A real export read "1|buffalo body coyote poem …" and was rejected: the classifier only accepted a bare phrase, so a version marker in front of the words was enough to make a valid seed look like junk. Wallets wrap the phrase in their own envelope — a version number, sometimes a derivation path, pipe- or comma-separated, sometimes JSON. Rather than guess which wallet produced it, the payload is now split on every run of non-letters (spaces survive, since they separate the words) and any BIP39-shaped run in the pieces is taken as the phrase. A derivation path found anywhere in the original string is carried over too. Being tolerant of the wrapper does not loosen what counts as a phrase: the pieces must still be 12/15/18/21/24 words of 3-8 lowercase letters, so a URL or an address breaks into single-word pieces and matches nothing. Verified that the phishing-URL and address cases still fill no field. The path only lands in the box when the box is empty. That field is prefilled with the coin's default and may have been edited, and silently changing which addresses get derived is what lost funds look like; if a path is already there and differs, the message names both and leaves the choice to the user. The unrecognised-payload preview also grew to 90 characters, since 48 truncated the evidence needed to tell what a rejected QR actually contained.
29 lines
1.1 KiB
JSON
29 lines
1.1 KiB
JSON
{
|
|
"id": "aegis",
|
|
"name": "Aegis Wallet",
|
|
"version": "0.13.2",
|
|
"category": "plugin",
|
|
"description": "Multi-chain wallet (BCH, BTC, TRX, ETH, SOL, SC, DGB) derived from your Theseus vault. Dapps get window.bitcoincash on .x sites; window.tronWeb / window.tronLink / window.ethereum / window.solana on any https page.",
|
|
"author": "Silent Mode",
|
|
"icon": "data:image/svg+xml;utf8,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 32 32' fill='none'%3E%3Cpolygon points='16,2 28,9 28,23 16,30 4,23 4,9' fill='%230a0a0d' stroke='%23D6FF3D' stroke-width='1.6' stroke-linejoin='round'/%3E%3Ccircle cx='16' cy='16' r='4.5' fill='none' stroke='%23D6FF3D' stroke-width='1.4'/%3E%3Ccircle cx='16' cy='16' r='1.6' fill='%23D6FF3D'/%3E%3C/svg%3E",
|
|
"main": "index.js",
|
|
"updateURL": "https://navigate.st/bns/theseus.x/extensions/aegis/updates.json",
|
|
"capabilities": [
|
|
"sidebar-panel",
|
|
"vault-derive",
|
|
"page-inject",
|
|
"approval-modal",
|
|
"scan-page",
|
|
"open-tab"
|
|
],
|
|
"absorbs": [
|
|
"bchwallet",
|
|
"siawallet"
|
|
],
|
|
"page-inject": {
|
|
"preload": "wallet-inject.js",
|
|
"origins": [
|
|
"https://*/*"
|
|
]
|
|
}
|
|
}
|