Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeGate Wallet
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Remote config fetched from multiple non-gateio CDN domains can redirect all wallet API traffic to attacker-controlled servers
  2. 02Analytics service generates and persists a unique UUID then sends wallet lifecycle events to app.posthog.com when SUPPORT_ANALYTICS and ENABLE_ANALYTICS_DEFAULT_ON feature flags are enabled
  3. 03Content script on x.com fetches all Twitter card URLs via proxy.dial.to proxy to detect Solana Action links, exposing browsed tweet card URLs to the Dialect proxy server
OTHER EXTENSIONS

Is Gate Wallet safe?

Medium risk

No summary available.

gate.iov2.92.1Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026cpmkedoipcpimgecpmgpldfpohjplkpp

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact