MetaMask / MetaMask/metamask-extension

Remove Blockaid. As currently implemented, it is lying to users.

Open
#35,000 17 comments 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

external-contributor INVALID-ISSUE-TEMPLATE team-product-safety
Dominant language
TypeScript
Stars
13.2k
Forks
5.6k
Avg merge
2d 5h
Merged PRs (30d)
451

Description

**What is this about?**

Blockaid is reporting brand new contracts deployed by anyone as "known for scams". Attempting to report the false positive to Blockaid results in them requiring you to prove your contract's innocence before they will whitelist it. While I can appreciate wanting to protect users, it goes against the whole ethos of crypto to create a walled garden that classifies every builder a scammer until they prove themselves innocent.

If they were just saying, "this contract has not been independently audited by Blockaid" that would be more reasonable, but instead what they are doing is flagging brand new contracts from legitimate sources (like myself) as scams.

Blockaid should be removed from MetaMask to send a clear message to them that this sort of behavior is unacceptable on Ethereum. We are trying to build an open ecosystem that welcomes new developers, not one that calls everyone who shows up a scammer.

Here are some people reporting the issue to MetaMask, who knows how many others have had their new contracts flagged as "definitely malicious" when they simply weren't manually verified by anyone at Blockaid yet.

https://github.com/MetaMask/metamask-extension/issues/34283
https://github.com/MetaMask/metamask-extension/issues/33835
https://github.com/MetaMask/metamask-extension/issues/30960
https://github.com/MetaMask/metamask-extension/issues/32721
https://github.com/MetaMask/metamask-extension/issues/25016
https://github.com/MetaMask/metamask-extension/issues/23854
https://github.com/MetaMask/metamask-extension/issues/23845
https://github.com/MetaMask/metamask-extension/issues/23752
https://github.com/MetaMask/metamask-extension/issues/23363
https://github.com/MetaMask/metamask-extension/issues/22062

**Stakeholder review needed before the work gets merged**

- [ ] Engineering (needed in most cases)
- [ ] Design
- [ ] Product
- [ ] QA (automation tests are required to pass before merging PRs but not all changes are covered by automation tests - please review if QA is needed beyond automation tests)
- [ ] Security
- [ ] Legal
- [ ] Marketing
- [ ] Management (please specify)
- [ ] Other (please specify)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the existing Blockaid integration in the MetaMask extension and read the linked reports to understand the false-positive behavior. Confirm the removal scope with the required stakeholder reviews; done means Blockaid no longer classifies contracts in the extension and the relevant automated tests pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.