Is Bearby safe?
ZilPay is medium risk. Our dynamic analysis confirmed that on every website you visit, Bearby sets window.coinbaseWalletExtension, the exact global the Coinbase Wallet SDK checks, alongside window.ethereum flags claiming to be MetaMask and ZilPay.
Who publishes itRinat - 1 other listing from the same operator, none carrying a finding
Rinat - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 10k+ users between them, none of them carrying a finding.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Bearby Wallet flags itself as MetaMask, ZilPay, and Coinbase on every site
Our dynamic analysis confirmed that on every website you visit, Bearby sets window.coinbaseWalletExtension, the exact global the Coinbase Wallet SDK checks, alongside window.ethereum flags claiming to be MetaMask and ZilPay.
- Severity
- Medium unwanted
- Type
- Unexpected
- CWE
- CWE-940
- Source
- Dynamic sandbox
You open any website in a normal browser tab.
A script Bearby injects into every page sets window.coinbaseWalletExtension and window.ethereum flags claiming to be MetaMask, ZilPay, and Bearby, all at once.
This runs automatically at page load, before you open the extension or connect a wallet.
The provider's identity flags and injection routine, shipped vs deobfuscated
Identity flags declared on the provider class, deobfuscated
injects/evm-provider.jsclass y { isZilPay = !0; isBearby = !0; isMetaMask = !0; supportedMethods = new Set(["eth_requestAccounts", "eth_accounts", "eth_coinbase", "eth_sendTransaction", "eth_getBalance", "eth_getTransactionByHash", "eth_getTransactionReceipt", "eth_call", "eth_estimateGas", "eth_blockNumber", "eth_getBlockByNumber", "eth_getBlockByHash", "eth_subscribe", "eth_unsubscribe", "net_version", "eth_chainId", "eth_getCode", "eth_getStorageAt", "eth_gasPrice", "eth_signTypedData", "eth_signTypedData_v4", "eth_getTransactionCount", "personal_sign", "eth_sign", "wallet_addEthereumChain", "wallet_switchEthereumChain", "wallet_watchAsset", "wallet_getPermissions", "wallet_requestPermissions", "wallet_scanQRCode", "eth_getEncryptionPublicKey", "eth_decrypt"]);The Coinbase Wallet SDK app-registration stub, deobfuscated
injects/evm-provider.jssetAppInfo(e, n, r, t) {}The IIFE that assigns the spoofed globals, deobfuscated
injects/evm-provider.js(function() { if (typeof window > "u" || !window) { console.warn("No window object available for Bearby injection"); return } if (window.__bearbyInjected) return; try { let e = new y; if (!("ethereum" in window) || !window.ethereum) try { Object.defineProperty(window, "ethereum", { value: e, writable: !1, configurable: !0 }) } catch (n) { window.ethereum = e, console.warn("Using fallback assignment for ethereum due to:", n) } window.coinbaseWalletExtension = e, j(e), w(e), window.__bearby_response_handlers = window.__bearby_response_handlers || {}, window.__bearbyInjected = !0, window.dispatchEvent(new Event("ethereum#initialized")) } catch (e) { console.error("Failed to inject Ethereum provider:", e) }})();- Coinbase Wallet globalwindow.coinbaseWalletExtension = BearbyProviderImpl instance
Tells any site checking for Coinbase Wallet that it is installed, when only Bearby is.
- MetaMask flagisMetaMask: true
Tells sites checking window.ethereum.isMetaMask that MetaMask is installed.
- ZilPay flagisZilPay: true
Also claims to be the ZilPay wallet on the same object.
- App-registration stubsetAppInfo("Uniswap", "https://app.uniswap.org/logo.png") => undefined
Accepts the call a dApp makes to register its name and logo with Coinbase Wallet, but does nothing with it and returns no error.
Checks a loaded page for the spoofed window.coinbaseWalletExtension and window.ethereum wallet-identity flags Bearby injects.
- Chrome or any Chromium-based browser
- Bearby Wallet extension installed
// Paste into the DevTools console on any http(s) page while Bearby Wallet is installed.(function () { const eth = window.ethereum; const report = { hasEthereum: typeof eth !== "undefined", isMetaMask: eth ? eth.isMetaMask : undefined, isZilPay: eth ? eth.isZilPay : undefined, isBearby: eth ? eth.isBearby : undefined, hasCoinbaseGlobal: typeof window.coinbaseWalletExtension !== "undefined", sameObjectAsEthereum: window.coinbaseWalletExtension === eth, setAppInfoIsNoOp: window.coinbaseWalletExtension && typeof window.coinbaseWalletExtension.setAppInfo === "function" ? window.coinbaseWalletExtension.setAppInfo("TestApp", "https://example.com/logo.png") === undefined : "n/a", }; console.table(report);})();- 1Install Bearby Wallet.
- 2Open any http(s) page.
- 3Open DevTools console.
- 4Paste and run this script.
- 5Read the printed table.
Bearby also implements EIP-6963, the current wallet-discovery standard, and correctly announces itself there as "Bearby Wallet" (rdns io.bearby). Only sites checking window.coinbaseWalletExtension or isMetaMask directly are affected.