Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeHOT Wallet
Findings · 3
MEDIUM FINDINGS · 3
  1. 01MAIN-world injected script accepts wallet response messages without validating event.origin, allowing cross-origin spoofing of wallet responses
  2. 02Extension injects window.ethereum with isMetaMask=true on all web pages, impersonating MetaMask
  3. 03Extension fetches remote chain configuration from app.hot-labs.org/chains.json that controls RPC endpoints, swap routers, bridge configuration, and fee parameters
OTHER EXTENSIONS

Is HOT Wallet safe?

Medium risk

No summary available.

HERE Walletv1.0.133Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026mpeengabcnhhjjgleiodimegnkpcenbk

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact