theseus/bundled-addons/aegis
Local Dev 70b35e2520 Aegis: the PIN pads use the one Theseus PIN when the host offers it
On a host with api.vault.pin, Aegis no longer keeps a PIN of its own:
its lock-screen, reveal and transaction pads send the digits to the
Theseus vault PIN, which is checked in main against the one strike
counter Settings, the unlock prompt and Pithos also use. The vault is
opened there, and the panel receives a single-use proof (two minutes)
where it used to receive the master password; vaultUnlock, revealSecret
and pinGateSatisfied accept it, still bound to the request it was
entered for. The master password no longer passes through Aegis or its
panel for a PIN entry.

An existing Aegis PIN moves to the vault PIN on its first correct entry.
If Theseus already has a different PIN, the user is asked once which
one to keep. Setting and removing the PIN act on the vault PIN, and
Settings says that it is shared. Hosts without the API (Theseus
0.3.74-0.3.76) keep Aegis's own PIN exactly as before.
2026-10-04 04:19:38 +02:00
..
lib Aegis: smaller hardening from the 0.32 audit 2026-10-04 04:09:45 +02:00
addon.json Aegis 0.32.0: tie the PIN to the TPM, never store it unsealed 2026-10-04 03:42:02 +02:00
electrum-servers.json Ship Theseus 0.3.28 5d15508b (Aegis update card + DevTools in tab sidebar + real favicons) 2026-09-08 18:17:25 +02:00
index.js Aegis: the PIN pads use the one Theseus PIN when the host offers it 2026-10-04 04:19:38 +02:00
LICENSE Aegis: README and MPL-2.0 license for its own repository 2026-10-04 00:24:01 +02:00
panel.html Aegis 0.32.0: tie the PIN to the TPM, never store it unsealed 2026-10-04 03:42:02 +02:00
panel.js Aegis: the PIN pads use the one Theseus PIN when the host offers it 2026-10-04 04:19:38 +02:00
qr.js Ship Theseus 0.3.28 5d15508b (Aegis update card + DevTools in tab sidebar + real favicons) 2026-09-08 18:17:25 +02:00
README.md Aegis: README and MPL-2.0 license for its own repository 2026-10-04 00:24:01 +02:00
wallet-inject.js Aegis: fees that follow the network, connections that come back, its own name on Solana 2026-10-04 01:55:38 +02:00

Aegis

The multi-chain wallet built into Theseus. Aegis runs as a Theseus add-on: it lives in the browser's sidebar and gives web pages a wallet without a separate extension.

  • Chains: Bitcoin Cash (with CashTokens and BCMR metadata), Bitcoin, DigiByte, Ethereum and EVM chains added through wallet_addEthereumChain, Solana, Tron and Siacoin.
  • Keys: every wallet is derived from the Theseus vault, so one master password protects them all. Seeds and private keys can also be imported.
  • Dapps: pages get window.bitcoincash, window.wizardconnect, window.ethereum (EIP-1193), window.solana and window.tronWeb / window.tronLink. Every connection and every signature goes through a Theseus approval overlay that shows what is being signed, decoded from the bytes that get signed.
  • WizardConnect: pair BCH dapps on the same device without scanning a QR.

Layout

addon.json        add-on manifest (id, version, capabilities, update URL)
index.js          the add-on: wallet runtimes, panel messages, dapp bridges
panel.html/.js    the sidebar UI
wallet-inject.js  page-side bridges (isolated world + injected main-world script)
lib/              chain adapters (chain-*.js), transaction and encoding helpers
lib/dgb/          vendored DigiByte address and PSBT modules

Aegis loads its heavier dependencies (@noble/*, @scure/bip32, bitcoinjs-lib, @wizardconnect/*, @bitauth/libauth) from Theseus's dependency tree through the add-on API, so this folder runs only inside Theseus.

Releases

Aegis has its own version and its own update channel, separate from Theseus releases. Theseus checks the signed feed in addon.json's updateURL, verifies the Ed25519 signature and the SHA-256 of the package, and applies the update on the next launch. Each Theseus release also bundles the current Aegis for new installs.

This repository mirrors TheseusNavigator/bundled-addons/aegis from the Theseus source tree, with its history.

License

Mozilla Public License 2.0, see LICENSE. lib/jsqr.js is jsQR, Apache-2.0, see lib/jsqr.LICENSE. WizardConnect (LGPL-3.0-or-later) is not included here; Aegis loads it from Theseus as a separate module.