22

Hardware wallet

No response

Additional context

Happy to help debugging it.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    To be fixed

    Status

    To be triaged

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions