MetaMask / MetaMask/metamask-extension
MetaMask should filter dust transactions from address poisoning attacks
- Dominant language
- TypeScript
- Stars
- 13.2k
- Forks
- 5.6k
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 451
Description
### What is this about?
MetaMask should absolutely filter out dust transactions from address/history poisoning attacks.
Happens all the time: send some amount of ETH or USDC, less than a second later receive one gwei from a similar-looking address that closely resembles your destination.
I tried looking for a setting for this, without success. I refuse to believe MetaMask is vulnerable to this kind of attack in 2026, so please point me to the correct setting if there is one.
### Scenario
_No response_
### Design
_No response_
### Technical Details
_No response_
### Threat Modeling Framework
_No response_
### Acceptance Criteria
_No response_
### Stakeholder review needed before the work gets merged
- [ ] Engineering (needed in most cases)
- [ ] Design
- [ ] Product
- [ ] QA (automation tests are required to pass before merging PRs but not all changes are covered by automation tests - please review if QA is needed beyond automation tests)
- [ ] Security
- [ ] Legal
- [ ] Marketing
- [ ] Management (please specify)
- [ ] Other (please specify)
### References
_No response_
Contributor guide
Research direction
No source files, tests, entry points, design, threat model, or acceptance criteria are named. First clarify whether MetaMask should hide or otherwise filter one-gwei ETH or USDC transactions in address history, then locate the transaction-history implementation and define testable behavior for address-poisoning cases.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100