Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeUniSat Wallet
Findings · 3
+5 more findings locked
MEDIUM FINDINGS · 3
  1. 01Active dapp website URL transmitted to UniSat API via checkWebsite endpoint
  2. 02New in v1.7.15: six wallet-data APIs (getPublicKey, getBalance, getInscriptions, getBitcoinUtxos, cosmosGetKey) promoted to SAFE, callable by connected dApps without wallet unlock
  3. 03New in v1.7.11: during PSBT sign-request analysis the extension POSTs the user's UTXO outpoints (txid:vout pairs) to wallet-api.unisat.io/v5/utxo/assets-by-outpoints to check for inscriptions/runes/alkanes
+5 more findings locked
OTHER EXTENSIONS

Is UniSat Wallet safe?

Medium risk

No summary available.

UniSat Teamv1.7.10Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+5 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026ppbibelpcjmhbdihakflkdcoccbgbkpo

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact