reference
Features
What the extension actually does, grouped, with status that matches the source.
Status words on this site are narrow.
- STABLE means the route and the background path exist, and the project treats them as the product.
- ALPHA means the code is real, but a browser check or a live-chain measurement is still open.
- NEW means it arrived in the 1.4.1 package on 2026-10-04. You can install it today, and no manual browser run is recorded against it yet.
- PLANNED means it is not a thing you can do in the extension today.
Wallet core
Create or import a phrase or a private key. Derive more HD accounts from a seed keyring. Keep several keyrings. Encrypt the vault with PBKDF2 (600,000 SHA-256 iterations) and AES-256-GCM. Ciphertext is in chrome.storage.local. Decrypted material is only in chrome.storage.session.
Auto-lock defaults to 15 minutes and is configurable from 0 to 240, password-gated either way. In 1.2.0 it was a fixed-period alarm despite the label. 1.4.1 stamps lastActivityAt on every API request and locks on measured idleness, with background sync explicitly not counting as activity — and it adds an immediate lock button plus Ctrl+L.
Daily use
Balances show human-scale THRU and the raw base units. 1 THRU = 1e9 base units. Account creation and faucet claim exist where the network supports them; contract v13 makes a faucet claim unlocked-only rather than signing-gated. Native send goes through review, and contract v15 catches a repeat transfer to the same recipient inside 30 seconds before it is signed. History is one flat stream: block time when known, otherwise Block <slot>, refreshed every 30 seconds. Optional desktop notifications announce confirm or fail.
The popup is 400px. The side panel is an explicit opt-in and does not steal the toolbar click.
Token work
token.getBalances and token.transfer are implemented on official @thru/programs/token bindings. A missing token account is a proven zero. A failed read is unknown. The token-program fee is unmeasured, and the UI is supposed to say so rather than quote the native 1-base-unit fee.
The token list lives in a drawer opened from the balance box, and a custom token is added by contract address: token.readMint reads the mint from the chain and uses its own symbol and decimals, because typed metadata is what made an added token spend the wrong number of base units.
Contacts CRUD is not a shipped screen. Account pin, hide, and order exist on the account routes.
Not shipping
Launchpad, DEX, and prediction UI were deleted. A future version of any of them has to be a separate feature module. There is no injected provider.