๐Ÿ“ฆ

Bitget Wallet - Crypto, Web3 | Bitcoin & USDT

๐Ÿ” Security Report Available
๐Ÿ‘ฅ 300K+ users
๐Ÿ“ฆ v2.19.13
๐Ÿ’พ 22.07MiB
๐Ÿ“… 2026-02-05
View on Chrome Web Store

Chrome will indicate if you already have this installed.

Blocks access to a wide range of DeFi services, including wallet management, swap feature, NFT trading, and DApp interaction, bringing a one-stop-shop experience for users looking to explore the world of crypto and blockchain. Most beneficial for cryptocurrency enthusiasts and developers seeking seamless integration with various platforms.

Overview

Secure Web3 crypto wallet extension for Bitcoin, Ethereum, DeFi, token swaps, and cross-chain transactions on 130+ blockchains.

๐Ÿ”น Bitcoin & Multi-Chain Token Swaps
Experience seamless cross-chain trading with Bitget Walletโ€”your multi-chain wallet and token swap extension for Bitcoin, Ethereum, USDT, and more. Our smart routing and gas auto-payment engine make swapping fast, efficient, and gas-optimized-all within your Chrome crypto wallet.
๐Ÿ”น Real-Time Market Tracking in Your Crypto Wallet
With Bitget Wallet Alpha, discover trending tokens and early trading signals across 130+ chains. Spot new opportunitiesโ€”whether you're tracking BTC, ETH, or altcoinsโ€”directly from your crypto browser wallet.
๐Ÿ”น Earn Crypto with DeFi Yield Tools
Stake your assets and earn crypto with stablecoin pools offering up to 8% APY. Bitget Wallet connects you to top DeFi protocols to help you generate crypto yield safely. One-click to join, track, and withdrawโ€”perfect for both beginners and DeFi veterans.
๐Ÿ”น Secure, Self-Custody Chrome Wallet
Bitget Wallet is a non-custodial crypto wallet built on MPC wallet technology. With real-time risk controls and a $300M protection fund, your Bitcoin, Ethereum, and USDT assets stay fully under your controlโ€”inside a battle-tested self-custody wallet extension.
๐Ÿ”น One Wallet for Web3 on Chrome
Manage your entire portfolioโ€”BTC, ETH, stablecoins, and DeFi tokens-in one Web3 wallet extension. From staking and swaps to market tracking, Bitget Wallet is your gateway to the decentralized future, right in your browser.

Bitget Wallet is your trusted Chrome extension for Bitcoin, DeFi, and Web3โ€”built for crypto beginners and pros alike. Secure. Powerful. Easy to use. Bitget Wallet brings crypto for everyone with seamless token swaps, DeFi tools, and self-custody security-all in one Web3 wallet.
Fastest-growing non-custodial wallet with 80M+ users worldwide.
Ranked Top 3 Web3 Wallets by users worldwide.

๐Ÿ‘‰ Download Bigget Wallet now and start your Web3 journey:
Official Website: https://web3.bitget.com/
IOS App: https://apps.apple.com/us/app/bitget-wallet-crypto-bitcoin/id1395301115
Android App: https://play.google.com/store/apps/details?id=com.bitkeep.wallet
X: https://twitter.com/BitgetWallet
Telegram: http://t.me/Bitget_Wallet_Announcement
Discord: https://discord.gg/bitget-wallet

Tags

Productivity/tools productivity/tools

Privacy Practices

โœ“ Not being sold to third parties, outside of the approved use cases
โœ“ Not being used or transferred for purposes that are unrelated to the item's core functionality
โœ“ Not being used or transferred to determine creditworthiness or for lending purposes
v2.19.13 Critical Scanned Feb 22, 2026

Security Analysis

Analyzed v2.19.13 ยท Feb 22, 2026 ยท 8 JS files ยท 56758 KB scanned

Permissions

storage activeTab notifications unlimitedStorage scripting tabs alarms sidePanel contextMenus http://localhost/* *://*/*

Code Patterns Detected

eval() used โ€” can execute arbitrary code Makes HTTP requests Potential data exfiltration pattern

External Connections

cdn.bitkeep.vip www.w3.org conf.chainnear.com links.ethers.org t.me fp-constantid.bitkeep.vip conf.bitkeep.app conf.bitkeep.biz conf.bitkeep.fun conf.bitkeep.life conf.packcard.com web3.bitget.com +8 more

Package Contents 563 files ยท 63.4MB

โ–พ๐Ÿ“_locales6KB
โ–พ๐Ÿ“en
{}messages.json556B
โ–พ๐Ÿ“es
{}messages.json575B
โ–พ๐Ÿ“hi
{}messages.json767B
โ–พ๐Ÿ“id
{}messages.json613B
โ–พ๐Ÿ“ja
{}messages.json562B
โ–พ๐Ÿ“pt
{}messages.json550B
โ–พ๐Ÿ“tu
{}messages.json542B
โ–พ๐Ÿ“vi
{}messages.json546B
โ–พ๐Ÿ“zh
{}messages.json513B
{}index.json565B
โ–พ๐Ÿ“_metadata75KB
{}verified_contents.json75KB
โ–พ๐Ÿ“static63.2MB
โ–พ๐Ÿ“fonts3.4MB
๐Ÿ”คHarmonyOS_Bold.ttf812KB
๐Ÿ”คHarmonyOS_Medium.ttf820KB
๐Ÿ”คHarmonyOS_Regular.ttf823KB
๐Ÿ”คInter-Light.otf244KB
๐Ÿ”คInter-Medium.otf248KB
๐Ÿ”คInter-Regular.otf239KB
๐Ÿ”คInter-SemiBold.otf248KB
โ–พ๐Ÿ“images2.5MB
โ–พ๐Ÿ“common11KB
๐Ÿ–ผLogo.png5KB
๐Ÿ–ผnft-fill-dark.png2KB
๐Ÿ–ผnft-fill.png1KB
๐Ÿ–ผselect.png1KB
๐Ÿ–ผunselect.png2KB
โ–พ๐Ÿ“default17KB
๐Ÿ–ผdapp_fav.png3KB
๐Ÿ–ผdapp_icon.jpg5KB
๐Ÿ–ผdapp_no_network.jpg5KB
๐Ÿ–ผdefault_token.jpg4KB
โ–พ๐Ÿ“icon1.5MB
๐Ÿ–ผAPT.png3KB
๐Ÿ–ผAPTDEV.png3KB
๐Ÿ–ผAPTDEV_GRAY.png4KB
๐Ÿ–ผAPT_GRAY.png4KB
๐Ÿ–ผAPT_MOVE_DARK.png4KB
๐Ÿ–ผAPT_MOVE_LIGHT.png4KB
๐Ÿ–ผAR.png6KB
๐Ÿ–ผAR_GRAY.png6KB
๐Ÿ–ผASM.png3KB
๐Ÿ–ผASM_GRAY.png4KB
๐Ÿ–ผATOM.png9KB
๐Ÿ–ผATOM_GRAY.png8KB
๐Ÿ–ผAURORA.png3KB
๐Ÿ–ผAURORA_GRAY.png4KB
๐Ÿ–ผAVAX_C.png3KB
๐Ÿ–ผAVAX_C_GRAY.png4KB
๐Ÿ–ผAVAX_X.png3KB
๐Ÿ–ผAVAX_X_GRAY.png4KB
๐Ÿ–ผArbitrum.png6KB
๐Ÿ–ผArbitrum_GRAY.png6KB
๐Ÿ–ผBASE.png2KB
๐Ÿ–ผBASE_GRAY.png3KB
๐Ÿ–ผBCH.png6KB
๐Ÿ–ผBCH_GRAY.png5KB
๐Ÿ–ผBGH.png4KB
๐Ÿ–ผBGH_GRAY.png5KB
๐Ÿ–ผBHP.png9KB
๐Ÿ–ผBHP_GRAY.png6KB
๐Ÿ–ผBNB.png4KB
๐Ÿ–ผBNB_GRAY.png5KB
๐Ÿ–ผBOBA.png6KB
๐Ÿ–ผBOBA_GRAY.png5KB
๐Ÿ–ผBRISE.png9KB
๐Ÿ–ผBRISE_GRAY.png4KB
๐Ÿ–ผBSC.png4KB
๐Ÿ–ผBSC_GRAY.png5KB
๐Ÿ–ผBTC.png4KB
๐Ÿ–ผBTC_GRAY.png5KB
๐Ÿ–ผBTC_SIGNET.png7KB
๐Ÿ–ผBTC_SIGNET_GRAY.png5KB
๐Ÿ–ผBTC_TESTNET.png4KB
๐Ÿ–ผBTC_TESTNET_GRAY.png5KB
๐Ÿ–ผBTT.png5KB
๐Ÿ–ผBTT_gray.png7KB
๐Ÿ–ผCARDANO.png7KB
๐Ÿ–ผCARDANO_GRAY.png6KB
๐Ÿ–ผCELO.png7KB
๐Ÿ–ผCELO_GRAY.png7KB
๐Ÿ–ผCFXL2.png2KB
๐Ÿ–ผCFXL2_GRAY.png4KB
๐Ÿ–ผCKB.png3KB
๐Ÿ–ผCKBL2.png3KB
๐Ÿ–ผCKBL2_GRAY.png3KB
๐Ÿ–ผCKB_EVM.png3KB
๐Ÿ–ผCKB_EVM_GRAY.png4KB
๐Ÿ–ผCLO.png6KB
๐Ÿ–ผCLO_GRAY.png5KB
๐Ÿ–ผCMP.png4KB
๐Ÿ–ผCMP_GRAY.png5KB
๐Ÿ–ผCOREDAO.png4KB
๐Ÿ–ผCOREDAO_GRAY.png4KB
๐Ÿ–ผCRO.png17KB
๐Ÿ–ผCROL2.png4KB
๐Ÿ–ผCROL2_GRAY.png5KB
๐Ÿ–ผCRO_GRAY.png5KB
๐Ÿ–ผCSPR.png1KB
๐Ÿ–ผCSPR_GRAY.png1KB
๐Ÿ–ผCUBE.png6KB
๐Ÿ–ผCUBE_GRAY.png6KB
๐Ÿ–ผCZZ.png4KB
๐Ÿ–ผCZZ_GRAY.png5KB
๐Ÿ–ผDASH.png3KB
๐Ÿ–ผDASH_GRAY.png4KB
๐Ÿ–ผDOGE.png3KB
๐Ÿ–ผDOGECHAIN.png19KB
๐Ÿ–ผDOGECHAIN_GRAY.png15KB
๐Ÿ–ผDOGEEVM.png6KB
๐Ÿ–ผDOGEEVM_GRAY.png5KB
๐Ÿ–ผDOGE_GRAY.png4KB
๐Ÿ–ผDOT.png5KB
๐Ÿ–ผDOT_GRAY.png5KB
๐Ÿ–ผDOT_GRAY_OLD.png5KB
๐Ÿ–ผDOT_OLD.png4KB
๐Ÿ–ผDSCC.png10KB
๐Ÿ–ผDSCC1.png7KB
๐Ÿ–ผDSCC1_GRAY.png5KB
๐Ÿ–ผDSCC_GRAY.png5KB
๐Ÿ–ผECLIPSE_DARK.png1KB
๐Ÿ–ผECLIPSE_LIGHT.png1KB
๐Ÿ–ผEGLD.png5KB
๐Ÿ–ผEGLD_GRAY.png6KB
๐Ÿ–ผEOS.png5KB
๐Ÿ–ผEOS_GRAY.png5KB
๐Ÿ–ผETC.png6KB
๐Ÿ–ผETC_GRAY.png6KB
๐Ÿ–ผETH.png4KB
๐Ÿ–ผETH_GRAY.png4KB
๐Ÿ–ผFIL.png3KB
๐Ÿ–ผFIL_GRAY.png4KB
๐Ÿ–ผFIO.png5KB
๐Ÿ–ผFIO_GRAY.png4KB
๐Ÿ–ผFRA.png4KB
๐Ÿ–ผFRA_GRAY.png5KB
๐Ÿ–ผFSC.png140KB
๐Ÿ–ผFSC_GRAY.png4KB
๐Ÿ–ผFTM.png4KB
๐Ÿ–ผFTM_GRAY.png5KB
๐Ÿ–ผFUEL_DARK.png2KB
๐Ÿ–ผFUEL_LIGHT.png2KB
๐Ÿ–ผFUSE.png7KB
๐Ÿ–ผFUSE_GRAY.png5KB
๐Ÿ–ผGT.png4KB
๐Ÿ–ผGT_GRAY.png4KB
๐Ÿ–ผHALO.png6KB
๐Ÿ–ผHALO_GRAY.png6KB
๐Ÿ–ผHBC.png4KB
๐Ÿ–ผHBC_GRAY.png5KB
๐Ÿ–ผHO.png6KB
๐Ÿ–ผHO_GRAY.png7KB
๐Ÿ–ผHT.png4KB
๐Ÿ–ผHTDF.png4KB
๐Ÿ–ผHTDF_GRAY.png4KB
๐Ÿ–ผHT_GRAY.png4KB
๐Ÿ–ผHYPER_EVM.png3KB
๐Ÿ–ผICP.png7KB
๐Ÿ–ผICP_GRAY.png5KB
๐Ÿ–ผINJ.png9KB
๐Ÿ–ผINJ_GRAY.png5KB
๐Ÿ–ผIOST.png4KB
๐Ÿ–ผIOST_GRAY.png5KB
๐Ÿ–ผIOTEX.png6KB
๐Ÿ–ผIOTEX_GRAY.png6KB
๐Ÿ–ผIOTX.png6KB
๐Ÿ–ผIOTX_GRAY.png7KB
๐Ÿ–ผKAI.png5KB
๐Ÿ–ผKAI_GRAY.png4KB
๐Ÿ–ผKAVA.png4KB
๐Ÿ–ผKAVA_GRAY.png3KB
๐Ÿ–ผKCS.png6KB
๐Ÿ–ผKCS_GRAY.png6KB
๐Ÿ–ผKHC.png5KB
๐Ÿ–ผKHC_GRAY.png5KB
๐Ÿ–ผKLAY.png4KB
๐Ÿ–ผKLAY_GRAY.png5KB
๐Ÿ–ผLAT.png4KB
๐Ÿ–ผLAT_GRAY.png3KB
๐Ÿ–ผLGCY.png4KB
๐Ÿ–ผLGCY_GRAY.png5KB
๐Ÿ–ผLINEA.png2KB
๐Ÿ–ผLINEA_GRAY.png3KB
๐Ÿ–ผLINEA_TESTNET_GRAY.png3KB
๐Ÿ–ผLINEA_TEST_NET.png2KB
๐Ÿ–ผLUCKY.png5KB
๐Ÿ–ผLUCKY_GRAY.png4KB
๐Ÿ–ผLUNA.png4KB
๐Ÿ–ผLUNAV2.png10KB
๐Ÿ–ผLUNAV2_GRAY.png5KB
๐Ÿ–ผLUNA_GRAY.png5KB
๐Ÿ–ผMATIC.png17KB
๐Ÿ–ผMATIC_GRAY.png4KB
๐Ÿ–ผMNT.png4KB
๐Ÿ–ผMNT_GRAY.png7KB
๐Ÿ–ผMNT_TESTNET.png4KB
๐Ÿ–ผMNT_TESTNET_GRAY.png7KB
๐Ÿ–ผMTR.png6KB
๐Ÿ–ผMTR_GRAY.png6KB
๐Ÿ–ผNEAR.png4KB
๐Ÿ–ผNEAR_GRAY.png4KB
๐Ÿ–ผNEO.png3KB
๐Ÿ–ผNEO_GRAY.png4KB
๐Ÿ–ผNULS.png4KB
๐Ÿ–ผNULS_GRAY.png4KB
๐Ÿ–ผOKT.png4KB
๐Ÿ–ผOKT_GRAY.png3KB
๐Ÿ–ผONE.png8KB
๐Ÿ–ผONE_GRAY.png4KB
๐Ÿ–ผONT.png3KB
๐Ÿ–ผONT_GRAY.png4KB
๐Ÿ–ผOPBNB.png5KB
๐Ÿ–ผOPBNB_GRAY.png6KB
๐Ÿ–ผOPTIMISM.png4KB
๐Ÿ–ผOPTIMISM_GRAY.png4KB
๐Ÿ–ผPG.png4KB
๐Ÿ–ผPG_GRAY.png5KB
๐Ÿ–ผPLUGCN.png7KB
๐Ÿ–ผPLUGCNEVM.png5KB
๐Ÿ–ผPLUGCNEVM_GRAY.png4KB
๐Ÿ–ผPLUGCN_GRAY.png5KB
๐Ÿ–ผPLUS.png7KB
๐Ÿ–ผPLUS_GRAY.png6KB
๐Ÿ–ผPolygon.png17KB
๐Ÿ–ผPolygon_GRAY.png4KB
๐Ÿ–ผQTUM.png8KB
๐Ÿ–ผQTUM_GRAY.png9KB
๐Ÿ–ผSCDO.png5KB
๐Ÿ–ผSCDO_gray.png6KB
๐Ÿ–ผSEI.png10KB
๐Ÿ–ผSEIATLANTIC2.png10KB
๐Ÿ–ผSEIATLANTIC2_GRAY.png6KB
๐Ÿ–ผSEI_GRAY.png6KB
๐Ÿ–ผSGB.png7KB
๐Ÿ–ผSGB_GRAY.png9KB
๐Ÿ–ผSHM1.png3KB
๐Ÿ–ผSHM1_GRAY.png4KB
๐Ÿ–ผSHM2.png3KB
๐Ÿ–ผSHM2_GRAY.png4KB
๐Ÿ–ผSOL.png9KB
๐Ÿ–ผSOL_GRAY.png3KB
๐Ÿ–ผSOL_SONIC_TESTNET_DARK.png6KB
๐Ÿ–ผSOL_SONIC_TESTNET_LIGHT.png5KB
๐Ÿ–ผSOL_SOON_DARK.png3KB
๐Ÿ–ผSOL_SOON_LIGHT.png4KB
๐Ÿ–ผSTARKNET.png5KB
๐Ÿ–ผSTARKNET_GRAY.png5KB
๐Ÿ–ผSTELLAR_DARK.jpeg21KB
๐Ÿ–ผSUI.png12KB
๐Ÿ–ผSUINET.png12KB
๐Ÿ–ผSUINET_GRAY.png5KB
๐Ÿ–ผSUITEST_GRAY.png5KB
๐Ÿ–ผSUI_GRAY.png5KB
๐Ÿ–ผSYS.png5KB
๐Ÿ–ผSYS_GRAY.png4KB
๐Ÿ–ผScroll.png4KB
๐Ÿ–ผScroll_GRAY.png4KB
๐Ÿ–ผTHUNDERCORE.png8KB
๐Ÿ–ผTHUNDERCORE_GRAY.png4KB
๐Ÿ–ผTLOS.png3KB
๐Ÿ–ผTLOS_GRAY.png1KB
๐Ÿ–ผTOMO.png2KB
๐Ÿ–ผTOMO_GRAY.png2KB
๐Ÿ–ผTON.png3KB
๐Ÿ–ผTON_GRAY.png4KB
๐Ÿ–ผTRUE.png5KB
๐Ÿ–ผTRUE_GRAY.png5KB
๐Ÿ–ผTRX.png5KB
๐Ÿ–ผTRX_GRAY.png5KB
๐Ÿ–ผTT.png8KB
๐Ÿ–ผTT_GRAY.png4KB
๐Ÿ–ผULAM.png4KB
๐Ÿ–ผULAM_GRAY.png5KB
๐Ÿ–ผVLX.png3KB
๐Ÿ–ผVLX_GRAY.png4KB
๐Ÿ–ผVS.png4KB
๐Ÿ–ผVS_GRAY.png4KB
๐Ÿ–ผWAX.png4KB
๐Ÿ–ผWAX_GRAY.png5KB
๐Ÿ–ผWICC.png5KB
๐Ÿ–ผWICC_GRAY.png6KB
๐Ÿ–ผXDAI.png6KB
๐Ÿ–ผXDAI_GRAY.png6KB
๐Ÿ–ผXRP.png5KB
๐Ÿ–ผXRP_GRAY.png4KB
๐Ÿ–ผYTA.png6KB
๐Ÿ–ผYTA_GRAY.png7KB
๐Ÿ–ผZBC.png3KB
๐Ÿ–ผZBC_GRAY.png3KB
๐Ÿ–ผZETAEVM.png4KB
๐Ÿ–ผZETAEVM_GRAY.png3KB
๐Ÿ–ผZETAEVM_TESTNET.png4KB
๐Ÿ–ผZETAEVM_TESTNET_GRAY.png3KB
๐Ÿ–ผZKEVM.png4KB
๐Ÿ–ผZKEVMNET.png4KB
๐Ÿ–ผZKEVMNET_GRAY.png5KB
๐Ÿ–ผZKEVM_GRAY.png5KB
๐Ÿ–ผZKS.png3KB
๐Ÿ–ผZKSV2.png3KB
๐Ÿ–ผZKSV2_GRAY.png3KB
๐Ÿ–ผZKS_GRAY.png3KB
๐Ÿ–ผZTB.png3KB
๐Ÿ–ผZTB_GRAY.png4KB
๐Ÿ–ผicon_facebook.png666B
๐Ÿ–ผicon_telegram.png2KB
๐Ÿ–ผicon_twitter.png1KB
๐Ÿ–ผicon_web.png556B
โ–พ๐Ÿ“icon-img11KB
๐Ÿ–ผ1.png2KB
๐Ÿ–ผ2.png2KB
๐Ÿ–ผ3.png833B
๐Ÿ–ผ4.png2KB
๐Ÿ–ผ5.png1008B
๐Ÿ–ผ6.png1KB
๐Ÿ–ผ7.png1KB
๐Ÿ–ผ8.png690B
๐Ÿ–ผ9.png690B
โ–พ๐Ÿ“json7KB
{}bitkeepLoading.json7KB
โ–พ๐Ÿ“otc5KB
โ–พ๐Ÿ“icons4KB
๐Ÿ–ผc2c_0.png389B
๐Ÿ–ผc2c_1.png364B
๐Ÿ–ผc2c_2.png237B
๐Ÿ–ผc2c_3.png315B
๐Ÿ–ผquick_0.png554B
๐Ÿ–ผquick_1.png698B
๐Ÿ–ผquick_2.png599B
๐Ÿ–ผquick_3.png1KB
๐Ÿ–ผclose.png282B
โ–พ๐Ÿ“rebrand22KB
โ–พ๐Ÿ“system11KB
๐Ÿ–ผconsensus-dark.svg861B
๐Ÿ–ผconsensus.svg861B
๐Ÿ–ผnull-data-dark.svg1014B
๐Ÿ–ผnull-data.svg1010B
๐Ÿ–ผnull-form-dark.svg897B
๐Ÿ–ผnull-form.svg891B
๐Ÿ–ผnull-search-dark.svg535B
๐Ÿ–ผnull-search.svg531B
๐Ÿ–ผofficial-dark.svg2KB
๐Ÿ–ผofficial.svg2KB
๐Ÿ–ผwarn.png2KB
โ–พ๐Ÿ“wallet11KB
๐Ÿ–ผbackup.png2KB
๐Ÿ–ผcheck-risk.png658B
๐Ÿ–ผcheck-safe.png738B
๐Ÿ–ผcheck-warn.png693B
๐Ÿ–ผcopy-words.png1KB
๐Ÿ–ผsafe-save.png2KB
๐Ÿ–ผsafe.png860B
๐Ÿ–ผwords.png2KB
โ–พ๐Ÿ“transaction4KB
๐Ÿ–ผcontract.svg2KB
๐Ÿ–ผtx-pending.svg2KB
โ–พ๐Ÿ“transfer24KB
๐Ÿ–ผContract-light.png2KB
๐Ÿ–ผSecurity-light.png2KB
๐Ÿ–ผSwap-light.png2KB
๐Ÿ–ผTransaction-failed.png2KB
๐Ÿ–ผTransaction-received.png1KB
๐Ÿ–ผTransaction-sending.png1KB
๐Ÿ–ผTransaction-sent.png1KB
๐Ÿ–ผbrowser-light.png3KB
๐Ÿ–ผt-fail.png3KB
๐Ÿ–ผt-success.png3KB
๐Ÿ–ผt-waiting.png3KB
โ–พ๐Ÿ“v2613KB
โ–พ๐Ÿ“activity17KB
๐Ÿ–ผnull.png17KB
โ–พ๐Ÿ“address5KB
๐Ÿ–ผnull.png5KB
โ–พ๐Ÿ“coin3KB
๐Ÿ–ผflat.png2KB
๐Ÿ–ผicon-loading.png2KB
โ–พ๐Ÿ“common110KB
๐Ÿ–ผBgActivityNullDark.svg3KB
๐Ÿ–ผBgActivityNullLight.svg3KB
๐Ÿ–ผaddress_null_dark.svg3KB
๐Ÿ–ผaddress_null_light.svg3KB
๐Ÿ–ผcircle_logo.png2KB
๐Ÿ–ผlogo.svg8KB
๐Ÿ–ผlogoDark.svg8KB
๐Ÿ–ผlogo_dark.svg829B
๐Ÿ–ผlogo_light.svg829B
๐Ÿ–ผsuccess-dark.png28KB
๐Ÿ–ผsuccess.png32KB
๐Ÿ–ผtonWallet.png8KB
๐Ÿ–ผtonWalletDark.png8KB
๐Ÿ–ผton_symbol.png2KB
โ–พ๐Ÿ“createImport66KB
๐Ÿ–ผ1.png10KB
๐Ÿ–ผ12.png1KB
๐Ÿ–ผ2.png4KB
๐Ÿ–ผ24.png1KB
๐Ÿ–ผ3.png14KB
๐Ÿ–ผbgdark.png3KB
๐Ÿ–ผbglight.png3KB
๐Ÿ–ผimport_icon.webp1KB
๐Ÿ–ผsuccess.png4KB
๐Ÿ–ผton1.png13KB
๐Ÿ–ผton1_dark.png11KB
โ–พ๐Ÿ“home113KB
๐Ÿ–ผall-dark.png1KB
๐Ÿ–ผall-light.png1KB
๐Ÿ–ผbackup.png5KB
๐Ÿ–ผbg.svg1KB
๐Ÿ–ผicon1.png4KB
๐Ÿ–ผicon1Dark.png4KB
๐Ÿ–ผicon2.png4KB
๐Ÿ–ผicon2Dark.png4KB
๐Ÿ–ผnewcreate.png20KB
๐Ÿ–ผnewcreateDark.png20KB
๐Ÿ–ผnftnull.png12KB
๐Ÿ–ผsearchNull.png9KB
๐Ÿ–ผsearchNullDark.png9KB
๐Ÿ–ผstarknet1.svg5KB
๐Ÿ–ผstarknet1Dark.svg5KB
๐Ÿ–ผstarknet2.svg4KB
๐Ÿ–ผstarknet2Dark.svg4KB
โ–พ๐Ÿ“nft24KB
๐Ÿ–ผnull.png12KB
๐Ÿ–ผnullDark.png12KB
โ–พ๐Ÿ“orderDetail4KB
๐Ÿ–ผ1.png2KB
๐Ÿ–ผ2.png2KB
โ–พ๐Ÿ“swap13KB
๐Ÿ–ผhome-img.png6KB
๐Ÿ–ผtransaction-dark.png4KB
๐Ÿ–ผtransaction.png3KB
โ–พ๐Ÿ“transfer25KB
๐Ÿ–ผloading.png24KB
๐Ÿ–ผselect.png884B
๐Ÿ–ผselectDark.svg322B
โ–พ๐Ÿ“wallet51KB
๐Ÿ–ผBitgetWallet.png2KB
๐Ÿ–ผCoinBase.png6KB
๐Ÿ–ผMetaMask.png9KB
๐Ÿ–ผOneKey.png5KB
๐Ÿ–ผRabby.png10KB
๐Ÿ–ผSafePal.png5KB
๐Ÿ–ผTokenPocket.png4KB
๐Ÿ–ผTrustWallet.png7KB
๐Ÿ–ผokx.png2KB
๐Ÿ–ผBgActivityNullDark.svg3KB
๐Ÿ–ผBgActivityNullLight.svg3KB
๐Ÿ–ผCopy.svg1KB
๐Ÿ–ผFrame-dark.svg19KB
๐Ÿ–ผFrame-light.svg19KB
๐Ÿ–ผallDark.png1KB
๐Ÿ–ผallLight.png2KB
๐Ÿ–ผfillInfo.svg566B
๐Ÿ–ผgetshield.png5KB
๐Ÿ–ผgetshieldMax.png39KB
๐Ÿ–ผlogo-dark.svg8KB
๐Ÿ–ผlogo-light.svg8KB
๐Ÿ–ผprivate_1_dark.svg2KB
๐Ÿ–ผprivate_1_light.svg2KB
๐Ÿ–ผprivate_2_dark.svg1KB
๐Ÿ–ผprivate_2_light.svg1KB
๐Ÿ–ผprivate_3_dark.svg5KB
๐Ÿ–ผprivate_3_light.svg5KB
๐Ÿ–ผrisk-dark.png23KB
๐Ÿ–ผrisk.png25KB
๐Ÿ–ผriskTwo-dark.png3KB
๐Ÿ–ผriskTwo.png3KB
๐Ÿ–ผstate-little-dark.png3KB
๐Ÿ–ผstate-little-dark.svg572B
๐Ÿ–ผstate-little.png3KB
๐Ÿ–ผstate-little.svg568B
๐Ÿ–ผtipsComm.svg892B
๐Ÿ–ผ4.png3KB
๐Ÿ–ผFrame.svg7KB
๐Ÿ–ผJump.png663B
๐Ÿ–ผMore.png357B
๐Ÿ–ผScreenshot_warning.png10KB
๐Ÿ–ผSecurityTips.png7KB
๐Ÿ–ผTransaction_fail.png3KB
๐Ÿ–ผTransaction_loading.png3KB
๐Ÿ–ผaddressMore.png1KB
๐Ÿ–ผallnetwork.png2KB
๐Ÿ–ผauthorize.png2KB
๐Ÿ–ผback.png3KB
๐Ÿ–ผbackupImg.png15KB
๐Ÿ–ผbell.png3KB
๐Ÿ–ผbit.png5KB
๐Ÿ–ผbitKeep.png5KB
๐Ÿ–ผbitkeep_cover.png1KB
๐Ÿ–ผbrowserLight.png3KB
๐Ÿ–ผchromTool.png3KB
๐Ÿ–ผchromToolDark.png3KB
๐Ÿ–ผconfig-1.png3KB
๐Ÿ–ผconfig-2.png3KB
๐Ÿ–ผconfig-3.png3KB
๐Ÿ–ผconfig-4.png3KB
๐Ÿ–ผcreateSuccess.png10KB
๐Ÿ–ผdapp-icon1.png2KB
๐Ÿ–ผdapp-icon2.png2KB
๐Ÿ–ผdapp.png2KB
๐Ÿ–ผdappLink.png2KB
๐Ÿ–ผding.png408B
๐Ÿ–ผdownload.png712B
๐Ÿ–ผdrag.png277B
๐Ÿ–ผens.png7KB
๐Ÿ–ผeyeclose_line.png788B
๐Ÿ–ผeyeopen_line.png721B
๐Ÿ–ผfacebook.png666B
๐Ÿ–ผfavicon.png2KB
๐Ÿ–ผfilter.png336B
๐Ÿ–ผgithub.png2KB
๐Ÿ–ผhome-img.png6KB
๐Ÿ–ผicon_Triangle.png368B
๐Ÿ–ผicon_triangle_down.png352B
๐Ÿ–ผino.png3KB
๐Ÿ–ผkeyword.png2KB
๐Ÿ–ผlist_a.png2KB
๐Ÿ–ผlist_aboutbk.png761B
๐Ÿ–ผlist_book.png553B
๐Ÿ–ผlist_dapp.png2KB
๐Ÿ–ผlist_feedback.png1KB
๐Ÿ–ผlist_one.png2KB
๐Ÿ–ผlogo.svg8KB
๐Ÿ–ผmatemask.png7KB
๐Ÿ–ผmenuset.png885B
๐Ÿ–ผmore02.png993B
๐Ÿ–ผnav_dapp.png2KB
๐Ÿ–ผnav_lock.png862B
๐Ÿ–ผnav_more.png549B
๐Ÿ–ผnav_refresh.png1KB
๐Ÿ–ผnav_set_wallet.jpg6KB
๐Ÿ–ผnftBg.png28KB
๐Ÿ–ผnftTitle1.png1KB
๐Ÿ–ผnftTitle2.png1KB
๐Ÿ–ผnftTitle3.png670B
๐Ÿ–ผno-data.png5KB
๐Ÿ–ผnodata.png4KB
๐Ÿ–ผnull.png4KB
๐Ÿ–ผnull1.png4KB
๐Ÿ–ผnull_coin_dark.png12KB
๐Ÿ–ผnull_coin_light.png14KB
๐Ÿ–ผnullnft.png2KB
๐Ÿ–ผnullnft2.png2KB
๐Ÿ–ผprotocol.png872B
๐Ÿ–ผquoteSafe.png1KB
๐Ÿ–ผreceive_circle.png1KB
๐Ÿ–ผreceive_success.png3KB
๐Ÿ–ผsend_success.png3KB
๐Ÿ–ผspace.png5KB
๐Ÿ–ผswap.png3KB
๐Ÿ–ผtelegram.png2KB
๐Ÿ–ผtools1.png2KB
๐Ÿ–ผtools2.png1KB
๐Ÿ–ผtools3.png1KB
๐Ÿ–ผtransfer_circle.png1KB
๐Ÿ–ผtransfer_failed.png5KB
๐Ÿ–ผtransfer_success.png5KB
๐Ÿ–ผtwitter.png1KB
๐Ÿ–ผvideoImage.png17KB
๐Ÿ–ผwaiting.png4KB
๐Ÿ–ผwallet.png2KB
๐Ÿ–ผwarning-big.png5KB
๐Ÿ–ผweb.png556B
๐Ÿ–ผwhitepaper.png671B
๐Ÿ–ผwrite.png1KB
โ–พ๐Ÿ“js55.3MB
๐Ÿ“œbackground.js23.5MBlarge
๐Ÿ“„background.js.LICENSE.txt11KB
๐Ÿ“œbundle.js357KBlarge
๐Ÿ“„bundle.js.LICENSE.txt71B
๐Ÿ“œcontentscript.js3.3MBlarge
๐Ÿ“„contentscript.js.LICENSE.txt163B
๐Ÿ“„firebase-messaging-sw.js.LICENSE.txt4KB
๐Ÿ“œfullScreen.js7.8MBlarge
๐Ÿ“„fullScreen.js.LICENSE.txt6KB
๐Ÿ“œinject.js3.2MBlarge
๐Ÿ“„inject.js.LICENSE.txt75B
๐Ÿ“œpopup.js17.3MBlarge
๐Ÿ“„popup.js.LICENSE.txt12KB
๐Ÿ“œthinkingdata.min.js36KB
โ–พ๐Ÿ“media2.1MB
๐Ÿ“„secrets-01-dark.mp4324KB
๐Ÿ“„secrets-01.mp4320KB
๐Ÿ“„secrets-02-dark.mp4221KB
๐Ÿ“„secrets-02.mp4227KB
๐Ÿ“„secrets-03-dark.mp4491KB
๐Ÿ“„secrets-03.mp4516KB
๐Ÿ“œfirebase-messaging-sw.js123KBlarge
{}manifest.json2KB
๐ŸŒnotifications.html319B
๐ŸŒpopup.html302B
๐ŸŒside_panel.html350B
๐ŸŒwelcome.html334B

What This Extension Does

A Web3 wallet extension that allows users to manage crypto assets, swap tokens, and interact with decentralized applications directly from their browser.

Permissions

  • *://*/*check this: This permission lets the extension access and modify any website you visit. For a wallet extension, this is necessary to interact with blockchain networks and DApps, but it also means it can potentially read or alter data on any site. โš  1
  • http://localhost/*check this: This permission allows access to local development servers running on your computer. While useful for developers testing locally, it's not typically needed in production extensions and could be misused if an attacker gains control. โš  1
  • storageexpected: This lets the extension save and retrieve data locally on your computer, such as wallet keys or settings. It's essential for a wallet to remember user preferences and securely store sensitive information.
  • activeTabexpected: This permission allows the extension to read and modify the currently active tab's contentโ€”important for interacting with DApps or performing actions on specific pages like swapping tokens.
  • notificationsexpected: This lets the extension show pop-up messages to alert you about events like transaction confirmations or price changes. It's standard for wallet extensions but should not be used for tracking behavior.
  • unlimitedStorageexpected: This gives the extension unlimited space to store local data on your deviceโ€”useful for caching large amounts of blockchain information or transaction history, but raises concerns about excessive disk usage.
  • scriptingexpected: This permission allows the extension to inject scripts into web pagesโ€”needed for interacting with DApps and executing smart contract calls in a browser environment.
  • tabsexpected: This lets the extension view and manage browser tabsโ€”important for switching between wallets or monitoring transactions across multiple open windows.
  • alarmsexpected: This allows the extension to schedule background tasksโ€”useful for periodic updates like checking balances or syncing with blockchain networks.
  • sidePanelexpected: This enables a side panel that appears within the browser UI, allowing quick access to wallet features like balance checks or transaction history.
  • contextMenusexpected: This lets the extension add custom menu items to right-click menus in the browserโ€”useful for quick actions like copying addresses or swapping tokens directly from any page.

Your Data

The extension can access and send data from any website you visit, including potentially sensitive information like login credentials or transaction details. It also communicates with several external domains for services such as analytics, support, and blockchain interaction.

Code Findings

Use of eval() function detectedHigh

The extension uses a dangerous JavaScript command called 'eval' that can run any code provided to it. This is risky because if an attacker could trick the extension into running malicious code, they might gain full control over your browser.

๐Ÿ’ก In legitimate extensions, eval() might be used to parse JSON or evaluate configuration files at runtime; however, its use here appears excessive and risky without clear justification.

Potential data exfiltration patternMedium

The extension may be sending user dataโ€”possibly including browsing history or wallet informationโ€”to external servers. While this could be part of normal operation (like syncing with a blockchain node), it's worth noting as potentially risky.

๐Ÿ’ก Data transmission may be required for syncing wallet state with backend services or fetching market data, which is common in DeFi wallets.

HTTP requests made to external domainsInfo

The extension makes network calls over HTTP instead of HTTPS. This means that information sent between your browser and those servers could be intercepted by attackers.

๐Ÿ’ก Some internal development environments may still use HTTP during testing phases; however, production deployments should always enforce HTTPS.

Trustworthiness

  • Developer: No developer name or organization listed in the extension metadata; lacks verifiable identity indicators.
  • Privacy Policy: A privacy policy exists but does not clearly explain how data from all origins is handled or whether it's shared with third parties beyond whatโ€™s described in the manifest and external domains.
  • Install Base: With 300K+ installs and regular updates (as per version 2.19.13), it is actively maintained but lacks transparency around developer identity.
Bottom Line

This extension appears consistent with its stated purpose, but the presence of broad network access permissions (*://*/*) and use of eval() raises concerns about potential misuse or exploitation if compromised. Users should exercise caution when installing this extension and consider reviewing its behavior in a controlled environment before using it for real funds.

Extension Overview

A Web3 wallet extension that allows users to manage crypto assets, swap tokens, and interact with decentralized applications directly from their browser.

Permissions

  • *://*/*check this: Grants broad network access via Chrome's declarativeNetRequest API; allows interception of all HTTP/HTTPS traffic from any origin. If compromised, an attacker could monitor or manipulate communications across the entire web, including sensitive financial transactions and personal information. โš  1
  • http://localhost/*check this: Enables network access to localhost (e.g., 127.0.0.1 or ::1), which may allow the extension to communicate with local services such as development APIs or debug tools. Risk is elevated because it can bypass typical browser security restrictions for internal hosts. โš  1
  • storageexpected: Uses Chrome's storage API (chrome.storage.local) to persistently store key-value pairs; includes access to sync storage if enabled. Could be used to persist credentials or session tokens, which would pose a risk if accessed by malicious code.
  • activeTabexpected: Grants access to the current pageโ€™s DOM via chrome.tabs.executeScript, enabling injection of scripts into the active tab. If misused, could allow manipulation of web forms or capture keystrokes during transactions.
  • notificationsexpected: Uses Chrome.notifications API to display UI alerts; no data transmission occurs unless explicitly coded otherwise. However, it could potentially be leveraged in phishing attacks if abused with misleading messages.
  • unlimitedStorageexpected: Allows unrestricted access to chrome.storage.local without quota limits. Could be used to persist sensitive data beyond normal expectations (e.g., logs, cached private keys), increasing attack surface if compromised.
  • scriptingexpected: Enables chrome.scripting API usage, allowing dynamic script injection into tabs. If misused, could enable arbitrary code execution on visited sites or steal session data from other domains.
  • tabsexpected: Provides access to chrome.tabs API, enabling tab navigation, URL inspection, and content manipulation. Could be used to track browsing habits or redirect users without consent if misused.
  • alarmsexpected: Uses chrome.alarms API to trigger scheduled events in background workers; can be used to periodically poll external APIs or perform maintenance operations without user interaction.
  • sidePanelexpected: Enables chrome.sidePanel API for displaying persistent panels in Chrome DevTools or sidebar views. May be used to present interactive dashboards but does not inherently expose data unless combined with other permissions.
  • contextMenusexpected: Uses chrome.contextMenus API to register context-aware actions. Could be misused to inject malicious behavior into user workflows, especially if combined with scripting capabilities.

Data Exposure (Technical)

External origins contacted include cdn.bitkeep.vip, www.w3.org, conf.chainnear.com, links.ethers.org, t.me, fp-constantid.bitkeep.vip, conf.bitkeep.app, conf.bitkeep.biz, conf.bitkeep.fun, conf.bitkeep.life, conf.packcard.com, web3.bitget.com. Data transmitted may include cookies, page content (if injected), authentication tokens, and potentially keystrokes or form inputs depending on how scripts are executed. Some endpoints use HTTP instead of HTTPS, which could allow interception of data in transit.

Code Findings

Use of eval() function detectedHigh

Detected usage of eval() in background scripts or content scriptsโ€”specifically on dynamically constructed strings (not static). If these inputs come from external sources like network responses or user input, this creates a potential vector for remote code execution. The presence of eval() is particularly concerning when combined with dynamic script injection capabilities.

๐Ÿ’ก In legitimate extensions, eval() might be used to parse JSON or evaluate configuration files at runtime; however, its use here appears excessive and risky without clear justification.

Potential data exfiltration patternMedium

Pattern matching detected in code that resembles attempts to send data over HTTP/HTTPS, possibly via XMLHttpRequests or fetch calls. No specific payload was identified but the structure suggests possible exfiltration mechanisms. This is especially concerning given the broad network access permissions and lack of encryption verification for some domains.

๐Ÿ’ก Data transmission may be required for syncing wallet state with backend services or fetching market data, which is common in DeFi wallets.

HTTP requests made to external domainsInfo

Several outbound connections are made using plain HTTP (e.g., conf.bitkeep.app, fp-constantid.bitkeep.vip). These lack TLS encryption, making them vulnerable to man-in-the-middle attacks or eavesdropping. Even if the data itself is not sensitive, it could be used for tracking purposes.

๐Ÿ’ก Some internal development environments may still use HTTP during testing phases; however, production deployments should always enforce HTTPS.

Code Analysis

  • Obfuscation: Code appears heavily obfuscated with techniques such as identifier mangling and string encoding. This makes manual inspection difficult for security researchers trying to understand behavior or detect hidden malicious patterns.
  • Content Security Policy: Content Security Policy is present but allows 'wasm-unsafe-eval' which undermines sandboxing protections. It also restricts script sources only to self, yet still permits unsafe eval usage in extension pagesโ€”a significant weakness that could allow arbitrary code execution if exploited.
  • Architecture: Built as a Manifest V3 extension with background service worker and content scripts injected into all origins (*://*/*). This architecture supports DApp interaction but increases exposure surface due to broad injection scope. Messaging between background and content scripts is likely used for cross-tab communication, though no explicit patterns were found.

Transparency

  • Developer: No developer name or organization listed in the extension metadata; lacks verifiable identity indicators.
  • Privacy Policy: A privacy policy exists but does not clearly explain how data from all origins is handled or whether it's shared with third parties beyond whatโ€™s described in the manifest and external domains.
  • Code Visibility: Source code appears minified/bundled, likely obfuscated. This prevents independent verification of behavior by security researchers or users who want to audit for vulnerabilities.
  • Install Base: With 300K+ installs and regular updates (as per version 2.19.13), it is actively maintained but lacks transparency around developer identity.
Researcher Assessment

The extension presents a high-risk attack surface due to the combination of broad network access, unsafe eval usage, and lack of developer transparency. The CSP allows wasm-unsafe-eval which undermines security boundaries; this is particularly concerning given that the extension handles sensitive financial data. Researchers should prioritize manual inspection of script injection behavior and investigate whether any remote code execution paths exist through dynamically evaluated strings.

Easy-to-use PDF tools to view, edit, convert, fill, e-sign PDF files, and more in your browser.
Productivity/tools AI
๐Ÿ“ฆ

Zotero Connector

7M+ users
Save references to Zotero from your web browser
Productivity/tools
๐Ÿ“ฆ
Browsec VPN is a Chrome VPN extension that protects your IP from Internet threats and lets you browse privately for freeโ€ฆ
Productivity/tools
The ultimate AI translator for web, files, ebooks, academic papers, images, and text
Productivity/tools AI