Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeZIlPay extension
Findings · 3
LOW FINDINGS · 3
  1. 01Content script runs on <all_urls> at document_start in all frames and injects inpage.js to expose a Zilliqa wallet provider to every page
  2. 02On every navigation, the current page hostname is sent inside a JSON-RPC GetSmartContractSubState call to api.zilliqa.com (or the user-configured Zilliqa RPC) to query an on-chain phishing registry; the feature is enabled by default and not disclosed to the user as a hostname-reporting behaviour
  3. 03Background script will, on user action, fetch and execute Zilliqa JSON-RPC against http://127.0.0.1:5555 (cleartext, allowed by manifest permissions) if the user selects a local node
OTHER EXTENSIONS

Is ZIlPay extension safe?

Low risk

No summary available.

Khasanshin Rinat Ildarovich, IPv1.8Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026Rinat-IP.zilpay-safari-addon.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact