{
  "id": "mt1-send-token",
  "title": "The Token Send",
  "extends": "m1-send-metamask",
  "context": {
    "wallet": "MetaMask extension",
    "platform": "Chrome extension",
    "network": "mainnet",
    "settings": "defaults",
    "version": "web/5.157.3",
    "observed": "2026-08-24",
    "captures": [
      {
        "run": "20260824-223756-send-token",
        "tx": "0xfda8cdbb4c36f7a99420d14c2c8fcd9bc16f9f3f2f2f2d3e2320569a2b8382cd"
      }
    ]
  },
  "_comment": "Sending an ERC-20 TOKEN (mUSD), not native ETH. Same MetaMask backbone as M1, with two real differences. (1) The signed transaction's 'to' is the TOKEN CONTRACT, not the person you're paying — the recipient and amount ride inside transfer() calldata (0xa9059cbb…) that the wallet must decode to show you who you're really paying. (2) An extra screening call fires: security-alerts.api.cx.metamask.io/token/scan-bulk — Blockaid scans the token contract itself (a plain ETH send never hits this). Observed live: real mainnet tx 0xfda8cdbb…82cd, 1.0 mUSD → austingriffith.eth, broadcast via the Smart Transactions relay. mUSD is the stablecoin M4's swap produced, so this maps the money's next hop.",
  "prepend_steps": [
    {
      "id": "token-scan",
      "phase": "discover",
      "name": "Blockaid · token-contract scan",
      "host": "security-alerts.api.cx.metamask.io/token/scan-bulk",
      "actor": "blockaid",
      "purpose": "Scan the ERC-20 contract you're transferring (bulk token security check) before the send — extra to the recipient/address scan a plain ETH send does",
      "need": "T",
      "carries": [
        "ip",
        "selected_address",
        "token_pair"
      ],
      "returns": "a token-safety verdict the send screen trusts",
      "can_block": false,
      "on_failure": "silent",
      "worst_lie": {
        "outcome": "false_belief",
        "note": "a wrong verdict either scares you off a real token or waves through a malicious one"
      },
      "removable_by": "security_alerts_off",
      "tx_input": "gate",
      "provenance": {
        "status": "observed",
        "ref": "20260824-223756-send-token · POST security-alerts.api.cx.metamask.io/token/scan-bulk"
      },
      "notes": "Only fires for token transfers; the plain ETH send (M1) has address/evm/scan but no token/scan-bulk.",
      "fixed_by": [
        "local-address-risk"
      ]
    }
  ],
  "own_node": {
    "node": "192.168.68.54",
    "runs": [
      "20260924-213914-send-token-localnode"
    ],
    "steps": {
      "token-scan": {
        "state": "out",
        "ref": "security-alerts.api.cx.metamask.io · 3 req after switch · /address//token/scan-bulk"
      },
      "ext-update": {
        "state": "unseen",
        "ref": "clients2.google.com seen before the switch only, not after"
      },
      "feature-flags": {
        "state": "out",
        "ref": "client-config.api.cx.metamask.io · 1 req after switch"
      },
      "phishing-list": {
        "state": "unseen",
        "ref": "phishing-detection.api.cx.metamask.io seen before the switch only, not after"
      },
      "c2-list": {
        "state": "unseen",
        "ref": "client-side-detection.api.cx.metamask.io seen before the switch only, not after"
      },
      "token-list": {
        "state": "unseen",
        "ref": "token.api.cx.metamask.io seen before the switch only, not after"
      },
      "spot-prices": {
        "state": "out",
        "ref": "price.api.cx.metamask.io · 9 req after switch · /v3/spot-prices"
      },
      "fiat-rates": {
        "state": "unseen",
        "ref": "price.api.cx.metamask.io still contacted (9 req) but this exact call wasn't singled out"
      },
      "accounts-balances": {
        "state": "out",
        "ref": "accounts.api.cx.metamask.io · 7 req after switch · /v4/multiaccount/balances"
      },
      "balance-fallback": {
        "state": "local",
        "ref": "192.168.68.54 · eth_call; mainnet.infura.io got 0 after switch"
      },
      "nft-detection": {
        "state": "unseen",
        "ref": "nft.api.cx.metamask.io seen before the switch only, not after"
      },
      "defi-positions": {
        "state": "out",
        "ref": "defiadapters.api.cx.metamask.io · 1 req after switch"
      },
      "icons": {
        "state": "unseen",
        "ref": "static.cx.metamask.io seen before the switch only, not after"
      },
      "block-poll": {
        "state": "local",
        "ref": "192.168.68.54 · eth_blockNumber; mainnet.infura.io got 0 after switch"
      },
      "segment": {
        "state": "out",
        "ref": "api.segment.io · 5 req after switch"
      },
      "sentry": {
        "state": "out",
        "ref": "sentry.io · 22 req after switch"
      },
      "screen-recipient": {
        "state": "out",
        "ref": "security-alerts.api.cx.metamask.io · 3 req after switch · /address/evm/scan"
      },
      "nonce": {
        "state": "unseen",
        "ref": "mainnet.infura.io seen before the switch only, not after"
      },
      "gas-fees": {
        "state": "out",
        "ref": "gas.api.cx.metamask.io · 2 req after switch · suggestedgasfees"
      },
      "estimate-gas": {
        "state": "local",
        "ref": "192.168.68.54 · eth_estimateGas; mainnet.infura.io got 0 after switch"
      },
      "simulation": {
        "state": "out",
        "ref": "tx-sentinel-ethereum-mainnet.api.cx.metamask.io · 8 req after switch"
      },
      "security-alert": {
        "state": "out",
        "ref": "security-alerts.api.cx.metamask.io · 3 req after switch · /validate"
      },
      "stx-broadcast": {
        "state": "unseen",
        "ref": "not in these runs"
      },
      "inclusion": {
        "state": "unseen",
        "ref": "not in these runs"
      },
      "stx-status": {
        "state": "unseen",
        "ref": "not in these runs"
      },
      "receipt-poll": {
        "state": "unseen",
        "ref": "mainnet.infura.io seen before the switch only, not after"
      },
      "etherscan-check": {
        "state": "unseen",
        "ref": "not in these runs"
      },
      "balance-refresh": {
        "state": "unseen",
        "ref": "accounts.api.cx.metamask.io still contacted (7 req) but this exact call wasn't singled out"
      }
    },
    "unmapped": [
      "tron-mainnet.infura.io",
      "solana-mainnet.infura.io",
      "bitcoin-mainnet.infura.io",
      "user-storage.api.cx.metamask.io",
      "tokens.api.cx.metamask.io",
      "monad-mainnet.infura.io",
      "subscription.api.cx.metamask.io",
      "api.merkl.xyz",
      "optimism-mainnet.infura.io",
      "base-mainnet.infura.io",
      "linea-mainnet.infura.io",
      "polygon-mainnet.infura.io",
      "arbitrum-mainnet.infura.io",
      "bsc-mainnet.infura.io",
      "sepolia.infura.io",
      "testnet-rpc.monad.xyz",
      "linea-sepolia.infura.io",
      "carrot.megaeth.com",
      "notification.api.cx.metamask.io",
      "geolocation.api.cx.metamask.io",
      "on-ramp-cache.api.cx.metamask.io",
      "authentication.api.cx.metamask.io",
      "metamask.github.io",
      "cdn.contentful.com",
      "gateway.api.cx.metamask.io",
      "www.4byte.directory"
    ]
  }
}
