Can a Malicious Jetton Request Affect a STON.fi User?
Yes. A malicious jetton request can affect a STON.fi user, but the risk is often misunderstood. Standard TON jettons do not use the approve and allowance model common with ERC-20.
Under TEP-74, there is no standard approve, allowance, or transferFrom function. A normal jetton transfer authorizes a specific transaction.
Where is the real risk?
The main danger is signing a transaction without checking what it actually does.
A fake website can copy STON.fi and request a jetton transfer to an attacker's address. It may look like a normal swap while sending funds somewhere else.
TON Connect can also request one or more outgoing messages.
Wallet V5 extensions also require care because they can provide broader wallet-level capabilities than a simple one-time transfer.
How does a STON.fi swap work?
In a normal STON.fi jetton-to-jetton swap, the user's jettons enter the Router flow through a defined transfer. A payload tells the Router how to process the request, then the Router interacts with the relevant pool.
The amount is part of the transaction the user signs. This is different from giving STON.fi a permanent or unlimited TEP-74 allowance.
What should you check?
Before signing, confirm the jetton, exact amount, destination, and transaction details.
For unfamiliar jettons, verify the official token master address. Do not trust only the name, symbol, logo, or website because fake tokens can copy them.
One important distinction
A malicious one-time transfer can cause the approved amount to be lost. However, it does not automatically create a reusable TEP-74 allowance for future STON.fi swaps.
The bigger danger comes from a compromised wallet. A leaked seed phrase, private key, or powerful extension can allow an attacker to authorize future transactions.
Non-standard jettons may also contain additional logic beyond basic TEP-74 behavior.
Explore more on STON.FI: app.ston.fi
$BTC $STON
#Market
Yes. A malicious jetton request can affect a STON.fi user, but the risk is often misunderstood. Standard TON jettons do not use the approve and allowance model common with ERC-20.
Under TEP-74, there is no standard approve, allowance, or transferFrom function. A normal jetton transfer authorizes a specific transaction.
Where is the real risk?
The main danger is signing a transaction without checking what it actually does.
A fake website can copy STON.fi and request a jetton transfer to an attacker's address. It may look like a normal swap while sending funds somewhere else.
TON Connect can also request one or more outgoing messages.
Wallet V5 extensions also require care because they can provide broader wallet-level capabilities than a simple one-time transfer.
How does a STON.fi swap work?
In a normal STON.fi jetton-to-jetton swap, the user's jettons enter the Router flow through a defined transfer. A payload tells the Router how to process the request, then the Router interacts with the relevant pool.
The amount is part of the transaction the user signs. This is different from giving STON.fi a permanent or unlimited TEP-74 allowance.
What should you check?
Before signing, confirm the jetton, exact amount, destination, and transaction details.
For unfamiliar jettons, verify the official token master address. Do not trust only the name, symbol, logo, or website because fake tokens can copy them.
One important distinction
A malicious one-time transfer can cause the approved amount to be lost. However, it does not automatically create a reusable TEP-74 allowance for future STON.fi swaps.
The bigger danger comes from a compromised wallet. A leaked seed phrase, private key, or powerful extension can allow an attacker to authorize future transactions.
Non-standard jettons may also contain additional logic beyond basic TEP-74 behavior.
Explore more on STON.FI: app.ston.fi
$BTC $STON
#Market
