Skip to content

Changelog

What changed, and in which artifact.

Authored entries are reviewed with the site. Desk notes are rows in Postgres. A store release and a contract bump are not the same event.

  1. 1.4.1

    04 Oct 2026

    RELEASE

    Live on the Chrome Web Store

    Package 1.4.1 was approved and published. For the first time since this site started tracking it, the store build and the source tree are the same build.

    • Listing now reads 1.4.1, updated 2026-10-04, 272 KiB, with five screenshots and a linked developer website at thruwallet.vercel.app. It replaced 1.2.0 from 2026-09-23, which was 209 KiB.
    • The description was replaced along with the package: betanet rather than alphanet, plus the token drawer, verified custom tokens by contract address, live 30-second activity auto-sync, desktop notifications, and Ctrl+L.
    • The Offered by PWNX0 row is no longer shown on the listing page, so this site no longer asserts a publisher name.
    • Auto-lock is the one claim that used to be wrong in both directions: the listing had always advertised an inactivity lock while 1.2.0 ran a fixed-period alarm. 1.4.1 is the first package where the behavior and the sentence match.
    • Published one day after the source release — merged 2026-10-03 as cee006e, tagged v1.4.1, approved 2026-10-04. Submission, merge, and publication stayed three separate events to the end.
    • Unchanged: docs/STATUS_AND_ROADMAP.md still claims contract v12 with 81 methods, and all 36 rows of docs/MANUAL_SMOKE_CHECKLIST.md are still unticked.
  2. 1.4.1

    03 Oct 2026

    RELEASE

    Merged and released — the betanet build is tagged v1.4.1

    PR #16 merged into main as cee006e and shipped as GitHub release v1.4.1. The source is betanet now; the store package is not.

    • Merged at 13:56 UTC and tagged thirteen seconds later, carrying Design System v2, betanet, @thru 0.4.1, the token drawer, chain-verified custom tokens, desktop notifications, and the send hardening pass.
    • Numbered 1.4.1 rather than 1.4.0 because 1.4.0 was submitted to the store and never published, so no released version is skipped.
    • Contract v15 with 83 declared methods is what main exports. This site reads its source facts from cee006e.
    • Gate at merge: 20 suites and 1,641 assertions green, plus the CI build-and-test job.
    • Still not installable from the store. The listing serves 1.2.0 until someone uploads the 1.4.1 package and a reviewer approves it.
    • docs/STATUS_AND_ROADMAP.md was not touched by the merge and still claims contract v12 with 81 methods at 4aa55ba.
  3. 1.4.0

    03 Oct 2026

    RELEASE

    Submitted to the Chrome Web Store — never published

    The betanet package is with Chrome's reviewers. Submitted is not published: the listing keeps serving 1.2.0 until a reviewer approves, and the public page is the only thing this site treats as proof.

    • Package 1.4.0 submitted with the rewritten betanet description and the fifth permission, notifications, justified in the dashboard.
    • The live listing page re-read on 2026-10-03 still reports 1.2.0, 2026-09-23, 209 KiB — unchanged, as expected during review.
    • Source side: PR #16 is in final review at 9086b22, with @thru/sdk and @thru/programs synced to 0.4.1.
    • This site tracks submission and merge as two separate events, because a rejection moves one without the other.
  4. site

    02 Oct 2026

    DOCS

    Three clocks: store build, source baseline, pending 1.4.0

    The extension's betanet work is reviewed and CI-green on an open pull request, so this site now tracks it as a third, clearly separate object instead of folding it into either shipped artifact.

    • Pending release block records PR #16 at 1338380: package 1.4.0, contract v15, 83 methods, @thru 0.4.0, betanet RPC.
    • Chrome Web Store facts re-verified against the live listing on 2026-10-02 and left at 1.2.0 / 2026-09-23 / 209 KiB.
    • Alphanet wording replaced with betanet where the project's target chain is meant, and kept where the shipped package is meant.
    • Auto-lock copy corrected: the pending build measures real inactivity, so the old 'the source says fixed-period alarm' gap is retired on merge, not before.
  5. 1.4.0

    02 Oct 2026

    RELEASE

    Betanet migration, token drawer, desktop notifications — pending

    Package 1.4.0 exists as reviewed source on an open pull request. It is not merged to main and it is not what Chrome installs today.

    • Betanet is the default and only enabled network: rpc.betanet.thru.org, explorer links carry ?network=betanet, and the CSP connect-src allows nothing else.
    • Program addresses come from @thru/programs 0.4.0 managed-genesis registry instead of the reverse-engineered marker-byte addresses the 2026-09-26 chain reset deleted.
    • The balance box is the token entry: click it and a sliding drawer lists tokens, searches, and adds a custom token by contract address after the chain supplies symbol and decimals.
    • Optional desktop notifications on transaction confirm or fail, which is the fifth manifest permission and a Settings toggle.
    • Auto-lock now measures real inactivity, the faucet no longer demands a signing password, and a repeat transfer inside 30 seconds is detected before it is signed.
    • Localnet is gone from the shipped wallet and the manifest homepage points at thruwallet.vercel.app.
    • Packages tracked the chain twice: 0.3.16 to 0.4.0 for the managed-genesis reset, then a 0.4.1 sync at 9086b22.
  6. v13 → v15

    02 Oct 2026

    SECURITY

    Contract moves to v15, 83 methods

    Three contract steps ride with the pending package: one deliberate behavior break and two additive reads. Append-only discipline holds for everything else.

    • v13 modifies tx.claimFaucet: auth drops from signing to unlocked and the vestigial password param leaves the declaration. Old callers that still send one are ignored, not rejected.
    • v14 appends token.readMint so a pasted contract address is verified on-chain before a custom token joins the ledger.
    • v15 appends tx.checkDuplicate for repeat transfers inside 30 seconds or still in flight, plus an optional allowDuplicate on the send methods.
    • Method count moves 81 → 83. The UI-to-background agreement is still enforced in both directions by test-contract.mjs.
  7. site

    26 Sept 2026

    RELEASE

    Dossier site, with the store as the install path

    This website now leads with the Chrome Web Store listing and keeps source install, docs, and the v12 status baseline in the same dossier.

    • Chrome Web Store link on the header, homepage, install page, footer, llms.txt, and catalog API.
    • Listing facts recorded beside the source baseline so the two versions are not collapsed into one.
    • Docs hub, architecture flow, security principles, agent policy, and a Postgres-backed desk ledger.
  8. v12

    26 Sept 2026

    DOCS

    Status baseline: contract v12, 81 methods

    The extension status document, audited at commit 4aa55ba, is the source baseline this site describes. It is newer than the packaged listing.

    • tx.registerAccount for an exact vault-owned address, unlocked-only, no value transfer.
    • tx.getCachedHistory for cache-first History paint, scoped by network and address.
    • Send review waits for just-in-time activation and shows the matched recipient label as display-only.
    • Signing password re-auth remains opt-in. The default is session signing while unlocked.
  9. 1.2.0

    23 Sept 2026

    RELEASE

    Chrome Web Store listing

    Thru Wallet is listed as an experimental self-custody wallet for Thru alphanet. Version 1.2.0, 209 KiB, offered by PWNX0.

    • Store id ocahgpmgfeapjnceaknkikanjikhjgok.
    • Disclosed privacy posture: data is not collected. Policy lives in the extension repository.
    • Listing copy mentions a 15-minute lock. The source describes that timer as a fixed-period alarm, not inactivity detection.
    • The listing is explicit: not affiliated with Unto Labs, and not for real financial value.
  10. v8

    18 Sept 2026

    SECURITY

    Token transfer shipped in code

    Token methods sit on official @thru/programs/token bindings. Live fee and recipient-owner questions stayed open on purpose.

    • token.transfer uses signing auth and mint units, never THRU units.
    • A missing recipient token account can be initialized by the sender first.
    • Failed balance reads stay unknown. They are not rendered as zero.
  11. v7

    18 Sept 2026

    SECURITY

    Custom networks quarantined

    Settings no longer offers Add custom network. The background also refuses activation, including direct API calls and stale storage.

    • network.setActive accepts enabled built-ins only.
    • A custom id returns CUSTOM_NETWORK_DISABLED.
    • Legacy rows remain visible so they can be removed.
  12. v6

    18 Sept 2026

    SECURITY

    Reset and auto-lock hardened

    Destructive and security-timer changes are enforced in the background, not only by the form that triggered them.

    • Reset requires confirmation and an unlocked-wallet password check.
    • Auto-lock changes are password-gated.
    • Generic settings writes reject security-sensitive keys.

Desk ledger

These notes are stored in the catalog database. They can be added from the desk without pretending to be a release.

  • DOCS4 Oct 2026, 19:30 UTC · dossier

    The deployed dossier is itself a stale clock

    thruwallet.vercel.app — the developer website linked from the Chrome Web Store listing — still serves the pre-merge build of this site as of 2026-10-04: alphanet framing, listing 1.2.0, offered by PWNX0, contract v12, and the auto-lock entry that calls the timer a fixed-period alarm. A reader who clicks Website from the store lands on a page that contradicts the listing above it. The corrected dossier exists only on the open website branch until it merges and redeploys.

  • DOCS4 Oct 2026, 18:20 UTC · dossier

    Merging the v16 chain re-opens the gap it closes

    The chain rewrites STATUS_AND_ROADMAP.md to describe v16, which fixes the third clock. It does not bump the package number. Merge it as-is and main is contract v16 under the string 1.4.1, while the 1.4.1 in the store is contract v15 — one version string, two builds. Flagged upstream; the fix is a bump in the same change.

  • RELEASE4 Oct 2026, 18:15 UTC · dossier

    Contract v16 is written and removes two methods

    Read from the heads of #17 (7883219) and #18 (97276a7) on 2026-10-04: CONTRACT_VERSION 16 with 81 methods, down from 83, retiring tx.send and token.transfer now that every shipped caller uses the checked methods. 19 source files change and a storage-migrations suite joins the gate. It is the first contract step that subtracts.

  • SMOKE4 Oct 2026, 18:10 UTC · dossier

    Smoke count reconciled: 36 rows, 95 checks, 0 ticked

    The extension repo counts 95 checkbox cells; this site counted 36 rows. Same file, same tree, same answer — most rows carry more than one cell because popup and side panel are checked separately, narrow and wide. Both numbers now appear with their units so neither reads as a correction of the other.

  • DOCS4 Oct 2026, 14:55 UTC · dossier

    Offered by PWNX0 is gone from the listing page

    The Details block no longer carries a publisher row; it now shows a developer website link to thruwallet.vercel.app and the contact email. This site stopped asserting a publisher name rather than quoting a row that is no longer there. extension.md still records the last listing sync as 2026-09-30, which is wrong by five days.

  • SMOKE4 Oct 2026, 14:50 UTC · dossier

    Published is not verified: 0 of 36

    docs/MANUAL_SMOKE_CHECKLIST.md has 36 rows and none are ticked. The package went merge to store in a day on 20 automated suites. Until someone installs the published package and walks the list, the people installing it are the first browser run — duplicate detection across the pending window, notification delivery, and the dark-mode surfaces most of all.

  • SECURITY4 Oct 2026, 14:45 UTC · dossier

    The auto-lock contradiction closed from both sides

    The 2026-09-26 note said the source wins until a build changes the behavior and the listing together. That is what happened: 1.4.1 locks on measured inactivity and the listing still says inactivity lock, so for the first time the sentence and the code agree. Keeping the old note on the record — it described the package that was installable at the time.

  • RELEASE4 Oct 2026, 14:40 UTC · dossier

    1.4.1 is live — the listing finally matches the source

    Live page read 2026-10-04: version 1.4.1, updated October 4, 272 KiB, five screenshots, betanet description naming the token drawer, verified custom tokens, desktop notifications, and Ctrl+L. The store and main at cee006e are the same build. The 1.2.0 alphanet package is gone from the install path.

  • DOCS3 Oct 2026, 14:15 UTC · dossier

    The merge did not fix the status doc

    docs/STATUS_AND_ROADMAP.md on main at cee006e still opens with contract v12 and 81 methods audited at 4aa55ba on 2026-09-26, three contract steps behind the manifest sitting next to it. The site now renders it as its own track on /status instead of treating it as the baseline.

  • RELEASE3 Oct 2026, 14:10 UTC · dossier

    1.4.0 was never published, so the release is 1.4.1

    The package submitted this morning did not reach the public page, and the release notes say so outright. Uploading the 1.4.1 package is still a human step, recorded as pending in extension.md, which is why the store track on this site did not move when the source track did.

  • RELEASE3 Oct 2026, 14:05 UTC · dossier

    PR #16 merged as cee006e and released as v1.4.1

    Merged 13:56 UTC on 2026-10-03, tagged v1.4.1 thirteen seconds later. Main is contract v15, 83 methods, @thru 0.4.1, and a CSP whose only connect-src is the betanet RPC. Store listing re-read the same day: 1.2.0, 209 KiB, September 23, alphanet copy. Released is not installed.

  • NOTE3 Oct 2026, 09:45 UTC · dossier

    PR #16 head moved to 9086b22

    Four commits after the audited tip: @thru/sdk and @thru/programs synced to 0.4.1, a warm header gradient with frosted pill borders, a fixed-width account pill with 6...6 address truncation, and a balance-hero refresh hover fix. Contract stays v15 with 83 methods and the manifest stays 1.4.0.