Learn

Security audit

There is no third-party audit yet. That is the honest status.

We have not paid a firm to review this code. Until that exists, treat the extension as an early build: useful, not blessed.

What you can verify yourself

  • The extension does not request access to keys
  • It wraps window.ethereum.request and related send methods
  • Reject throws the standard user-rejected error (4001)
  • Continue calls the original wallet method unchanged

When an audit is published, it will live on this page — the report, the date, and the scope. Not a badge with no file behind it.