MetaMask / MetaMask/metamask-extension
False positive: Blockaid "Malicious site" warning persists on presale.hyvechain.com after Blockaid confirmed removal
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 13.2k
- Forks
- 5.6k
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 451
Description
What is this about?
Hi MetaMask team,
This is not a code bug — it's a false-positive security warning that
persists in MetaMask after the underlying provider (Blockaid) has
confirmed removal on their side. Filing here because Blockaid support
directed us to contact MetaMask directly.
Summary
MetaMask shows a red "Malicious site — This has been identified as
malicious" warning at the transaction confirmation step when users try
to participate in our presale. The popup indicates "1 of 2" alerts,
meaning two separate signals are firing.
Details
- Domain: presale.hyvechain.com
- Root domain: hyvechain.com
- Chain: BNB Smart Chain (BSC)
- Destination address: 0xc0484ce15f4982b0d8bc11df99cb54990e2fd7c0
(project multisig — the presale is a direct
BNB transfer to this address, not a smart
contract interaction)
What we've already done
- Disputed the domain with Blockaid; they confirmed removal.
- Followed up after 48+ hours when warning persisted; Blockaid
re-confirmed the domain flag is removed and advised us to contact
MetaMask. - Now following up with Blockaid separately about the multisig
address, since two alerts are firing and they may only have
removed the domain flag. - Cross-checked all other lists via ChainPatrol:
https://app.chainpatrol.io/search?content=presale.hyvechain.com
All providers (ChainPatrol, MetaMask/eth-phishing-detect, SEAL-ISAC,
Polkadot Phishing) return "Unknown" / no evidence of malicious
activity.
Questions for the MetaMask team
- Is MetaMask's Security Alerts feature serving a cached Blockaid
response? If so, what's the cache TTL and how can we force a
refresh once Blockaid clears a flag? - The popup shows "1 of 2" alerts. What is the second signal source?
Is it also Blockaid (address vs. domain), or a different provider
we need to contact? - Anything we need to do on our side (domain verification, etc.) to
expedite the clear-through?
Environment
- MetaMask extension version: 12.10.1
- Browser: Chrome 126.0.6478.127
- OS: Windows 11
- Affecting: all users attempting the presale buy
Screenshot of the warning attached.
Thank you for any help — this is actively blocking users from our
presale.
Contact:
- Email: tlon@hyvechain.com
- Project: Hyve Chain
- Site: hyvechain.com
Scenario
Hi MetaMask team,
This is not a code bug — it's a false-positive security warning that
persists in MetaMask after the underlying provider (Blockaid) has
confirmed removal on their side. Filing here because Blockaid support
directed us to contact MetaMask directly.
Summary
MetaMask shows a red "Malicious site — This has been identified as
malicious" warning at the transaction confirmation step when users try
to participate in our presale. The popup indicates "1 of 2" alerts,
meaning two separate signals are firing.
Details
- Domain: presale.hyvechain.com
- Root domain: hyvechain.com
- Chain: BNB Smart Chain (BSC)
- Destination address: 0xc0484ce15f4982b0d8bc11df99cb54990e2fd7c0
(project multisig — the presale is a direct
BNB transfer to this address, not a smart
contract interaction)
What we've already done
- Disputed the domain with Blockaid; they confirmed removal.
- Followed up after 48+ hours when warning persisted; Blockaid
re-confirmed the domain flag is removed and advised us to contact
MetaMask. - Now following up with Blockaid separately about the multisig
address, since two alerts are firing and they may only have
removed the domain flag. - Cross-checked all other lists via ChainPatrol:
https://app.chainpatrol.io/search?content=presale.hyvechain.com
All providers (ChainPatrol, MetaMask/eth-phishing-detect, SEAL-ISAC,
Polkadot Phishing) return "Unknown" / no evidence of malicious
activity.
Questions for the MetaMask team
- Is MetaMask's Security Alerts feature serving a cached Blockaid
response? If so, what's the cache TTL and how can we force a
refresh once Blockaid clears a flag? - The popup shows "1 of 2" alerts. What is the second signal source?
Is it also Blockaid (address vs. domain), or a different provider
we need to contact? - Anything we need to do on our side (domain verification, etc.) to
expedite the clear-through?
Environment
- MetaMask extension version: 12.10.1
- Browser: Chrome 126.0.6478.127
- OS: Windows 11
- Affecting: all users attempting the presale buy
Screenshot of the warning attached.
Thank you for any help — this is actively blocking users from our
presale.
Contact:
- Email: tlon@hyvechain.com
- Project: Hyve Chain
- Site: hyvechain.com
Design
No response
Technical Details
No response
Threat Modeling Framework
No response
Acceptance Criteria
No response
Stakeholder review needed before the work gets merged
- Engineering (needed in most cases)
- Design
- Product
- QA (automation tests are required to pass before merging PRs but not all changes are covered by automation tests - please review if QA is needed beyond automation tests)
- Security
- Legal
- Marketing
- Management (please specify)
- Other (please specify)
References
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating the Security Alerts integration with Blockaid and tracing how domain and destination-address signals are combined or cached. Confirm the source of both alerts and whether cleared provider results reach MetaMask; the issue provides no file, test, or acceptance criteria, so resolution would require investigation and coordination rather than a defined edit.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100