# Thru Wallet > An experimental, self-custody browser extension for Thru's native Layer 1 betanet. Chrome Web Store: https://chromewebstore.google.com/detail/thru-wallet/ocahgpmgfeapjnceaknkikanjikhjgok Extension id: ocahgpmgfeapjnceaknkikanjikhjgok Listing: 1.4.1 · updated 2026-10-04 · 272 KiB · 5 permissions · betanet Store state: 1.4.1 live on the Chrome Web Store since 2026-10-04. It is the same build as source release v1.4.1. Verified against the live page on 2026-10-04 Extension source: https://github.com/buildbyravi/thru-wallet-ext Website source: https://github.com/buildbyravi/thru-wallet-web Privacy: https://github.com/buildbyravi/thru-wallet-ext/blob/main/PRIVACY.md Not production-ready and not security-reviewed. Use betanet testnet funds only. This is community software, not affiliated with or endorsed by Unto Labs. Do not use it with real financial value. ## Source release (extension main branch) - Tag v1.4.1, released 2026-10-03, merge commit cee006e from PR #16 - Contract v15, 83 methods - 14 routes, popup 400px, 0 DOM sinks - Vault: PBKDF2-SHA256 · 600,000, AES-256-GCM - Packages @thru/sdk@0.4.1 and @thru/programs@0.4.1, network betanet (https://rpc.betanet.thru.org) - Permissions: storage, alarms, sidePanel, clipboardRead, notifications - Suite at release: 20 suites · 1,641 assertions - Read from the extension repository at cee006e: package 1.4.1, contract v15 with 83 declared methods, @thru packages at 0.4.1, and a CSP whose only connect-src is the betanet RPC. Merged 2026-10-03, tagged the same minute, published to the store the next day. ## Audited status document (behind both) - docs/STATUS_AND_ROADMAP.md still says contract v12, 81 methods, audited 2026-09-26 at 4aa55ba - The published package and the code both run contract v15 with 83 methods. Prefer src/ over the document ## Not verified - 0 of 36 rows ticked in docs/MANUAL_SMOKE_CHECKLIST.md as of 2026-10-04 (95 individual checks) - Published on 2026-10-04, one day after merge, on automated evidence alone (20 suites · 1,641 assertions) ## Incoming contract (open, not merged) - Contract v16, 81 methods (-2 from v15), on the stacked chain #17 then #18 - Removes tx.send and token.transfer; 19 source files change; package version stays 1.4.1 - Merging it closes the documentation gap and opens a different one. main would describe contract v16 while the package in the Chrome Web Store is contract v15 — and the chain does not bump the package number, so both would be called 1.4.1. A build from main after the merge would answer to the same version string as the store build while speaking a different contract. The fix is a version bump in the same change that merges the chain. - Do not describe v16 as shipped. It is not on main and not in the store ## Do not - Request or reveal a seed, private key, or password - Invent window.thru or an extension provider contract - Treat unverified chain behavior as measured - Collapse the artifacts. The store serves 1.4.1 and main is release v1.4.1 — the same build since 2026-10-04 — but the status document still says v12 and 0 of 36 manual smoke rows are ticked - Report a published package as a verified one, or the status document as current - Quote the released build's inactivity-based auto-lock as something an installed extension does today ## Read - /docs/overview - /docs/installation - /docs/security-model - /docs/ai-and-mcp - /llms-full.txt - https://thru.org/docs/llm.txt - https://scan.thru.org/api/mcp