Skip to content

ALPHA · unofficial · Betanet testnet only

A self-custody wallet extension, built for Thru’s betanet.

Thru Wallet is an unofficial, high-performance browser extension for personal key management and basic account operations against the Thru betanet — built on the real @thru/sdk and @thru/programs packages.

Listing 1.4.1 · 272 KiB · updated 04 Oct 2026. Extension id ocahgpmgfeapjnceaknkikanjikhjgok.

Not production-ready and not security-reviewed. Use betanet testnet funds only. This is community software, not affiliated with or endorsed by Unto Labs. Do not use it with real financial value.

Thru

Popup study · 400px

Sample

primary

7Kq3Rt ··· Pe91Aq

Locked view

12.480

THRU · 12,480,000,000 base

THRU · USDX · 2 more

Send

Receive

Faucet

Activity

No invented dates

  • Sent

    Block 1,842,201

    −0.500 THRU

  • Faucet

    Raw units, not 10,000 THRU

    +10,000 base

  • Received

    Block 1,841,994

    +2.000 THRU

Betanet

contract v15 · v1.4.1

Static study of the v1.4.1 build, where the balance box is the token-drawer entry. Not connected. Sample figures only — not a balance, not an address format certification.

Extension · Chrome Web Store

The store build is the betanet build.

High-performance self-custody wallet and key manager for Thru. Version 1.4.1, updated 04 Oct 2026. Use this link unless you are loading dist/ from source.

Published 04 Oct 2026, one day after the source release v1.4.1 it was built from — contract v15, betanet, five permissions. It replaced 1.2.0, the alphanet-era package that had been the only installable version since 23 Sept 2026. What it has not had is a human in a browser: 0 of 36 manual smoke rows are ticked.

https://chromewebstore.google.com/detail/thru-wallet/ocahgpmgfeapjnceaknkikanjikhjgok

Three artifacts. Two of them now agree.

Status detail

Temporarily. Contract v16 is already written on the open #17 to #18 chain, and it retires tx.send and token.transfer. The day that merges, the source stops matching the package you can install.

Chrome Web Store

1.4.1

Published 2026-10-04

Updated 2026-10-04 · 272 KiB · 5 permissions

What Chrome installs today: the betanet build, with listing copy that finally describes it — token drawer, verified custom tokens, desktop notifications, Ctrl+L. It replaced 1.2.0, which had been the only installable version since 2026-09-23.

Open the listing

Source release

v1.4.1

Merged cee006e · contract v15

83 methods · @thru 0.4.1 · released 2026-10-03

The same build, one day earlier. Clone main at cee006e, run the suite, build dist/, and you get what the store is serving — which is the first time that sentence has been true here.

Release v1.4.1

Audited status doc

v12

behind both

81 methods · 2026-09-26 · 4aa55ba

STATUS_AND_ROADMAP.md was not rewritten for the merge or the release, so the repository's own summary describes neither the store build nor the code beside it. A rewrite exists on the open #17 to #18 chain and has not merged.

STATUS_AND_ROADMAP.md
Chrome installs
1.4.1
Betanet build · 2026-10-04
Contract
v15
83 methods · append-only
Smoke rows run
0 of 36
95 checks, none ticked
Vault
600k
PBKDF2 rounds, then AES-GCM

Features

What the extension actually does.

Grouped the way the product is used. Planned means it is not in the extension today.

Full feature index

Wallet Core

Create and import wallets

STABLE

Generate a recovery phrase, import an existing phrase, or import a private key. Key material is created locally. The extension does not ask a page, agent, or remote service to hold it.

Multiple accounts, one wallet

STABLE

Derive further HD accounts from a seed keyring. A private-key-only vault cannot derive new accounts — that limit is intentional, not a missing button.

Multi-seed keyring vault

STABLE

Several seed and private-key keyrings can sit side by side. Labels, the active account, and keyring metadata stay in the background, not in the page.

Password-encrypted local storage

STABLE

PBKDF2 with 600,000 SHA-256 iterations, then AES-256-GCM. Ciphertext lives in chrome.storage.local. Decrypted vault data lives only in chrome.storage.session and is wiped when the browser session ends.

Configurable auto-lock

STABLE

Default is 15 minutes, user-configurable from 0 to 240, and changing it is password-gated. 1.4.1 stamps every API request and locks on measured idleness, so background sync no longer counts as activity. It is the first packaged build whose behavior matches the listing's inactivity-lock wording — 1.2.0 ran a fixed-period alarm under that same sentence.

Lock on demand

NEW

1.4.1 adds an explicit lock button in Settings and a Ctrl+L shortcut, so clearing decrypted keys does not mean waiting out the timer or closing the browser. The store listing advertises the shortcut.

Security posture, computed not promised

NEW

1.4.1 replaces the dashboard's coming-soon security tile with checks derived from state the background already owns: signing re-auth, auto-lock window, keyring origin, backup state. A value that cannot be read says unknown instead of grading itself.

Daily Use

Balances in human-scale THRU

STABLE

1 THRU = 1e9 base units. The human amount is primary. Raw units stay visible underneath so a faucet credit of 10000 base units cannot be mistaken for 10000 THRU.

Account creation and faucet claims

STABLE

Create the on-chain account and claim from the faucet where the active network supports one. Betanet's faucet is a managed program whose vault credited 10,000 base units on the reset chain. Contract v13 drops the signing-password demand from a claim: an incoming credit is not a spend.

Native sends and decoded history

STABLE

Review precedes send. History is one flat stream: a known time comes from the containing block, otherwise the row shows Block <slot> instead of an invented date. No per-card fee line is shipped. 1.4.1 refreshes the feed every 30 seconds while it is open, which the listing now advertises as live auto-sync.

Repeat-transfer detection

NEW

Contract v15 adds tx.checkDuplicate: the same recipient and amount inside 30 seconds, or still in flight, is caught before signing. v1.4.1 moved the tracking to submission time, so the Repeated Transaction card covers the whole pending window, and the send proceeds only with an explicit allowDuplicate the backend enforces.

Desktop notifications

NEW

1.4.1 posts a native notification when a transaction confirms or fails, so a closed popup is not a blind spot. It is the fifth manifest permission, it is a Settings toggle, and the message carries no amount, address, or signature.

Popup and side panel, mutually exclusive

STABLE

The shared page is 400px in the toolbar popup. Side Panel Mode is an explicit Settings choice and calls chrome.sidePanel.open() from a user gesture. It never calls setPanelBehavior, so the toolbar icon still opens the popup.

Receive address and QR

ALPHA

The receive route shows the address and a canvas QR. Explorer links point at scan.thru.org and carry ?network=betanet. Canvas paint, clipboard prompts, and the exact explorer path are still manual browser checks.

Account pin, hide, and order

ALPHA

Labels, hiding, pinning, and ordering are part of the shipped account routes. Contacts CRUD on top of the contacts.* backend is still a follow-up screen, not a promised address book.

Token Work

Token balances, honestly

ALPHA

token.getBalances reads official @thru/programs/token bindings. A missing token account is a proven zero. A failed read is unknown — never a fabricated 0. Decimals come from the mint when a balance exists.

Token drawer from the balance box

NEW

1.4.1 makes the whole balance box the token entry: click it, press Enter, or use the token strip and a drawer slides up with the full list and a live search. The inline dashboard token ledger is gone rather than duplicated.

Custom tokens, verified on-chain

NEW

Contract v14 adds token.readMint, so a pasted contract address is read from the chain and the mint's own symbol and decimals are used. Free-typed metadata is what made an added token burn the wrong number of base units.

Token transfer, live probe open

ALPHA

token.transfer shipped in contract v8 with signing auth. A missing recipient token account can be initialized by the sender in a preceding transaction. Whether a never-registered owner can receive, and the token-program fee, are still unmeasured.

Contacts

PLANNED

Backend contact methods exist. A full contacts screen is not the current product surface. Arbitrary contacts are never registered on-chain by the v12 just-in-time path.

Future Modules

Local wallet MCP companion

PLANNED

A future companion may read permitted non-secret state and prepare intents. It must not receive a seed, password, or private key, and it must not sign or broadcast on its own.

Isolated launchpad, DEX, prediction

PLANNED

The legacy surface was deleted, not hidden. A return is only allowed as a new feature module with verified program semantics, guarded DOM, and its own tests. Nothing of that kind ships today.

No injected dApp provider

PLANNED

Thru's documented wallet is the hosted iframe, not an extension provider. This project will not invent window.thru or copy connect(), getSigningContext(), and signTransaction() into a browser injection.

Install

Store first. Source if you need the tree.

The Chrome listing is the path for a packaged extension. Clone only when you intend to read or rebuild it.

Both paths
Unpacked, after the store
git clone https://github.com/buildbyravi/thru-wallet-ext.git
cd thru-wallet-ext
npm install
npm test
npm run build

Load unpacked

  1. Open chrome://extensions and enable Developer mode.
  2. Load unpacked and select dist/, not the repo root.
  3. Reload the extension — not only the popup — after a rebuild.
Add to Chrome

Architecture

Five layers, one direction of trust.

The popup never holds signing authority. The background does, behind an append-only contract.

Architecture
  1. 01

    UI route stack

    src/ui/app/routes/*

    Fourteen real routes share one guarded DOM kit, router, modal, focus trap, and popup/side-panel page. There is no legacy popup fallback.

  2. 02

    Bridge seam

    bridge.send(method, params)

    The UI has one outbound Chrome message caller. BigInt values become strings before they cross the port. Nothing unserializable is allowed through.

  3. 03

    API router

    src/background/api-router.js

    Every request is checked against the append-only manifest, auth tier, sender context, and JSON-serializable contract. Unknown methods fail closed.

  4. 04

    Services

    src/background/services/*

    Account, network, transaction, token, history, settings, registration, and vault orchestration live in the background. The UI does not import them.

  5. 05

    Sacred adapters

    src/lib/vault.js · thru-client.js · networks.js

    Crypto, session, and keyring; Thru RPC, transaction, and program code; and network config stay behind strict import boundaries. Program addresses are read from the pinned @thru/programs release, not pasted in as strings.

Security

Constraints, not a certificate.

The design is strict. The review has not happened. Those are different sentences.

Security model

Self-custody boundary

The extension never asks an AI tool, a web page, or a remote service to hold the seed phrase, private key, or password. Export is password-gated. Signing stays in the background after the wallet auth policy passes.

Manifest-first API

The contract declares the methods the UI can call — v15 with 83 methods in the published build, v12 with 81 in a status document that has not caught up. Unknown methods fail closed. Contract tests keep route callers and background handlers aligned, and the surface is append-only except for documented, versioned breaks.

No unsafe DOM sinks

The source guard keeps innerHTML and related sinks at zero across src/. New UI is built with the kit DOM factory. Route lifecycle tests walk the rendered tree for seeded secrets.

Ledger

Listing, contract, and desk notes stay separate.

A store version is not a contract version. A desk note is neither.

Changelog

Authored

  • RELEASE04 Oct 2026

    Live on the Chrome Web Store

    Package 1.4.1 was approved and published. For the first time since this site started tracking it, the store build and the source tree are the same build.

  • RELEASE03 Oct 2026

    Merged and released — the betanet build is tagged v1.4.1

    PR #16 merged into main as cee006e and shipped as GitHub release v1.4.1. The source is betanet now; the store package is not.

  • RELEASE03 Oct 2026

    Submitted to the Chrome Web Store — never published

    The betanet package is with Chrome's reviewers. Submitted is not published: the listing keeps serving 1.2.0 until a reviewer approves, and the public page is the only thing this site treats as proof.

From the desk database

  • DOCS4 Oct 2026, 19:30 UTC

    The deployed dossier is itself a stale clock

    thruwallet.vercel.app — the developer website linked from the Chrome Web Store listing — still serves the pre-merge build of this site as of 2026-10-04: alphanet framing, listing 1.2.0, offered by PWNX0, contract v12, and the auto-lock entry that calls the timer a fixed-period alarm. A reader who clicks Website from the store lands on a page that contradicts the listing above it. The corrected dossier exists only on the open website branch until it merges and redeploys.

  • DOCS4 Oct 2026, 18:20 UTC

    Merging the v16 chain re-opens the gap it closes

    The chain rewrites STATUS_AND_ROADMAP.md to describe v16, which fixes the third clock. It does not bump the package number. Merge it as-is and main is contract v16 under the string 1.4.1, while the 1.4.1 in the store is contract v15 — one version string, two builds. Flagged upstream; the fix is a bump in the same change.

  • RELEASE4 Oct 2026, 18:15 UTC

    Contract v16 is written and removes two methods

    Read from the heads of #17 (7883219) and #18 (97276a7) on 2026-10-04: CONTRACT_VERSION 16 with 81 methods, down from 83, retiring tx.send and token.transfer now that every shipped caller uses the checked methods. 19 source files change and a storage-migrations suite joins the gate. It is the first contract step that subtracts.

Agents

Read-only context. No signing path.

Machine-readable files for this site, plus the policy a future wallet companion would have to obey.

Agent page

Allowed reads

  • wallet_get_public_accounts
  • wallet_get_balances
  • wallet_get_assets
  • wallet_get_activity
  • wallet_get_networks
  • wallet_get_capabilities

Protected intents

  • wallet_prepare_native_send
  • wallet_prepare_token_transfer
  • wallet_prepare_swap — only after real Thru-native swap support exists
  • wallet_prepare_launchpad_create — only after verified launchpad semantics exist

Forbidden

  • Mnemonic or private-key export
  • Password access
  • Direct signing or direct broadcast
  • Reset wallet or security-setting mutation
  • Raw decrypted vault access or arbitrary chrome.storage access