Lab · Demo 04 · Cinder Wallet
Cinder Wallet signing walkthrough
Follow a signing request through Cinder Wallet, from the web page to the keyring, with the code for each step. MIT licensed, not audited.
Cinder Wallet is my open-source Solana wallet, a Manifest V3 Chrome extension. I wrote it to be small and plain enough to read end to end, with its security boundaries in the places you’d look for them.
The encrypted keyring lives in the extension’s service worker. The popup and the approval window only ever send it requests, so the popup never holds a keypair. Sites connect through Wallet Standard. The content script rebuilds every message field by field and takes the origin from the browser, never from the page, and the worker validates each request and response against one protocol file. Before you sign, the approval screen simulates the transaction and shows the balance change.
- License
- MIT
- Status
- Open source
- Release
- v0.5.0
- Case study
- Read the case study →
Where a signing request goes
- 01Web pageTalks only to the injected Wallet Standard provider
- 02Wallet Standard providerConnect, sign transaction, sign and send, sign message
- 03Content scriptRebuilds each message field by field and takes the origin from the browser
- 04Service workerHolds the encrypted keyring and validates every request and response
The keyring never leaves the service worker.
Read it yourself
It isn’t audited, so don’t put money on it that you can’t afford to lose.
It’s the one project on this site you can check line by line. The code, its tests, the coverage gate and the design records are all in the public repo.