Skip to content

[Bug]: Deceptive site request. Domain mismatch when signing messages with matching domain #18332

@steddyman

Description

@steddyman

Describe the bug

Users have just started reporting that when they visit my site, and try to sign in via signing a message, that the domain does not match the one in the URI request (which it does). I do not get an RPC error, but see the UI warning about the domains not matching when they do match when the user goes to sign the login message.

As ou can see in the screenshots they do actually match. This only seems to have started this week, possibly only today with Metamask 10.26.2. It does not relate to my site being flagged as malicious, but an incorrect flagging of the domain.

It seems related to this issue: #17707

image

image

image

Steps to reproduce

  1. Visit https://mintmonster.io
  2. Connect Wallet
  3. Click Sign-in button until you are promoted to sign the login message

Error messages or log output

Deceptive site request. The site you're attempting to sign into doesn't match the domain in the request. Proceed with caution.

Version

10.26.2

Build type

None

Browser

Chrome

Operating system

MacOS

Hardware wallet

No response

Additional context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    team-confirmations-planning(only for internal use within Confirmations team)type-bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions