MetaMask / MetaMask/metamask-extension

False positive: Blockaid "Malicious site" warning persists on presale.hyvechain.com after Blockaid confirmed removal

Open
#43,118 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

external-contributor
Dominant language
TypeScript
Stars
13.2k
Forks
5.6k
Avg merge
2d 5h
Merged PRs (30d)
451

Description

What is this about?

Hi MetaMask team,

This is not a code bug — it's a false-positive security warning that
persists in MetaMask after the underlying provider (Blockaid) has
confirmed removal on their side. Filing here because Blockaid support
directed us to contact MetaMask directly.

Summary

MetaMask shows a red "Malicious site — This has been identified as
malicious" warning at the transaction confirmation step when users try
to participate in our presale. The popup indicates "1 of 2" alerts,
meaning two separate signals are firing.

Details

  • Domain: presale.hyvechain.com
  • Root domain: hyvechain.com
  • Chain: BNB Smart Chain (BSC)
  • Destination address: 0xc0484ce15f4982b0d8bc11df99cb54990e2fd7c0
    (project multisig — the presale is a direct
    BNB transfer to this address, not a smart
    contract interaction)

What we've already done

  • Disputed the domain with Blockaid; they confirmed removal.
  • Followed up after 48+ hours when warning persisted; Blockaid
    re-confirmed the domain flag is removed and advised us to contact
    MetaMask.
  • Now following up with Blockaid separately about the multisig
    address, since two alerts are firing and they may only have
    removed the domain flag.
  • Cross-checked all other lists via ChainPatrol:
    https://app.chainpatrol.io/search?content=presale.hyvechain.com
    All providers (ChainPatrol, MetaMask/eth-phishing-detect, SEAL-ISAC,
    Polkadot Phishing) return "Unknown" / no evidence of malicious
    activity.

Questions for the MetaMask team

  1. Is MetaMask's Security Alerts feature serving a cached Blockaid
    response? If so, what's the cache TTL and how can we force a
    refresh once Blockaid clears a flag?
  2. The popup shows "1 of 2" alerts. What is the second signal source?
    Is it also Blockaid (address vs. domain), or a different provider
    we need to contact?
  3. Anything we need to do on our side (domain verification, etc.) to
    expedite the clear-through?

Environment

  • MetaMask extension version: 12.10.1
  • Browser: Chrome 126.0.6478.127
Image
  • OS: Windows 11
  • Affecting: all users attempting the presale buy

Screenshot of the warning attached.

Thank you for any help — this is actively blocking users from our
presale.


Contact:

  • Email: tlon@hyvechain.com
  • Project: Hyve Chain
  • Site: hyvechain.com
Scenario

Hi MetaMask team,

This is not a code bug — it's a false-positive security warning that
persists in MetaMask after the underlying provider (Blockaid) has
confirmed removal on their side. Filing here because Blockaid support
directed us to contact MetaMask directly.

Summary

MetaMask shows a red "Malicious site — This has been identified as
malicious" warning at the transaction confirmation step when users try
to participate in our presale. The popup indicates "1 of 2" alerts,
meaning two separate signals are firing.

Details

  • Domain: presale.hyvechain.com
  • Root domain: hyvechain.com
  • Chain: BNB Smart Chain (BSC)
  • Destination address: 0xc0484ce15f4982b0d8bc11df99cb54990e2fd7c0
    (project multisig — the presale is a direct
    BNB transfer to this address, not a smart
    contract interaction)

What we've already done

  • Disputed the domain with Blockaid; they confirmed removal.
  • Followed up after 48+ hours when warning persisted; Blockaid
    re-confirmed the domain flag is removed and advised us to contact
    MetaMask.
  • Now following up with Blockaid separately about the multisig
    address, since two alerts are firing and they may only have
    removed the domain flag.
  • Cross-checked all other lists via ChainPatrol:
    https://app.chainpatrol.io/search?content=presale.hyvechain.com
    All providers (ChainPatrol, MetaMask/eth-phishing-detect, SEAL-ISAC,
    Polkadot Phishing) return "Unknown" / no evidence of malicious
    activity.

Questions for the MetaMask team

  1. Is MetaMask's Security Alerts feature serving a cached Blockaid
    response? If so, what's the cache TTL and how can we force a
    refresh once Blockaid clears a flag?
  2. The popup shows "1 of 2" alerts. What is the second signal source?
    Is it also Blockaid (address vs. domain), or a different provider
    we need to contact?
  3. Anything we need to do on our side (domain verification, etc.) to
    expedite the clear-through?

Environment

  • MetaMask extension version: 12.10.1
  • Browser: Chrome 126.0.6478.127
Image
  • OS: Windows 11
  • Affecting: all users attempting the presale buy

Screenshot of the warning attached.

Thank you for any help — this is actively blocking users from our
presale.


Contact:

  • Email: tlon@hyvechain.com
  • Project: Hyve Chain
  • Site: hyvechain.com
Design

No response

Technical Details

No response

Threat Modeling Framework

No response

Acceptance Criteria

No response

Stakeholder review needed before the work gets merged
  • Engineering (needed in most cases)
  • Design
  • Product
  • QA (automation tests are required to pass before merging PRs but not all changes are covered by automation tests - please review if QA is needed beyond automation tests)
  • Security
  • Legal
  • Marketing
  • Management (please specify)
  • Other (please specify)
References
Image

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the Security Alerts integration with Blockaid and tracing how domain and destination-address signals are combined or cached. Confirm the source of both alerts and whether cleared provider results reach MetaMask; the issue provides no file, test, or acceptance criteria, so resolution would require investigation and coordination rather than a defined edit.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.