Skip to content

Hide unverified asset impersonators by default - #976

Open
Emelie-Dev wants to merge 9 commits into
Miracle656:mainfrom
Emelie-Dev:feat/730-hide-impersonating-assets
Open

Emelie-Dev wants to merge 9 commits into
Miracle656:mainfrom
Emelie-Dev:feat/730-hide-impersonating-assets

Conversation

@Emelie-Dev

Copy link
Copy Markdown
Contributor

Pull Request for Veil - Close Issue

❗ Pull Request Information

Improve asset visibility and safety by separating verified and unverified assets, while explicitly identifying unverified assets that impersonate registered assets. Users can still expand the unverified section to view every asset held in their wallet.

🌀 Summary of Changes

  • Asset grouping: Group wallet balances into Verified and Unverified sections.
  • Unverified assets: Keep unverified assets collapsed by default and display the total count.
  • Impersonation detection: Detect unverified assets whose asset code matches a registered asset and identify the registered issuer.
  • Explicit warnings: Clearly call out code collisions in the affected asset row instead of silently hiding the asset.
  • Full visibility: Ensure users can expand the unverified section and view all assets held.
  • Responsive coverage: Apply the updated asset presentation across the mobile dashboard, assets screen, and web dashboard.
  • Testing: Add coverage for a wallet containing both the legitimate USDY and an unverified USDY impersonator.

Evidence After Solution

  • Verified that registered assets appear before unverified assets.
  • Verified that unverified assets are collapsed by default with an accurate count.
  • Verified that an unverified asset sharing a registered asset code is explicitly marked as impersonating the registered issuer.
  • Verified that users can expand the unverified section and view all held assets.
  • Verified that legitimate USDY and an unverified USDY impersonator are displayed distinctly.
  • Verified the behavior across the mobile dashboard, assets screen, and web dashboard.

closes #730

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@Emelie-Dev
Emelie-Dev requested a review from Miracle656 as a code owner October 3, 2026 12:12
@vercel

vercel Bot commented Oct 3, 2026

Copy link
Copy Markdown

@Emelie-Dev is attempting to deploy a commit to the miracle656's projects Team on Vercel.

A member of the Team first needs to authorize it.

@gitguardian

gitguardian Bot commented Oct 8, 2026

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

Since your pull request originates from a forked repository, GitGuardian is not able to associate the secrets uncovered with secret incidents on your GitGuardian dashboard.
Skipping this check run and merging your pull request will create secret incidents on your GitGuardian dashboard.

🔎 Detected hardcoded secret in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
37882553 Triggered Generic High Entropy Secret ce2657d frontend/wallet/lib/tests/sep45.test.ts View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Hide unknown assets that impersonate a registered one

1 participant