Skip to content

fix(sdk-coin-trx): validate TRC20 transfers on native Trx TSS path - #9800

Draft
ralph-bitgo[bot] wants to merge 1 commit into
masterfrom
cecho-2248-prevent-transient-trx-verification-errors
Draft

ralph-bitgo[bot] wants to merge 1 commit into
masterfrom
cecho-2248-prevent-transient-trx-verification-errors

Conversation

@ralph-bitgo

@ralph-bitgo ralph-bitgo Bot commented Sep 23, 2026

Copy link
Copy Markdown

What

  • Extract TRC20 TSS validation from TrxToken.verifyTransaction into a shared Trx.validateTriggerSmartContract.
  • Trx.verifyTransaction now validates TriggerSmartContract prebuilds on the TSS path instead of throwing "verification is not supported by native TRX".
  • Fail closed unless the ABI selector is a9059cbb (transfer), the decoded contract_address matches the intended token (tokenName / tokenAddress or TrxToken config), and recipient/amount match. approve(), a different token contract, or missing token identity still reject.
  • TrxToken.verifyTransaction delegates to the same validator (no behavior change for correctly routed token wallets).

Why

Customers briefly saw a non-blocking error during TRC20 withdrawals (including API-initiated ones) even though the withdrawal later confirmed. Token wallets are sometimes constructed with the native TRX coin instance, so a valid TRC20 transfer hit the CHALO-448 fail-closed throw on Trx.verifyTransaction. Validating the transfer on that path removes the transient UI error without weakening the guard.

Test plan

  • @bitgo/sdk-coin-trx unit tests: native Trx TriggerSmartContract cases (valid transfer, amount mismatch, destination mismatch, missing token identity, wrong contract, approve selector) and existing TrxToken TSS cases.
  • Confirm a TRC20 withdrawal routed through native TRX no longer surfaces "TriggerSmartContract verification is not supported by native TRX".

Ticket: CECHO-2248

Token wallets are sometimes constructed with the native coin instance,
so TriggerSmartContract prebuilds were rejected by Trx.verifyTransaction
and briefly shown as errors in the UI even when the withdrawal later
confirmed.

Validate TRC20 transfers on native Trx instead of throwing: require the
transfer selector a9059cbb, bind the contract to the intended token
(tokenName/tokenAddress or TrxToken config), and compare recipient and
amount. Fail closed on approve(), wrong token, or missing token identity.

Ticket: CECHO-2248
Session-Id: 40ede34c-a7a5-431f-b293-e97a24c2c391
Task-Id: 6294f511-db62-4b82-b0fd-84fb618f7d64
@ralph-bitgo
ralph-bitgo Bot force-pushed the cecho-2248-prevent-transient-trx-verification-errors branch from 4a10ff0 to 59c2158 Compare September 23, 2026 10:34
@linear-code

linear-code Bot commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

CECHO-2248

@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Unit tests are failing on Node 26.x (Current release line, non-blocking). This is not an LTS version yet, so it does not block merge, but it signals an incompatibility to fix before Node 26.x becomes LTS.

View run

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant