نسخهٔ فارسی

Transparent, non-custodial, yours

Hardening the wallet that lives in your browser

Fake extensions, malicious updates, clipboard hijacking and over-permissioned add-ons. How a browser wallet gets compromised and how to harden it.

Install source Only the link on the project's own site
Hidden risk Every other extension with page-read permission
Authoritative view The wallet's own prompt, never the web page

FBT Swap

What you should know

A browser wallet is the most convenient way to use decentralised applications and the most exposed place to keep a key. It runs inside the same program you use for everything else, alongside whatever else you have installed.

The risks are specific and so are the mitigations. None of them require giving up the convenience entirely.

Installing the real thing

Fake wallet extensions appear in official stores regularly, sometimes with convincing review counts. Install only from the link on the project's own site, and check the publisher and install count before adding it.

An extension that asks you to import a phrase immediately on install, before you have created anything, is the clearest possible warning sign.

Other extensions are part of your threat model

Any extension with permission to read page content can see what you are doing, and some can modify it. A compromised or sold-on extension — a common fate for popular free ones — inherits that access.

Audit your installed list. Remove anything you do not use. Consider a dedicated browser profile, or a separate browser entirely, used only for wallet activity.

Clipboard and page-level attacks

Clipboard hijackers replace a copied address with the attacker's. Overlay attacks render a fake approval dialog on top of a real page. Both are defeated by verifying the address in your wallet's own prompt rather than on the website.

The wallet prompt is rendered by the extension, not by the page, which is why it is the authoritative view of what you are about to sign.

Sensible limits

Keep the browser wallet as a spending account. Use a hardware wallet as the signer for anything significant — the extension then becomes an interface rather than a key store. Lock the wallet when you walk away, and keep the browser updated.

FBT Swap works with browser wallets and with hardware wallets through them. In either case the signing prompt comes from your wallet, and that prompt is the thing worth reading.

At a glance

At a glance

Install source

Only the link on the project's own site

Hidden risk

Every other extension with page-read permission

Authoritative view

The wallet's own prompt, never the web page

Best hardening

Hardware signer plus a dedicated browser profile

FAQ

Frequently asked questions

Clear answers before you decide.

Is a browser wallet safe for large amounts?

Not as a key store. Paired with a hardware wallet as the signer it becomes a reasonable interface for larger balances, because the key is no longer in the browser at all.

Can a website read my private key from the extension?

No. Pages interact through a restricted interface and cannot access key material. The realistic attack is persuading you to approve something, or compromising the extension itself.

Does a separate browser profile really help?

Yes, meaningfully. It isolates the wallet from unrelated extensions, cookies and sessions, and makes it much harder for a compromised page in normal browsing to interact with your wallet context.

Risk notice

Crypto assets are volatile and on-chain transactions cannot be reversed. You can lose money, including all of it. Nothing here is financial advice.