security
Security model
Custody boundary, contract auth, DOM ratchet, and the checks that are still open.
This extension has not had a security review. The notes below are design constraints, not a certification.
Custody
Seeds, private keys, and passwords stay inside the extension. Export re-checks the password even when the wallet is unlocked. Agents, pages, and this website are outside the boundary.
Encrypted vault bytes may persist. Decrypted vault data belongs only in the session store, which is wiped when the browser session ends.
Signing
Signing requires an unlocked wallet. Password re-authentication for ordinary signing is off by default. Turning that preference on goes through a password-gated settings path. Generic settings.set rejects security-sensitive keys.
Do not extend the v12 registration exception to send, faucet, token transfer, export, or contacts.
DOM
innerHTML and related sinks are ratcheted at zero. New interface code uses the kit DOM factory. Lifecycle tests look for a seeded mnemonic, private key, or password in text, attributes, dataset values, input values, and the URL.
Networks
Custom endpoints cannot become active, including by a direct bridge call or by stale storage. Re-enabling them requires HTTPS policy, host permission, a verified capability record, and password re-auth — together, not one at a time. Localnet was removed from the shipped wallet for the same reason: selecting it bound the extension to a localhost endpoint the user may not control.
Permissions
1.4.1 requests five: storage, alarms, sidePanel, clipboardRead, and notifications. The fifth is new, it is a Settings toggle, and the notification body says only that a transfer confirmed or failed — no amount, address, or signature. The CSP remains default-src 'none' with script-src 'self' and a single connect-src origin.
What tests do not prove
Layout, real focus, canvas QR, the side panel, clipboard prompts, and service-worker eviction are browser facts. See the status page.