theseus/bundled-addons/aegis
Local Dev b85605416e Aegis: the PIN is checked by the host, and guessing ends at five
The panel fetched the PIN blob and decrypted it itself, then reported its
own failures. The lockout therefore counted only what a well-behaved panel
chose to report, a 15-minute timer handed out five more guesses forever,
and anything able to run in the panel could take the blob and search the
million PINs offline in minutes.

The blob now never leaves index.js: pinSet builds it after checking the
master password against the vault, pinUnwrap counts each guess before
trying it, and five wrong guesses switch the PIN off until the master
password is entered. The panel keeps its PIN pads and only sends digits.
A blob from an older build (200k iterations) is re-made at 600k under a
fresh salt on the next correct PIN. Only the topmost PIN pad listens to
typed digits, so two stacked pads cannot both take one entry.
2026-10-04 02:17:26 +02:00
..
lib Aegis: refuse a Tron transaction whose fields appear twice 2026-10-04 02:10:51 +02:00
addon.json Aegis 0.31.0: chain adapters stop trusting what they should check 2026-10-04 01:38:50 +02:00
electrum-servers.json Ship Theseus 0.3.28 5d15508b (Aegis update card + DevTools in tab sidebar + real favicons) 2026-09-08 18:17:25 +02:00
index.js Aegis: the PIN is checked by the host, and guessing ends at five 2026-10-04 02:17:26 +02:00
LICENSE Aegis: README and MPL-2.0 license for its own repository 2026-10-04 00:24:01 +02:00
panel.html Aegis: fees that follow the network, connections that come back, its own name on Solana 2026-10-04 01:55:38 +02:00
panel.js Aegis: the PIN is checked by the host, and guessing ends at five 2026-10-04 02:17:26 +02:00
qr.js Ship Theseus 0.3.28 5d15508b (Aegis update card + DevTools in tab sidebar + real favicons) 2026-09-08 18:17:25 +02:00
README.md Aegis: README and MPL-2.0 license for its own repository 2026-10-04 00:24:01 +02:00
wallet-inject.js Aegis: fees that follow the network, connections that come back, its own name on Solana 2026-10-04 01:55:38 +02:00

Aegis

The multi-chain wallet built into Theseus. Aegis runs as a Theseus add-on: it lives in the browser's sidebar and gives web pages a wallet without a separate extension.

  • Chains: Bitcoin Cash (with CashTokens and BCMR metadata), Bitcoin, DigiByte, Ethereum and EVM chains added through wallet_addEthereumChain, Solana, Tron and Siacoin.
  • Keys: every wallet is derived from the Theseus vault, so one master password protects them all. Seeds and private keys can also be imported.
  • Dapps: pages get window.bitcoincash, window.wizardconnect, window.ethereum (EIP-1193), window.solana and window.tronWeb / window.tronLink. Every connection and every signature goes through a Theseus approval overlay that shows what is being signed, decoded from the bytes that get signed.
  • WizardConnect: pair BCH dapps on the same device without scanning a QR.

Layout

addon.json        add-on manifest (id, version, capabilities, update URL)
index.js          the add-on: wallet runtimes, panel messages, dapp bridges
panel.html/.js    the sidebar UI
wallet-inject.js  page-side bridges (isolated world + injected main-world script)
lib/              chain adapters (chain-*.js), transaction and encoding helpers
lib/dgb/          vendored DigiByte address and PSBT modules

Aegis loads its heavier dependencies (@noble/*, @scure/bip32, bitcoinjs-lib, @wizardconnect/*, @bitauth/libauth) from Theseus's dependency tree through the add-on API, so this folder runs only inside Theseus.

Releases

Aegis has its own version and its own update channel, separate from Theseus releases. Theseus checks the signed feed in addon.json's updateURL, verifies the Ed25519 signature and the SHA-256 of the package, and applies the update on the next launch. Each Theseus release also bundles the current Aegis for new installs.

This repository mirrors TheseusNavigator/bundled-addons/aegis from the Theseus source tree, with its history.

License

Mozilla Public License 2.0, see LICENSE. lib/jsqr.js is jsQR, Apache-2.0, see lib/jsqr.LICENSE. WizardConnect (LGPL-3.0-or-later) is not included here; Aegis loads it from Theseus as a separate module.