Create and import wallets
STABLEGenerate a recovery phrase, import an existing phrase, or import a private key. Key material is created locally. The extension does not ask a page, agent, or remote service to hold it.
Features
Stable means it is the product. Alpha means the code exists and a live or browser check is still open. New means it arrived in the 1.4.1 package on 2026-10-04 and no manual browser run is recorded against it yet. Planned means you cannot do it in the extension at all.
Generate a recovery phrase, import an existing phrase, or import a private key. Key material is created locally. The extension does not ask a page, agent, or remote service to hold it.
Derive further HD accounts from a seed keyring. A private-key-only vault cannot derive new accounts — that limit is intentional, not a missing button.
Several seed and private-key keyrings can sit side by side. Labels, the active account, and keyring metadata stay in the background, not in the page.
PBKDF2 with 600,000 SHA-256 iterations, then AES-256-GCM. Ciphertext lives in chrome.storage.local. Decrypted vault data lives only in chrome.storage.session and is wiped when the browser session ends.
Default is 15 minutes, user-configurable from 0 to 240, and changing it is password-gated. 1.4.1 stamps every API request and locks on measured idleness, so background sync no longer counts as activity. It is the first packaged build whose behavior matches the listing's inactivity-lock wording — 1.2.0 ran a fixed-period alarm under that same sentence.
1.4.1 adds an explicit lock button in Settings and a Ctrl+L shortcut, so clearing decrypted keys does not mean waiting out the timer or closing the browser. The store listing advertises the shortcut.
1.4.1 replaces the dashboard's coming-soon security tile with checks derived from state the background already owns: signing re-auth, auto-lock window, keyring origin, backup state. A value that cannot be read says unknown instead of grading itself.
1 THRU = 1e9 base units. The human amount is primary. Raw units stay visible underneath so a faucet credit of 10000 base units cannot be mistaken for 10000 THRU.
Create the on-chain account and claim from the faucet where the active network supports one. Betanet's faucet is a managed program whose vault credited 10,000 base units on the reset chain. Contract v13 drops the signing-password demand from a claim: an incoming credit is not a spend.
Review precedes send. History is one flat stream: a known time comes from the containing block, otherwise the row shows Block <slot> instead of an invented date. No per-card fee line is shipped. 1.4.1 refreshes the feed every 30 seconds while it is open, which the listing now advertises as live auto-sync.
Contract v15 adds tx.checkDuplicate: the same recipient and amount inside 30 seconds, or still in flight, is caught before signing. v1.4.1 moved the tracking to submission time, so the Repeated Transaction card covers the whole pending window, and the send proceeds only with an explicit allowDuplicate the backend enforces.
1.4.1 posts a native notification when a transaction confirms or fails, so a closed popup is not a blind spot. It is the fifth manifest permission, it is a Settings toggle, and the message carries no amount, address, or signature.
The shared page is 400px in the toolbar popup. Side Panel Mode is an explicit Settings choice and calls chrome.sidePanel.open() from a user gesture. It never calls setPanelBehavior, so the toolbar icon still opens the popup.
The receive route shows the address and a canvas QR. Explorer links point at scan.thru.org and carry ?network=betanet. Canvas paint, clipboard prompts, and the exact explorer path are still manual browser checks.
Labels, hiding, pinning, and ordering are part of the shipped account routes. Contacts CRUD on top of the contacts.* backend is still a follow-up screen, not a promised address book.
token.getBalances reads official @thru/programs/token bindings. A missing token account is a proven zero. A failed read is unknown — never a fabricated 0. Decimals come from the mint when a balance exists.
1.4.1 makes the whole balance box the token entry: click it, press Enter, or use the token strip and a drawer slides up with the full list and a live search. The inline dashboard token ledger is gone rather than duplicated.
Contract v14 adds token.readMint, so a pasted contract address is read from the chain and the mint's own symbol and decimals are used. Free-typed metadata is what made an added token burn the wrong number of base units.
token.transfer shipped in contract v8 with signing auth. A missing recipient token account can be initialized by the sender in a preceding transaction. Whether a never-registered owner can receive, and the token-program fee, are still unmeasured.
Backend contact methods exist. A full contacts screen is not the current product surface. Arbitrary contacts are never registered on-chain by the v12 just-in-time path.
A future companion may read permitted non-secret state and prepare intents. It must not receive a seed, password, or private key, and it must not sign or broadcast on its own.
The legacy surface was deleted, not hidden. A return is only allowed as a new feature module with verified program semantics, guarded DOM, and its own tests. Nothing of that kind ships today.
Thru's documented wallet is the hosted iframe, not an extension provider. This project will not invent window.thru or copy connect(), getSigningContext(), and signTransaction() into a browser injection.