Skip to content

WalletBeat safety: address reputation and suspicious-recipient warnings #149

Description

@0xpantera

Problem

WalletBeat scam-alert fixtures include known-scam and wallet-owned/custom-recipient tests. Deckard currently has clear-signing review and fail-closed parsing, but no address reputation or suspicious-recipient engine.

Scope

  • Define a local/test-only reputation fixture format for scam/suspicious addresses.
  • Warn or refuse when a recipient/spender/verifying contract matches a known-bad test entry.
  • Keep production reputation-source policy explicit; do not silently depend on an opaque third-party list.
  • Cover native ETH sends and ERC-20 approvals/transfers in local-chain QA.

Acceptance criteria

  • WalletBeat wallet-own-1 and known-scam-eth-send have positive Deckard warning/refusal coverage.
  • Tests use local fixtures only and never require production wallet state or real funds.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    qaAutomated QA, Playwright, local-chain testssecuritySecurity-relevantwalletbeatWalletBeat compatibility and QA

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions