Is Bearby safe?

Medium risk

ZilPay is medium risk. Our dynamic analysis confirmed that on every website you visit, Bearby sets window.coinbaseWalletExtension, the exact global the Coinbase Wallet SDK checks, alongside window.ethereum flags claiming to be MetaMask and ZilPay.

Rinatv2.0.14Chrome Web Store
45Risk
Who publishes it

Rinat - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Rinat

Same store account

1 other listing published from this account, 10k+ users between them, none of them carrying a finding.

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

viewblock.io
Also called by 5 other listings, including Braavos

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Bearby Wallet flags itself as MetaMask, ZilPay, and Coinbase on every site

Our dynamic analysis confirmed that on every website you visit, Bearby sets window.coinbaseWalletExtension, the exact global the Coinbase Wallet SDK checks, alongside window.ethereum flags claiming to be MetaMask and ZilPay.

Severity
Medium unwanted
Type
Unexpected
CWE
CWE-940
Source
Dynamic sandbox
What actually happens
You did this

You open any website in a normal browser tab.

The extension did this

A script Bearby injects into every page sets window.coinbaseWalletExtension and window.ethereum flags claiming to be MetaMask, ZilPay, and Bearby, all at once.

This runs automatically at page load, before you open the extension or connect a wallet.

The code that does this

The provider's identity flags and injection routine, shipped vs deobfuscated

Readable version

Identity flags declared on the provider class, deobfuscated

injects/evm-provider.js
class y {  isZilPay = !0;  isBearby = !0;  isMetaMask = !0;  supportedMethods = new Set(["eth_requestAccounts", "eth_accounts", "eth_coinbase", "eth_sendTransaction", "eth_getBalance", "eth_getTransactionByHash", "eth_getTransactionReceipt", "eth_call", "eth_estimateGas", "eth_blockNumber", "eth_getBlockByNumber", "eth_getBlockByHash", "eth_subscribe", "eth_unsubscribe", "net_version", "eth_chainId", "eth_getCode", "eth_getStorageAt", "eth_gasPrice", "eth_signTypedData", "eth_signTypedData_v4", "eth_getTransactionCount", "personal_sign", "eth_sign", "wallet_addEthereumChain", "wallet_switchEthereumChain", "wallet_watchAsset", "wallet_getPermissions", "wallet_requestPermissions", "wallet_scanQRCode", "eth_getEncryptionPublicKey", "eth_decrypt"]);

The Coinbase Wallet SDK app-registration stub, deobfuscated

injects/evm-provider.js
setAppInfo(e, n, r, t) {}

The IIFE that assigns the spoofed globals, deobfuscated

injects/evm-provider.js
(function() {  if (typeof window > "u" || !window) {    console.warn("No window object available for Bearby injection");    return  }  if (window.__bearbyInjected) return;  try {    let e = new y;    if (!("ethereum" in window) || !window.ethereum) try {      Object.defineProperty(window, "ethereum", {        value: e,        writable: !1,        configurable: !0      })    } catch (n) {      window.ethereum = e, console.warn("Using fallback assignment for ethereum due to:", n)    }    window.coinbaseWalletExtension = e, j(e), w(e), window.__bearby_response_handlers = window.__bearby_response_handlers || {}, window.__bearbyInjected = !0, window.dispatchEvent(new Event("ethereum#initialized"))  } catch (e) {    console.error("Failed to inject Ethereum provider:", e)  }})();
Identity flags set on the injected provider object
  • Coinbase Wallet global
    window.coinbaseWalletExtension = BearbyProviderImpl instance

    Tells any site checking for Coinbase Wallet that it is installed, when only Bearby is.

  • MetaMask flag
    isMetaMask: true

    Tells sites checking window.ethereum.isMetaMask that MetaMask is installed.

  • ZilPay flag
    isZilPay: true

    Also claims to be the ZilPay wallet on the same object.

  • App-registration stub
    setAppInfo("Uniswap", "https://app.uniswap.org/logo.png") => undefined

    Accepts the call a dApp makes to register its name and logo with Coinbase Wallet, but does nothing with it and returns no error.

Check if you're affected

Checks a loaded page for the spoofed window.coinbaseWalletExtension and window.ethereum wallet-identity flags Bearby injects.

Requires
  • Chrome or any Chromium-based browser
  • Bearby Wallet extension installed
check-wallet-spoofing.js · js
// Paste into the DevTools console on any http(s) page while Bearby Wallet is installed.(function () {  const eth = window.ethereum;  const report = {    hasEthereum: typeof eth !== "undefined",    isMetaMask: eth ? eth.isMetaMask : undefined,    isZilPay: eth ? eth.isZilPay : undefined,    isBearby: eth ? eth.isBearby : undefined,    hasCoinbaseGlobal: typeof window.coinbaseWalletExtension !== "undefined",    sameObjectAsEthereum: window.coinbaseWalletExtension === eth,    setAppInfoIsNoOp:      window.coinbaseWalletExtension &&      typeof window.coinbaseWalletExtension.setAppInfo === "function"        ? window.coinbaseWalletExtension.setAppInfo("TestApp", "https://example.com/logo.png") === undefined        : "n/a",  };  console.table(report);})();
How to run it
  1. 1Install Bearby Wallet.
  2. 2Open any http(s) page.
  3. 3Open DevTools console.
  4. 4Paste and run this script.
  5. 5Read the printed table.
Why this does not fool every dApp

Bearby also implements EIP-6963, the current wallet-discovery standard, and correctly announces itself there as "Bearby Wallet" (rdns io.bearby). Only sites checking window.coinbaseWalletExtension or isMetaMask directly are affected.

Updated 30 September 2026klnaejjgbibmhlephnhpmaofohgkpgkd