STOCK BUBBLES

Browser extension crypto wallets

Who holds the keys, whether the code is open, whether development is alive. The score is ours and made only of things that can be checked.

Wallets installed into a browser. 14 entries

NameScoreCodeLast updateCode reviewsKeys
Rabby10/10OpenAugust 29, 20262With the user
Enkrypt8/10MITAugust 19, 2026With the user
MetaMask8/10OpenAugust 30, 2026With the user
Rainbow8/10GPL-3.0August 30, 2026With the user
SubWallet8/10Apache-2.0August 28, 2026With the user
Talisman8/10OpenAugust 28, 2026With the user
Uniswap Wallet8/10GPL-3.0August 17, 2026With the user
Backpack5/10GPL-3.0August 12, 2024With the user
Coinbase Wallet5/10OpenJune 12, 2025With the user
Bitget Wallet2/10ClosedWith the user
Keplr2/10ClosedWith the user
OKX Wallet2/10ClosedWith the user
Phantom2/10ClosedWith the user
Zerion2/10ClosedWith the user

How this kind works

The wallet lives in the browser, next to every page you have open. That suits on-chain applications: the page talks to the wallet directly and a transaction is two clicks away. Hence the main risk is not a stolen file but signing the wrong thing. A page can show one thing and send another for signature, and the difference is hard to see in the confirmation window. The second risk is delivery: an extension updates itself, and one poisoned update reaches everyone at once. Meanwhile the keys sit on the machine that also opens mail and downloads files.

What the score is made of

Wallet: open code 3, development in the past three months 3 (within a year 1), code review 2, keys with the user 2.

A low score means «we could check little», not «this one is a bad choice». Closed code offers nothing to look at — that is an absence of proof, not an accusation.

Open code and development from GitHub, code reviews and networks from DefiLlama. The list itself is ours.