theseus/bundled-addons/aegis/addon.json
Local Dev 3a4f47307c feat(aegis): 0.13.0 — read a seed phrase from a QR image
Import accepts a picture of a QR code. The file is decoded in the panel by
the vendored jsQR, drawn to a canvas: no upload, no network, no camera.

Image, not camera, on purpose. Theseus sets blockCamera + hideMediaDevices
by default and hides device labels from fingerprinting; a camera scanner
would fail silently for everyone until they turned that off globally, and a
wallet should not be the reason a privacy browser gives up the camera. A
photo or screenshot of the code needs no permission at all.

What comes back is classified, never trusted. A QR is opaque to the person
holding it, and "scan this to restore your wallet" is a working phish, so
the decode only chooses which field to fill:

  BIP39-shaped (12/15/18/21/24 lowercase words) -> mnemonic field
  WIF or 32-byte hex                            -> private key field
  anything else                                 -> nothing is filled; the
                                                   decoded text is shown so
                                                   the user can see it was a
                                                   URL, an address, or junk

Nothing auto-submits. The user reads what landed in the box and presses
Import, and the host handler still does the real validation.

jsQR 1.4.0 is vendored at lib/jsqr.js under Apache-2.0 with its LICENSE
beside it, unmodified and unminified — code that touches seed phrases should
be auditable in the shipped add-on, not an opaque blob. It is 57 KB gzipped.

Verified by round-tripping through the shipped path: Aegis's own encoder
builds the QR, it is rasterised to a real PNG File, and decodeQrFile() reads
it back byte-exact; an image with no code returns null rather than throwing;
and driving the actual file input fills the mnemonic for a seed, fills the
key field for a WIF, and leaves every field untouched for a phishing URL.
2026-09-28 00:05:04 +02:00

29 lines
1.1 KiB
JSON

{
"id": "aegis",
"name": "Aegis Wallet",
"version": "0.13.0",
"category": "plugin",
"description": "Multi-chain wallet (BCH, BTC, TRX, ETH, SOL, SC, DGB) derived from your Theseus vault. Dapps get window.bitcoincash on .x sites; window.tronWeb / window.tronLink / window.ethereum / window.solana on any https page.",
"author": "Silent Mode",
"icon": "data:image/svg+xml;utf8,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 32 32' fill='none'%3E%3Cpolygon points='16,2 28,9 28,23 16,30 4,23 4,9' fill='%230a0a0d' stroke='%23D6FF3D' stroke-width='1.6' stroke-linejoin='round'/%3E%3Ccircle cx='16' cy='16' r='4.5' fill='none' stroke='%23D6FF3D' stroke-width='1.4'/%3E%3Ccircle cx='16' cy='16' r='1.6' fill='%23D6FF3D'/%3E%3C/svg%3E",
"main": "index.js",
"updateURL": "https://navigate.st/bns/theseus.x/extensions/aegis/updates.json",
"capabilities": [
"sidebar-panel",
"vault-derive",
"page-inject",
"approval-modal",
"scan-page",
"open-tab"
],
"absorbs": [
"bchwallet",
"siawallet"
],
"page-inject": {
"preload": "wallet-inject.js",
"origins": [
"https://*/*"
]
}
}