theseus/bundled-addons/aegis
Local Dev cc8a87c5d6 Aegis: dapp overlays show fees and flag risky Solana, Ethereum and Tron calls
Solana: a ComputeBudget price the site added was paid on top of the
base fee but shown as "program ComputeB...: not decoded", so a
transaction could burn the balance in priority fees behind a plain
Sign button. The maximum network fee is now a row, and Assign, durable
nonces, Approve/ApproveChecked, SetAuthority, closing a token account
to someone else and very high fees get a warning and the danger button.
signAndSend also requires one signature slot per required signer.

Ethereum: only allowances of 2^255 and up counted as unlimited; 2^96
and up now does, and Permit2 approve, increaseApproval, NFT
safeTransferFrom and multicall are decoded. The estimate shown was
gas x the node's price even when the site set a far higher tip, which
is what is actually paid; it now uses base fee + the real tip (or the
full legacy gasPrice) and warns when the site's fee is far above the
network's or a fifth of the balance. A personal_sign over 32 raw bytes
is a hash a Safe or an order book will take as approval of something
unseen, so it gets the danger button and the PIN.

Tron: TRC10 sent along with a contract call (call_token_value) was
never read, contract types Aegis does not decode were shown by name as
if harmless, a truncated TRC20 call rendered as "undefined", and the
validity window was hidden. Those are now shown, flagged or refused;
the TronGrid draft check also refuses a memo, a permission id or an
expiration more than a day away.
2026-10-04 03:56:45 +02:00
..
lib Aegis: dapp overlays show fees and flag risky Solana, Ethereum and Tron calls 2026-10-04 03:56:45 +02:00
addon.json Aegis 0.32.0: tie the PIN to the TPM, never store it unsealed 2026-10-04 03:42:02 +02:00
electrum-servers.json Ship Theseus 0.3.28 5d15508b (Aegis update card + DevTools in tab sidebar + real favicons) 2026-09-08 18:17:25 +02:00
index.js Aegis: dapp overlays show fees and flag risky Solana, Ethereum and Tron calls 2026-10-04 03:56:45 +02:00
LICENSE Aegis: README and MPL-2.0 license for its own repository 2026-10-04 00:24:01 +02:00
panel.html Aegis 0.32.0: tie the PIN to the TPM, never store it unsealed 2026-10-04 03:42:02 +02:00
panel.js Aegis: stay-unlocked needs a real keystore and the right password 2026-10-04 03:49:40 +02:00
qr.js Ship Theseus 0.3.28 5d15508b (Aegis update card + DevTools in tab sidebar + real favicons) 2026-09-08 18:17:25 +02:00
README.md Aegis: README and MPL-2.0 license for its own repository 2026-10-04 00:24:01 +02:00
wallet-inject.js Aegis: fees that follow the network, connections that come back, its own name on Solana 2026-10-04 01:55:38 +02:00

Aegis

The multi-chain wallet built into Theseus. Aegis runs as a Theseus add-on: it lives in the browser's sidebar and gives web pages a wallet without a separate extension.

  • Chains: Bitcoin Cash (with CashTokens and BCMR metadata), Bitcoin, DigiByte, Ethereum and EVM chains added through wallet_addEthereumChain, Solana, Tron and Siacoin.
  • Keys: every wallet is derived from the Theseus vault, so one master password protects them all. Seeds and private keys can also be imported.
  • Dapps: pages get window.bitcoincash, window.wizardconnect, window.ethereum (EIP-1193), window.solana and window.tronWeb / window.tronLink. Every connection and every signature goes through a Theseus approval overlay that shows what is being signed, decoded from the bytes that get signed.
  • WizardConnect: pair BCH dapps on the same device without scanning a QR.

Layout

addon.json        add-on manifest (id, version, capabilities, update URL)
index.js          the add-on: wallet runtimes, panel messages, dapp bridges
panel.html/.js    the sidebar UI
wallet-inject.js  page-side bridges (isolated world + injected main-world script)
lib/              chain adapters (chain-*.js), transaction and encoding helpers
lib/dgb/          vendored DigiByte address and PSBT modules

Aegis loads its heavier dependencies (@noble/*, @scure/bip32, bitcoinjs-lib, @wizardconnect/*, @bitauth/libauth) from Theseus's dependency tree through the add-on API, so this folder runs only inside Theseus.

Releases

Aegis has its own version and its own update channel, separate from Theseus releases. Theseus checks the signed feed in addon.json's updateURL, verifies the Ed25519 signature and the SHA-256 of the package, and applies the update on the next launch. Each Theseus release also bundles the current Aegis for new installs.

This repository mirrors TheseusNavigator/bundled-addons/aegis from the Theseus source tree, with its history.

License

Mozilla Public License 2.0, see LICENSE. lib/jsqr.js is jsQR, Apache-2.0, see lib/jsqr.LICENSE. WizardConnect (LGPL-3.0-or-later) is not included here; Aegis loads it from Theseus as a separate module.