CCLab
CC
Email me

Cinder Wallet is my open-source Solana wallet, a Manifest V3 Chrome extension. I wrote it to be small and plain enough to read end to end, with its security boundaries in the places you’d look for them.

The encrypted keyring lives in the extension’s service worker. The popup and the approval window only ever send it requests, so the popup never holds a keypair. Sites connect through Wallet Standard. The content script rebuilds every message field by field and takes the origin from the browser, never from the page, and the worker validates each request and response against one protocol file. Before you sign, the approval screen simulates the transaction and shows the balance change.

License
MIT
Status
Open source
Release
v0.5.0
Case study
Read the case study →

Where a signing request goes

  1. 01Web pageTalks only to the injected Wallet Standard provider
  2. 02Wallet Standard providerConnect, sign transaction, sign and send, sign message
  3. 03Content scriptRebuilds each message field by field and takes the origin from the browser
  4. 04Service workerHolds the encrypted keyring and validates every request and response

The keyring never leaves the service worker.

Read it yourself

It isn’t audited, so don’t put money on it that you can’t afford to lose.

It’s the one project on this site you can check line by line. The code, its tests, the coverage gate and the design records are all in the public repo.

Read the code on GitHub ↗Read the case study →All demos

Questions