A 6-digit PIN behind PBKDF2 + DPAPI falls in minutes to anything that can open DPAPI (malware running as the user, a disk image plus the Windows password). The PIN is now also the authorization value of a TPM key from the Microsoft Platform Crypto Provider; the key releases a secret mixed with PBKDF2(pin), so the stored blob alone opens nothing and the chip's own lockout (32 failures, then one per 10 minutes) limits guesses however the blob was obtained. Reached through Windows PowerShell's CNG classes with the PIN on stdin, so no native module. Machines without a TPM keep the software PIN, and Settings now says plainly what that protects against. A PIN is no longer stored when there is no real OS keystore (including Linux's basic_text backend, whose key is a constant); a pre-0.31 plain blob is sealed or deleted and remembered, so the panel can tell the user to change the master password if the profile was ever copied. |
||
|---|---|---|
| .. | ||
| lib | ||
| addon.json | ||
| electrum-servers.json | ||
| index.js | ||
| LICENSE | ||
| panel.html | ||
| panel.js | ||
| qr.js | ||
| README.md | ||
| wallet-inject.js | ||
Aegis
The multi-chain wallet built into Theseus. Aegis runs as a Theseus add-on: it lives in the browser's sidebar and gives web pages a wallet without a separate extension.
- Chains: Bitcoin Cash (with CashTokens and BCMR metadata), Bitcoin,
DigiByte, Ethereum and EVM chains added through
wallet_addEthereumChain, Solana, Tron and Siacoin. - Keys: every wallet is derived from the Theseus vault, so one master password protects them all. Seeds and private keys can also be imported.
- Dapps: pages get
window.bitcoincash,window.wizardconnect,window.ethereum(EIP-1193),window.solanaandwindow.tronWeb/window.tronLink. Every connection and every signature goes through a Theseus approval overlay that shows what is being signed, decoded from the bytes that get signed. - WizardConnect: pair BCH dapps on the same device without scanning a QR.
Layout
addon.json add-on manifest (id, version, capabilities, update URL)
index.js the add-on: wallet runtimes, panel messages, dapp bridges
panel.html/.js the sidebar UI
wallet-inject.js page-side bridges (isolated world + injected main-world script)
lib/ chain adapters (chain-*.js), transaction and encoding helpers
lib/dgb/ vendored DigiByte address and PSBT modules
Aegis loads its heavier dependencies (@noble/*, @scure/bip32,
bitcoinjs-lib, @wizardconnect/*, @bitauth/libauth) from Theseus's
dependency tree through the add-on API, so this folder runs only inside
Theseus.
Releases
Aegis has its own version and its own update channel, separate from Theseus
releases. Theseus checks the signed feed in addon.json's updateURL,
verifies the Ed25519 signature and the SHA-256 of the package, and applies the
update on the next launch. Each Theseus release also bundles the current Aegis
for new installs.
This repository mirrors TheseusNavigator/bundled-addons/aegis from the
Theseus source tree, with its history.
License
Mozilla Public License 2.0, see LICENSE. lib/jsqr.js is jsQR,
Apache-2.0, see lib/jsqr.LICENSE. WizardConnect (LGPL-3.0-or-later) is not
included here; Aegis loads it from Theseus as a separate module.