Backpack

Backpack

πŸ” Security Report Available
πŸ‘₯ 400K+ users
View on Chrome Web Store

Chrome will indicate if you already have this installed.

Overview

A next level crypto wallet for Solana, Ethereum, Monad, Sui, and more.

Security Analysis

Analyzed v0.10.190 Β· Feb 21, 2026 Β· 83 JS files Β· 44603 KB scanned

Permissions

storage unlimitedStorage background sidePanel declarativeNetRequest

Code Patterns Detected

eval() used β€” can execute arbitrary code innerHTML assignment β€” potential XSS vector Makes HTTP requests Listens to keyboard events

External Connections

backpack-shared-assets.s3.us-east-1.amazonaws.com www.w3.org swr.xnftdata.com github.com t.me blockaid.xnftdata.com 0x.xnfts.dev support.backpack.exchange eu.support.backpack.exchange eips.ethereum.org api.devnet.aptoslabs.com explorer.solana.com +8 more

Package Contents 259 files Β· 47.5MB

β–ΎπŸ“_metadata33KB
{}verified_contents.json33KB
β–ΎπŸ“assets3.9MB
πŸ–Όback-icon-mask.png653B
πŸ–Όback-icon.png207B
πŸ–Όbackpack-logo-and-wordmark-vertical@4x.png5KB
πŸ–Όbackpack-logo.png569B
πŸ–Όbackpack-logo@4x.png2KB
πŸ–Όbackpack-recovery-phrase@4x.png845B
πŸ–Όbackpack-wordmark-eu@4x.png7KB
πŸ–Όbackpack-wordmark@4x.png5KB
πŸ–Όbackpack.png998B
πŸ–Όbank@4x.png854B
πŸ–Όbanner-bpsol.png27KB
πŸ–Όbanner-monad.png13KB
πŸ–Όbanner-sui.png3KB
πŸ–Όbanner-wallet-backup-bg.png115KB
πŸ–Όbanner-wallet-backup-icon.png1KB
πŸ–Όbronze@4x.png17KB
πŸ–Όcandlestick-chart@4x.png671B
πŸ–Όchallenger@4x.png29KB
πŸ–Όclear-icon.png645B
πŸ–Όclose-icon.png332B
πŸ–ΌdefaultSplash1000.svg2KB
πŸ–ΌdefaultSplash2000.svg2KB
πŸ–ΌdefaultSplash600.svg2KB
πŸ–Όdiamond@4x.png24KB
πŸ–Όexplore-active.png376B
πŸ–Όexplore-active@4x.png995B
πŸ–Όexplore-inactive.png495B
πŸ–Όexplore-inactive@4x.png1KB
πŸ–Όface-recognition@4x.png3KB
πŸ–Όform-error@4x.png341B
πŸ–Όgold@4x.png20KB
πŸ”€inter-all-400-normal.woff126KB
πŸ”€inter-all-500-normal.woff136KB
πŸ”€inter-all-600-normal.woff137KB
πŸ”€inter-cyrillic-400-normal.woff26KB
πŸ”€inter-cyrillic-500-normal.woff27KB
πŸ”€inter-cyrillic-600-normal.woff27KB
πŸ”€inter-cyrillic-ext-400-normal.woff29KB
πŸ”€inter-cyrillic-ext-500-normal.woff210KB
πŸ”€inter-cyrillic-ext-600-normal.woff210KB
πŸ”€inter-greek-400-normal.woff28KB
πŸ”€inter-greek-500-normal.woff28KB
πŸ”€inter-greek-600-normal.woff28KB
πŸ”€inter-greek-ext-400-normal.woff25KB
πŸ”€inter-greek-ext-500-normal.woff25KB
πŸ”€inter-greek-ext-600-normal.woff25KB
πŸ”€inter-latin-400-normal.woff216KB
πŸ”€inter-latin-500-normal.woff217KB
πŸ”€inter-latin-600-normal.woff217KB
πŸ”€inter-latin-ext-400-normal.woff220KB
πŸ”€inter-latin-ext-500-normal.woff222KB
πŸ”€inter-latin-ext-600-normal.woff222KB
πŸ”€inter-vietnamese-400-normal.woff24KB
πŸ”€inter-vietnamese-500-normal.woff24KB
πŸ”€inter-vietnamese-600-normal.woff24KB
πŸ–Όlogo-circle-aptos.png994B
πŸ–Όlogo-circle-aptos@4x.png3KB
πŸ–Όlogo-circle-arbitrum.png1KB
πŸ–Όlogo-circle-arbitrum@4x.png3KB
πŸ–Όlogo-circle-avalanche.png530B
πŸ–Όlogo-circle-avalanche@4x.png1KB
πŸ–Όlogo-circle-base.png1KB
πŸ–Όlogo-circle-base@4x.png6KB
πŸ–Όlogo-circle-berachain.png629B
πŸ–Όlogo-circle-berachain@4x.png2KB
πŸ–Όlogo-circle-bitcoin.png599B
πŸ–Όlogo-circle-bitcoin@4x.png2KB
πŸ–Όlogo-circle-bsc.png652B
πŸ–Όlogo-circle-bsc@4x.png2KB
πŸ–Όlogo-circle-cosmos.png964B
πŸ–Όlogo-circle-cosmos@4x.png3KB
πŸ–Όlogo-circle-eclipse-testnet.png776B
πŸ–Όlogo-circle-eclipse-testnet@4x.png2KB
πŸ–Όlogo-circle-eclipse.png328B
πŸ–Όlogo-circle-eclipse@4x.png800B
πŸ–Όlogo-circle-ethereum-sepolia.png979B
πŸ–Όlogo-circle-ethereum-sepolia@4x.png3KB
πŸ–Όlogo-circle-ethereum.png941B
πŸ–Όlogo-circle-ethereum@4x.png3KB
πŸ–Όlogo-circle-fogo.png899B
πŸ–Όlogo-circle-fogo@4x.png3KB
πŸ–Όlogo-circle-gorbagana-testnet.png2KB
πŸ–Όlogo-circle-gorbagana-testnet@4x.png18KB
πŸ–Όlogo-circle-hyperevm.png934B
πŸ–Όlogo-circle-hyperevm@4x.png3KB
πŸ–Όlogo-circle-monad-testnet.png816B
πŸ–Όlogo-circle-monad-testnet@4x.png2KB
πŸ–Όlogo-circle-monad.png507B
πŸ–Όlogo-circle-monad@4x.png1KB
πŸ–Όlogo-circle-optimism.png475B
πŸ–Όlogo-circle-optimism@4x.png1KB
πŸ–Όlogo-circle-plasma.png1KB
πŸ–Όlogo-circle-plasma@4x.png5KB
πŸ–Όlogo-circle-polygon.png579B
πŸ–Όlogo-circle-polygon@4x.png2KB
πŸ–Όlogo-circle-sei.png1KB
πŸ–Όlogo-circle-sei@4x.png4KB
πŸ–Όlogo-circle-solana-devnet.png677B
πŸ–Όlogo-circle-solana-devnet@4x.png2KB
πŸ–Όlogo-circle-solana.png953B
πŸ–Όlogo-circle-solana@4x.png5KB
πŸ–Όlogo-circle-sonic-devnet.png928B
πŸ–Όlogo-circle-sonic-devnet@4x.png3KB
πŸ–Όlogo-circle-sonic.png2KB
πŸ–Όlogo-circle-sonic@4x.png10KB
πŸ–Όlogo-circle-sui-testnet.png562B
πŸ–Όlogo-circle-sui-testnet@4x.png1KB
πŸ–Όlogo-circle-sui.png505B
πŸ–Όlogo-circle-sui@4x.png1KB
πŸ–Όlogo-circle-tron-testnet.png1KB
πŸ–Όlogo-circle-tron-testnet@4x.png3KB
πŸ–Όlogo-circle-tron.png1KB
πŸ–Όlogo-circle-tron@4x.png3KB
πŸ–Όlogo-discord-icon@4x.png956B
πŸ–Όlogo-xnft-icon@4x.png845B
πŸ–Όmad-lads-logo@4x.png3KB
πŸ–Όnotifications_none@4x.png763B
πŸ–Όother-recovery-phrase@4x.png818B
πŸ–Όplatinum@4x.png24KB
πŸ–Όportfolio-active.png384B
πŸ–Όportfolio-active@4x.png950B
πŸ–Όrefer-logo@4x.png874B
πŸ–Όrocket-launch@4x.png2KB
πŸ–Όsearch-icon.png928B
πŸ–Όsecret-key@4x.png620B
πŸ–Όsgqr@4x.png4KB
πŸ–Όshare-bg-backpack-girl@4x.png528KB
πŸ–Όshare-bg-backpack-japan@4x.png522KB
πŸ–Όshare-position-bg-doge@4x.png238KB
πŸ–Όshare-position-bg-empty@4x.png145KB
πŸ–Όshare-position-bg-jupiter@4x.png313KB
πŸ–Όshare-position-bg-mad-lads-1@4x.png348KB
πŸ–Όshare-position-bg-mad-lads-2@4x.png341KB
πŸ–Όshare-position-bg-paris@4x.png345KB
πŸ–Όshare-position-bg-pepe@4x.png123KB
πŸ–Όsilver@4x.png19KB
πŸ–Όsimulator.png1KB
πŸ–Όsolana-pay@4x.png12KB
πŸ–Όunranked@4x.png11KB
πŸ–Όuser-lock@4x.png1KB
πŸ–Όwallet@4x.png913B
β–ΎπŸ“vendor2KB
πŸ“œtrezor-content-script.js306B
πŸ“œtrezor-usb-permissions.js1KB
πŸ“œ1221.js1.1MBlarge
πŸ“„1221.js.LICENSE.txt1KB
πŸ“œ1371.js8KB
πŸ“œ1683.js149KBlarge
πŸ“œ1770.js7KB
πŸ“œ1924.js38KB
πŸ“œ2073.js147KBlarge
πŸ“„2073.js.LICENSE.txt470B
πŸ“œ2210.js10KB
πŸ“œ2280.js22KB
πŸ“œ2282.js439KBlarge
πŸ“„2282.js.LICENSE.txt69B
πŸ“œ2726.js14KB
πŸ“œ3123.js76KBlarge
πŸ“œ3175.js208KBlarge
πŸ“œ3334.js22KB
πŸ“œ3646.js103KBlarge
πŸ“œ3748.js79KBlarge
πŸ“œ3803.js182KBlarge
πŸ“œ3842.js21KB
πŸ“œ3886.js149KBlarge
πŸ“œ4322.js236KBlarge
πŸ“œ4510.js510KBlarge
πŸ“œ4614.js18KB
πŸ“œ4652.js171KBlarge
πŸ“œ4861.js85KBlarge
πŸ“œ5315.js193KBlarge
πŸ“œ537.js288KBlarge
πŸ“œ5529.js524KBlarge
πŸ“œ558.js45KB
πŸ“œ574.js34KB
πŸ“œ5846.js2.8MBlarge
πŸ“„5846.js.LICENSE.txt7KB
πŸ“œ6054.js136KBlarge
πŸ“œ6096.js188KBlarge
πŸ“œ6145.js709KBlarge
πŸ“„6145.js.LICENSE.txt856B
πŸ“œ6475.js103KBlarge
πŸ“œ656.js18KB
πŸ“œ6630.js34KB
πŸ“œ7028.js84KBlarge
πŸ“„7028.js.LICENSE.txt222B
πŸ“œ7282.js13KB
πŸ“œ7452.js6KB
πŸ“œ7462.js3KB
πŸ“œ7474.js3KB
πŸ“œ7616.js208KBlarge
πŸ“œ8419.js24KB
πŸ“œ8565.js171KBlarge
πŸ“œ8589.js28KB
πŸ“œ8596.js973KBlarge
πŸ“„8596.js.LICENSE.txt518B
πŸ“œ8746.js128KBlarge
πŸ“œ9243.js25KB
πŸ“œ9246.js29KB
πŸ“œ9463.js35KB
πŸ“„9463.js.LICENSE.txt267B
πŸ“œ9653.js16KB
πŸ“œ970.js34KB
πŸ“œ9825.js30KB
πŸ“œ9941.js27KB
πŸ–Όanchor-development.png582B
πŸ–Όanchor-production.png576B
πŸ–Όanchor.png576B
πŸ“œbackground.js3.6MBlarge
πŸ“„background.js.LICENSE.txt856B
πŸ“œcontentScript-early-evm.js636B
πŸ“œcontentScript-early-solana.js1KB
πŸ“œcontentScript.js13KB
πŸ“œinjected.js7MBlarge
πŸ“œinpage-evm-early.js4KB
πŸ“œinpage-solana-early.js3KB
{}manifest.json2KB
🌐onboarding.html675B
πŸ“œonboarding.js6.2MBlarge
πŸ“„onboarding.js.LICENSE.txt12KB
🌐options.html3KB
πŸ“œoptions.js922KBlarge
πŸ“„options.js.LICENSE.txt1KB
🌐permissions.html354B
πŸ“œpermissions.js452KBlarge
πŸ“„permissions.js.LICENSE.txt1KB
🌐popout.html728B
🌐popup.html741B
πŸ“œpopup.js187KBlarge
πŸ“„popup.js.LICENSE.txt962B
πŸ“œquickStart.js1KB
🌐sidePanel.html719B
πŸ“œsidePanel.js140B
🌐trezor-usb-permissions.html556B
πŸ“œvendor-aftermath.js324KBlarge
πŸ“œvendor-apollo.js161KBlarge
πŸ“œvendor-cardinal.js223KBlarge
πŸ“„vendor-cardinal.js.LICENSE.txt225B
πŸ“œvendor-ethereumjs.js125KBlarge
πŸ“œvendor-ethers.js470KBlarge
πŸ“„vendor-ethers.js.LICENSE.txt143B
πŸ“œvendor-hardware.js8.6MBlarge
πŸ“œvendor-lightprotocol.js237KBlarge
πŸ“„vendor-lightprotocol.js.LICENSE.txt157B
πŸ“œvendor-mayan.js235KBlarge
πŸ“œvendor-metaplex.js909KBlarge
πŸ“„vendor-metaplex.js.LICENSE.txt225B
πŸ“œvendor-noble.js305KBlarge
πŸ“„vendor-noble.js.LICENSE.txt143B
πŸ“œvendor-serum.js96KBlarge
πŸ“„vendor-serum.js.LICENSE.txt808B
πŸ“œvendor-solana.js391KBlarge
πŸ“„vendor-solana.js.LICENSE.txt4KB
πŸ“œvendor-sui.js469KBlarge
πŸ“„vendor-sui.js.LICENSE.txt160B
πŸ“œvendor-tronweb.js538KBlarge
πŸ“„vendor-tronweb.js.LICENSE.txt143B
πŸ“œvendor-wormhole.js1.6MBlarge
πŸ“„vendor-wormhole.js.LICENSE.txt69B

What This Extension Does

The Backpack extension appears to be a cryptocurrency wallet, allowing users to manage multiple blockchain assets such as Solana, Ethereum, Monad, Sui, and others.

Permissions Explained

  • storage: Allows the extension to store data locally on the user's device.
  • unlimitedStorage: Grants the extension permission to use an unlimited amount of storage space on the user's device. This is unusual for a typical extension and may indicate that the extension requires significant storage capacity.
  • background: Enables the extension to run in the background, allowing it to perform tasks without being actively used by the user.
  • sidePanel: Allows the extension to display a panel or sidebar within the browser.
  • declarativeNetRequest: Grants the extension permission to modify network requests made by the browser. This is unusual for a typical wallet extension and may indicate that the extension is intercepting or modifying web traffic in some way.
  • https://twitter.com/*, https://x.com/*, https://connect.trezor.io/*: These permissions allow the extension to access specific websites or APIs directly from within the browser. This is unusual for a typical wallet extension and may indicate that the extension requires direct access to these services.

What We Found in the Code

  • [high] eval() used β€” can execute arbitrary code: The use of eval() is generally considered a security risk, as it allows execution of arbitrary code. However, without more context, it's difficult to determine if this is being used maliciously or for legitimate purposes.
  • [medium] innerHTML assignment β€” potential XSS vector: Assigning innerHTML can be a potential cross-site scripting (XSS) vulnerability if untrusted data is being inserted into the DOM. However, in many cases, innerHTML is used for UI rendering and may not pose an actual risk.
  • [info] Makes HTTP requests: The extension makes HTTP requests to various domains, which is a normal behavior for any web application or extension that interacts with external services.
  • [high] Listens to keyboard events: Listening to keyboard events can be used for legitimate purposes such as implementing shortcuts. However, without more context, it's difficult to determine if this is being used maliciously.

External Connections

The extension communicates with the following domains:
  • backpack-shared-assets.s3.us-east-1.amazonaws.com: This domain appears to be a storage bucket for shared assets related to the extension.
  • www.w3.org, eips.ethereum.org, and eu.support.backpack.exchange are likely used for documentation, API access, or support purposes.
  • github.com may indicate that the extension uses GitHub APIs or services.
  • Other domains (t.me, blockaid.xnftdata.com, 0x.xnfts.dev, etc.) appear to be related to cryptocurrency or blockchain services.

Things to Consider

Given the extension's purpose as a cryptocurrency wallet, it is expected to interact with various blockchain services and APIs. However, some permissions (e.g., declarativeNetRequest) seem broader than necessary for this type of functionality. The use of eval() and listening to keyboard events may be concerning, but without more context, it's difficult to determine if these are being used maliciously or for legitimate purposes. Users should carefully review the extension's permissions and behavior before installing or using it.

Similar Extensions

More in extensions β†’
Grammarly for Chrome helps you write with confidence. Get AI support for grammar, clarity, and tone, from first draft to…
extensions

Metamask

12M+ users
The world's most trusted crypto wallet
extensions
LastPass is an award-winning password manager for secure credential management on any device.
extensions

Phantom

5M+ users
A crypto wallet reimagined for DeFi & NFTs
extensions