trezor-firmware icon indicating copy to clipboard operation
trezor-firmware copied to clipboard

dApp transactions on Cardano can look like sending away a lot of ada even though it's not really

Open SeekerFS opened this issue 1 year ago • 0 comments

Describe the bug I was signing a lenfi transaction, it had input with a lot of ada that were'nt mine, but the trezor screen told me that I'm sending all those ada (even more than i have), and asked me to sign it. It didn't seem to recognize that these inputs were from my wallet, but from external script addresses that i was interacting with. The trezor was telling me I was sending out much more ada than i was actually sending out from my wallet.

Firmware version and revision 2.6.4

Desktop/smartphone setup (please complete the following information):

  • Wallet software: Eternl
  • OS: Windows 11
  • Browser: Chrome
  • Version:

To Reproduce Steps to reproduce the behavior:

  1. Go to https://app.lenfi.io/pools
  2. Click on Deposit
  3. Deposit a small ammount of ada
  4. See on the device that you are signing sending out a lot more ada, than you are actually sending out from your wallet

Expected behavior Should not look that scary. If there's a tx that takes 100 000 ADA from some external script address and 100 ADA from my wallet, and sends 100 100 ADA somewhere, then the app should tell me I am sending out only 100 ADA, Looks like the device only shows the outputs, it should also tell me how many of the ADA i'm sending is not actually mine.

SeekerFS avatar Feb 24 '24 12:02 SeekerFS