# @coinbase/wallet-sdk@4.3.6 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:06:00.000Z
- Files reviewed: 98
- Findings: 1 high, 19 medium, 39 low severity findings
- Report: https://security.togoder.click/npm/@coinbase/wallet-sdk
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @coinbase/wallet-sdk@4.3.6 on Oct 4, 2026. An AI review of 98 source files produced 1 high, 19 medium, 39 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Sensitive Data Persistence in localStorage

Finding ID: `NPS-BA436252BB0E`

File: `dist/store/store.js:60`

The store persists sensitive cryptographic material including `keys`, `account`, and `spendPermissions` to `localStorage` via `createJSONStorage(() => localStorage)`. Any XSS vulnerability in the host application would allow an attacker to exfiltrate these credentials/wallet keys, leading to account compromise or fund theft. The `partialize` function explicitly includes the `keys` slice in persistence, meaning private keys or seed material may be stored in clear text in browser storage.

### [medium] Telemetry / External Script Loading

Finding ID: `NPS-B97756C20F59`

File: `dist/CoinbaseWalletSDK.js:34`

The constructor and makeWeb3Provider method call loadTelemetryScript() which dynamically loads an external telemetry script from a Coinbase-controlled endpoint by default (when preference.telemetry is not false). This constitutes code that runs at import/instantiation time and performs network requests to an external server, potentially transmitting usage data without explicit user consent or transparency. While this is a known, documented feature of Coinbase Wallet SDK for analytics, it represents a data exfiltration vector that should be disclosed and can be disabled.

### [medium] Dynamic Module Loading

Finding ID: `NPS-09E7F6A6D555`

File: `dist/CoinbaseWalletSDK.js:34`

Telemetry script is loaded dynamically via loadTelemetryScript(), which likely injects a <script> tag or uses import() with a hardcoded but external URL. Dynamic loading of external code can be abused if the endpoint is compromised or if the URL is manipulated, leading to arbitrary code execution in the dapp context.

### [medium] Dynamic code execution

Finding ID: `NPS-12B642B2394F`

File: `dist/core/telemetry/initCCA.js:11`

The code injects a script element with content from TELEMETRY_SCRIPT_CONTENT and appends it to the document head, causing immediate execution. While not using eval directly, this is a form of dynamic code execution that can be exploited if the content is attacker-controlled.

### [medium] Data exfiltration

Finding ID: `NPS-9DA09B474449`

File: `dist/core/telemetry/initCCA.js:37`

The code initializes a telemetry client that sends analytics data to an external endpoint 'https://cca-lite.coinbase.com' with a hardcoded Amplitude API key. It also collects and transmits a device identifier. This constitutes data exfiltration to a third-party server, which may be legitimate telemetry but is a privacy and security concern.

### [medium] Telemetry data exfiltration risk

Finding ID: `NPS-8EDBE3D74D5D`

File: `dist/core/telemetry/logEvent.js:39`

The logEvent function forwards SDK usage data to window.ClientAnalytics.logEvent, including appName, appOrigin (window.location.origin), sdkVersion, and arbitrary event payloads. While window.ClientAnalytics is an externally defined object (not directly imported), this represents a telemetry channel that could transmit sensitive application metadata and user interaction events to an external analytics service. The actual destination depends on how ClientAnalytics is initialized elsewhere, which is outside this file's scope.

### [medium] Environment/context harvesting via global object

Finding ID: `NPS-7EB593E338DB`

File: `dist/core/telemetry/logEvent.js:44`

The identify(event) function passes an arbitrary event object to window.ClientAnalytics.identify(), which in analytics SDKs commonly sends user identification data (user IDs, wallet addresses, preference options) to external servers. Combined with store.config.get().preference?.options being included in logEvent, sensitive configuration or preference data may be transmitted externally.

### [medium] Data exfiltration / telemetry collection

Finding ID: `NPS-5DE839AA56DD`

File: `dist/core/telemetry/telemetry-content.js`

The bundled script (Coinbase ClientAnalytics SDK) collects extensive user/device telemetry—device memory, hardware concurrency, network information (effectiveType, RTT, downlink, saveData), user agent/OS/browser fingerprint, storage estimates, session data, referrer/UTM parameters, and user IDs—and transmits it to Coinbase-controlled analytics endpoints (e.g., analytics-service-dev.cbhq.net, as.coinbase.com). This is intentional analytics behavior but represents a privacy-sensitive data collection pattern that should be scrutinized in a third-party dependency.

### [medium] Environment / user data harvesting via IndexedDB and cookies

Finding ID: `NPS-1FB2EC6EE1A8`

File: `dist/core/telemetry/telemetry-content.js`

The code reads/sets persistent data in IndexedDB ('keyval-store'), reads referrer and UTM/campaign params from the URL, and references an auth cookie ('logged_in') plus a JWT ('authorization' header). This is a broad harvesting of user-identifying and session data, though it targets the SDK's own storage rather than credential files like ~/.npmrc or ~/.ssh.

### [medium] Suspicious network requests (sendBeacon / XHR / fetch to external endpoints)

Finding ID: `NPS-5E3FF8843065`

File: `dist/core/telemetry/telemetry-content.js`

Telemetry is exfiltrated via navigator.sendBeacon, XMLHttpRequest, and fetch() to configurable API endpoints, with checksum of the payload signed using the amplitude API key. Endpoint is hardcoded to Coinbase domains but configurable via setConfig, meaning any consumer of this package could redirect telemetry.

### [medium] Minified/obfuscated content in embedded string

Finding ID: `NPS-BB5A62A103EB`

File: `dist/core/telemetry/telemetry-content.js:4`

The exported TELEMETRY_SCRIPT_CONTENT is a large minified JavaScript blob auto-generated by compile-assets.cjs. While this is a legitimate build artifact, embedding minified third-party code as a string reduces auditability and is a common vector for supply-chain attacks if the generator is compromised.

### [medium] Cryptographic key management in third-party code

Finding ID: `NPS-0691615C1E03`

File: `dist/kms/crypto-key/index.js:21`

This module generates and stores P-256 keypairs using WebCryptoP256 (non-extractable) and WebAuthn-style signing bound to the origin 'https://keys.coinbase.com'. While it does not exfiltrate keys or send them over the network, it manages cryptographic material used for signing WebAuthn payloads. Any compromise of the storage layer (createStorage) or modification to this module could allow unauthorized signing on behalf of the user. The keys are stored via a storage abstraction whose security properties are not verifiable from this file alone, and keys are marked non-extractable which limits but does not eliminate risk.

### [medium] Local persistence of sensitive data

Finding ID: `NPS-EF2351C4FFED`

File: `dist/kms/crypto-key/storage.js:3`

The createStorage function stores arbitrary key-value pairs in IndexedDB without encryption. If callers use it to persist cryptographic keys or other secrets, they will be stored in plaintext and remain accessible to any script running on the same origin (including third-party scripts and XSS).

### [medium] Hardcoded chain ID

Finding ID: `NPS-F8FE6C6D7EE0`

File: `dist/sign/scw/utils/handleAddSubAccountOwner.js:51`

The function uses a hardcoded chainId (84532) instead of the account's actual chain ID (account.chain.id). This could cause operations to be sent to the wrong network, potentially leading to asset loss or failed transactions if the wallet is connected to a different chain. While not inherently malicious, it is a dangerous practice.

### [medium] Open redirect / deeplink manipulation

Finding ID: `NPS-341277005B5D`

File: `dist/sign/walletlink/relay/ui/WLMobileRelayUI.js:16`

The code constructs a URL to CBW_MOBILE_DEEPLINK_URL and appends the current page URL (redirect_url) and an optional walletLinkUrl (wl_url) as query parameters, then immediately navigates the user via a synthetic anchor click. If CBW_MOBILE_DEEPLINK_URL is attacker-controlled or the appended parameters are not validated, this could be used for redirect abuse or parameter injection into the Coinbase Wallet deeplink scheme.

### [medium] Wallet Key Management

Finding ID: `NPS-7D699F2B2FCE`

File: `dist/store/store.js:16`

The code manages a `keys` slice and a `spendPermissions` slice, indicating it handles cryptocurrency wallet keys and spending permissions. While not inherently malicious, storing wallet keys in localStorage without encryption is a dangerous practice that could enable key theft if any script injection occurs.

### [medium] Access to injected browser providers / global window state

Finding ID: `NPS-E0869ED4D69D`

File: `dist/util/provider.js:20`

Functions access globalThis.coinbaseWalletExtension, window.ethereum, and window.top.ethereum, and call setAppInfo on them. This reads and mutates host-page wallet provider state, which is sensitive and can be abused to manipulate wallet interactions if the module is compromised.

### [medium] Popup/Window Opener

Finding ID: `NPS-838F2FCE39E3`

File: `dist/util/web.js:24`

The openPopup function uses window.open with a generated popup ID and appends SDK info (name, version, origin, COOP) as query parameters to the URL. While this is a legitimate wallet SDK pattern for authentication flows, opening external popups with dynamic parameters could potentially be abused if the URL is not validated to be same-origin or a trusted domain. However, no explicit URL validation is present in this file, meaning the caller must ensure the URL is trusted.

### [medium] Data collection and exfiltration to external analytics endpoints

Finding ID: `NPS-7DB31F3F5A8B`

File: `dist/vendor-js/CCA/ca.js`

The package `@cbhq/client-analytics` (Coinbase Client Analytics SDK) collects extensive data including user IDs, device IDs, browser fingerprint data (user agent, screen dimensions, device memory, hardware concurrency), session information, page paths, referrer data, UTM parameters, and performance metrics. This data is transmitted to external endpoints such as `https://as.coinbase.com/amp` and `https://analytics-service-dev.cbhq.net/amp` via XHR, fetch, and `navigator.sendBeacon`. While this appears to be an intentional analytics SDK for Coinbase, the broad data collection and transmission to remote servers is a privacy concern and could be considered data exfiltration if used outside its intended context.

### [medium] Additional fingerprinting via UAParser

Finding ID: `NPS-637EE91C914F`

File: `dist/vendor-js/CCA/ca.js`

The bundle includes a UAParser library (module 353) that parses user agent strings to extract browser, engine, OS, device, and CPU architecture details. This is used for fingerprinting and analytics, which is a privacy concern but not malicious per se.

### [low] Environment / Browser Data Access

Finding ID: `NPS-45528FC04D7B`

File: `dist/CoinbaseWalletSDK.js:20`

The code uses getFavicon() to retrieve the current site's favicon and collects app metadata (appName, appLogoUrl, appChainIds) by default. This data is sent to the telemetry system and potentially to the wallet provider. While not credential harvesting, it does access browser/environment data automatically upon instantiation.

### [low] JSON parsing with unsanitized input

Finding ID: `NPS-57248AC8908E`

File: `dist/core/error/errors.js:135`

viemHttpErrorToProviderError parses JSON from error.details. While JSON.parse is generally safe against code execution, the resulting object fields (message, data) may be attacker-controlled and could lead to unexpected behavior if consumed unsafely downstream. This is a minor input validation concern, not a malicious pattern.

### [low] Telemetry Event Logging

Finding ID: `NPS-C81986ABE7C4`

File: `dist/core/telemetry/events/scw-signer.js`

The file defines functions that log analytics events for SCW signer handshake and request lifecycle (started, error, completed). It imports a store and logEvent utility, gathering context like method, correlationId, errorMessage, and enableAutoSubAccounts. No sensitive data exfiltration, credential harvesting, obfuscation, dynamic execution, or suspicious network/file/process operations are present. The logging appears to be standard product telemetry.

### [low] Code runs at import time

Finding ID: `NPS-CE7A578302C7`

File: `dist/core/telemetry/initCCA.js:4`

The loadTelemetryScript function is exported and may be called during module import or initialization, leading to automatic telemetry setup and data transmission without explicit user consent.

### [low] Global object dependency without validation

Finding ID: `NPS-AF24A76F62E8`

File: `dist/core/telemetry/logEvent.js:38`

Both exported functions rely on window.ClientAnalytics without verifying its origin, integrity, or that it is a trusted, expected SDK instance. A malicious or compromised page script could override window.ClientAnalytics to intercept telemetry payloads, and this code would faithfully forward potentially sensitive data to it.

### [low] Dynamic module loading with computed input

Finding ID: `NPS-F50634E3633A`

File: `dist/core/telemetry/telemetry-content.js`

The bundle uses a custom webpack-style module loader with runtime-computed requires (n(2), n(353), n(762), etc.) and dynamic export assignment, plus UMD-style fallback attaching ClientAnalytics to the global object. This is normal bundler output but makes auditing harder and could mask malicious payloads in minified form.

### [low] Telemetry/network exfiltration

Finding ID: `NPS-8A1B5A85F396`

File: `dist/createCoinbaseWalletSDK.js:42`

The SDK conditionally loads a telemetry script via `loadTelemetryScript()` when `options.preference.telemetry` is not set to false. Telemetry can send usage data to external Coinbase servers, which is a potential privacy/data-exfiltration concern, though it is opt-out and part of the official Coinbase Wallet SDK design.

### [low] Dynamic external resource loading

Finding ID: `NPS-838AD6FC88AB`

File: `dist/createCoinbaseWalletSDK.js:42`

`loadTelemetryScript` dynamically loads an external script (telemetry init). If fetched from a remote origin without integrity verification, this could be an avenue for supply-chain injection, though here it is a first-party core module.

### [low] Cryptowallet-related functionality

Finding ID: `NPS-C82C224DBD4D`

File: `dist/createCoinbaseWalletSDK.js:60`

The module implements subaccount creation and owner-adding via EIP-1193 requests (`wallet_addSubAccount`, `wallet_connect`, `wallet_sendCalls`) and encodes ABI calls for on-chain owner management. This is expected wallet SDK behavior, not a drainer pattern, but warrants review to ensure no address rewriting or unauthorized signing occurs.

### [low] Import-time side effect (storage initialization)

Finding ID: `NPS-CC32F5F5904E`

File: `dist/kms/crypto-key/index.js:12`

A storage instance is created at module top-level (export const storage = createStorage(...)), which executes on import. This is a common pattern but constitutes import-time side effect in third-party packages. It does not perform network or filesystem operations outside the storage scope visible here, but the actual behavior depends on createStorage which is not shown.

### [low] Hardcoded external origin / domain binding

Finding ID: `NPS-5E1E945791FB`

File: `dist/kms/crypto-key/index.js:52`

WebAuthn signing payloads are hardcoded to origin 'https://keys.coinbase.com'. This is expected for Coinbase SDK functionality but ties the cryptographic operations to a specific external domain; if this package were used outside that context or if the domain were spoofed, signatures could be produced for unintended relying parties.

### [low] Missing error handling / silent failure

Finding ID: `NPS-AD518A21F810`

File: `dist/kms/crypto-key/storage.js`

getItem, setItem, and removeItem do not handle errors from idb-keyval. In a key-management context, a failed write or delete could leave stale or inconsistent key material, but no error is surfaced to the caller.

### [low] Unvalidated storage scope and name

Finding ID: `NPS-B3588054BBEE`

File: `dist/kms/crypto-key/storage.js:3`

The scope and name arguments are passed directly to createStore without validation, allowing callers to choose arbitrary IndexedDB database/object store names. This could be abused to interfere with other components or to persist data in unexpected locations.

### [low] Encrypted remote communication

Finding ID: `NPS-3281BE89FE32`

File: `dist/sign/scw/SCWSigner.js`

The code sends encrypted requests to a popup communicator and fetches chain/RPC metadata, but uses standard cryptographic helpers and known SDK URLs rather than obvious exfiltration endpoints.

### [low] External RPC/network request

Finding ID: `NPS-EDEC86F3F592`

File: `dist/sign/scw/SCWSigner.js`

Unrecognized JSON-RPC requests are forwarded to a chain RPC URL, and `coinbase_fetchPermissions` calls the hardcoded `CB_WALLET_RPC_URL`; these are expected provider behaviors, not malicious exfiltration.

### [low] Wallet-related signer functionality

Finding ID: `NPS-99DC01FAAEAA`

File: `dist/sign/util.js`

This module implements a signer type selection and wallet link session handshake mechanism for a cryptocurrency wallet SDK (likely Coinbase Wallet SDK, given 'CBWSDK' namespace). It handles wallet connection types (SCW and WalletLink) but does not contain obvious exfiltration, credential harvesting, or key theft patterns. However, it is security-sensitive code managing wallet sessions and signer selection, which warrants scrutiny in a supply chain context.

### [low] Top-level storage initialization

Finding ID: `NPS-94A57638AB87`

File: `dist/sign/util.js:5`

Module-level instantiation of ScopedLocalStorage runs at import time. While not inherently malicious in this context, top-level side effects on import can be a concern if the storage scope is manipulated or if this is used to persist sensitive state unexpectedly.

### [low] Data exfiltration risk

Finding ID: `NPS-3C42C9BCAB59`

File: `dist/sign/walletlink/relay/connection/WalletLinkConnection.js`

The code sends data to a Coinbase Wallet link server URL (linkAPIUrl). While this is expected for a wallet SDK, it includes broadcasting origin and location (location.origin, location.href) along with encrypted event data, which could be used for tracking or analytics. This is a privacy concern but not necessarily malicious.

### [low] Environment and credential access

Finding ID: `NPS-1BF8AA38EE83`

File: `dist/sign/walletlink/relay/connection/WalletLinkConnection.js`

The code uses session secrets and keys (session.secret, session.key) for encryption and authentication. While this is necessary for the SDK's functionality, it handles sensitive cryptographic material. However, no harvesting of external credentials (e.g., .npmrc, ~/.ssh) is observed.

### [low] Dynamic code execution

Finding ID: `NPS-F853C02A7661`

File: `dist/sign/walletlink/relay/connection/WalletLinkConnection.js`

No use of eval, Function constructor, or other dynamic code execution mechanisms was found.

### [low] Suspicious network requests

Finding ID: `NPS-4A2D553D271D`

File: `dist/sign/walletlink/relay/connection/WalletLinkConnection.js`

The code makes WebSocket connections and HTTP requests to a configurable linkAPIUrl. This is expected for a wallet connection SDK, but it could be a vector for data exfiltration if the URL is controlled by an attacker. No hardcoded suspicious external URLs were found.

### [low] File system manipulation

Finding ID: `NPS-5B59E753FD48`

File: `dist/sign/walletlink/relay/connection/WalletLinkConnection.js`

No file system operations (reading, writing, deleting files) were observed.

### [low] Process spawning

Finding ID: `NPS-209D33FC88C1`

File: `dist/sign/walletlink/relay/connection/WalletLinkConnection.js`

No spawning of child processes or shell commands was detected.

### [low] Install-time execution

Finding ID: `NPS-55624DBDB1DA`

File: `dist/sign/walletlink/relay/connection/WalletLinkConnection.js`

This is a library file, not a script that runs at install time. It is part of a larger package (likely @coinbase/wallet-sdk), and its import-time behavior is limited to class definition and constant initialization.

### [low] Credential handling via Basic Auth

Finding ID: `NPS-990AF2AFC057`

File: `dist/sign/walletlink/relay/connection/WalletLinkHTTP.js:6`

The constructor encodes the session key into a Basic Authorization header. While not inherently malicious, this pattern could expose sensitive session material in network logs or if the endpoint is intercepted. It is a standard practice for some wallet relay protocols but warrants review.

### [low] Network requests to configurable endpoint

Finding ID: `NPS-C934CC692084`

File: `dist/sign/walletlink/relay/connection/WalletLinkHTTP.js:12`

The code sends authenticated POST and GET requests to a user‑provided `linkAPIUrl`. If an attacker can control this URL (e.g., via a compromised configuration), session data could be exfiltrated. However, this is expected functionality for a wallet relay client.

### [low] Credential storage in browser storage

Finding ID: `NPS-3A05E0ADAD66`

File: `dist/sign/walletlink/relay/type/WalletLinkSession.js:45`

Session secret is stored in browser storage (localStorage/sessionStorage) via STORAGE_KEY_SESSION_SECRET. While this is a common pattern for session management, secrets stored in browser storage are accessible to any JavaScript running on the same origin, which could be a concern if there is an XSS vulnerability. However, this is not a malicious pattern and is standard for such SDKs.

### [low] Synthetic user interaction / popup bypass

Finding ID: `NPS-5139B989FDA9`

File: `dist/sign/walletlink/relay/ui/WLMobileRelayUI.js:24`

A synthetic anchor element is created and clicked programmatically to navigate to an external deeplink, and a setTimeout is used to trigger a second redirect dialog. This pattern bypasses expected user interaction and could be abused to force navigation without explicit consent.

### [low] Inline SVG data URIs

Finding ID: `NPS-32F2C9364C9F`

File: `dist/sign/walletlink/relay/ui/components/Snackbar/Snackbar.js:7`

The code embeds two base64-encoded SVG images as data URIs (Coinbase logo and gear icon). These are decoded and rendered as images, not evaluated as code. The decoded SVGs appear to be legitimate UI icons with no script content.

### [low] Sensitive data in URL query parameters

Finding ID: `NPS-C6B88A7E4B84`

File: `dist/sign/walletlink/relay/ui/components/util.js:3`

createQrUrl embeds sessionSecret (a shared secret) into a URL query string, which may be exposed via browser history, referrer headers, server logs, or QR code scanning.

### [low] Cross-origin iframe location access

Finding ID: `NPS-BCE47FD410CF`

File: `dist/sign/walletlink/relay/ui/components/util.js:17`

getLocation attempts to read window.top.location when in an iframe. While guarded by try/catch, accessing parent/top location is blocked by same-origin policy and this pattern is sometimes used to probe embedding context.

### [low] Weak cryptographic parameter / potential security risk

Finding ID: `NPS-138902AE04D8`

File: `dist/util/cipher.js`

The encrypt function uses a 12-byte (96-bit) IV for AES-GCM, which is standard. However, the IV is randomly generated with crypto.getRandomValues, which is cryptographically secure. No immediate issue. But note: deriveSharedSecret uses ECDH with P-256 and derives an AES-GCM key, which is secure. No direct malicious pattern.

### [low] Key export/import with extractable flag

Finding ID: `NPS-E5FF96D880B6`

File: `dist/util/cipher.js`

exportKeyToHexString exports private keys as pkcs8 and public keys as spki, and importKeyFromHexString imports them with extractable=true for both public and private keys. This allows private key extraction, which could be a security concern if keys are mishandled, but it is not inherently malicious. It is a design choice for key serialization.

### [low] Potential information leakage via error serialization

Finding ID: `NPS-CC8298CC3FB9`

File: `dist/util/cipher.js`

encryptContent serializes Error objects by including error.code and error.message. This could inadvertently expose sensitive information in error messages when encrypted content is later decrypted. However, this is a functional behavior, not a malicious pattern.

### [low] Suspicious network request

Finding ID: `NPS-DE56C720184D`

File: `dist/util/provider.js:3`

The fetchRPCRequest function uses window.fetch to send arbitrary JSON-RPC requests to a caller-provided rpcUrl. While expected for a wallet SDK, this constitutes a network egress primitive that could be abused to exfiltrate wallet-related data if rpcUrl is attacker-controlled.

### [low] Cross-origin request with identifying headers

Finding ID: `NPS-5753EC407615`

File: `dist/util/provider.js:8`

Requests include X-Cbw-Sdk-Version and X-Cbw-Sdk-Platform headers, fingerprinting the SDK/version/platform to the remote RPC endpoint. Combined with arbitrary rpcUrl this could leak client environment details to third parties.

### [low] Telemetry and Logging

Finding ID: `NPS-A2C143898B17`

File: `dist/util/web.js:2`

The code imports and calls telemetry functions (logSnackbarActionClicked, logSnackbarShown) which may send user interaction data to external servers. While common for analytics, this could be a privacy concern if data is exfiltrated without user consent. The telemetry destination is not visible in this file, so it cannot be fully assessed.

### [low] Dynamic code execution via eval-like patterns

Finding ID: `NPS-09B51B18B878`

File: `dist/vendor-js/CCA/ca.js`

The code contains a Webpack module loader that evaluates modules dynamically using `e[r].call(a.exports, a, a.exports, n)`. While this is standard Webpack bundling behavior, it constitutes dynamic code execution and could be abused if module IDs or content are attacker-controlled. The presence of `Function` constructor or `eval` is not directly observed, but the module system allows runtime execution of bundled code.

### [low] Use of IndexedDB for persistent storage

Finding ID: `NPS-A24443454C44`

File: `dist/vendor-js/CCA/ca.js`

The code uses IndexedDB (`keyval-store`) to persist analytics data such as event IDs, session IDs, and user IDs across sessions. This is standard for analytics but enables long-term tracking.

## Files reviewed

- `dist/CoinbaseWalletSDK.js` (medium): The code is a legitimate Coinbase Wallet SDK entry point, but it automatically loads external telemetry scripts and collects app metadata, which presents privacy and potential data exfiltration concerns that users should be aware of and can disable via preferences.
- `dist/core/telemetry/initCCA.js` (medium): The code performs telemetry data collection and transmission to an external server with a hardcoded API key, raising privacy and security concerns, though no overtly malicious patterns like credential harvesting or backdoors were found.
- `dist/core/telemetry/logEvent.js` (medium): Telemetry module forwards SDK metadata, preferences, and arbitrary events to a globally-defined ClientAnalytics object, presenting a medium-risk data exposure surface depending on where that object sends data.
- `dist/core/telemetry/telemetry-content.js` (medium): This is a bundled Coinbase analytics/telemetry SDK that intentionally collects extensive user, device, session and network data and transmits it to Coinbase endpoints; it is not overtly malicious (no credential theft, shells, crypto miners, or eval), but its aggressive telemetry, persistent storage, and embedded minified payload warrant caution as a third-party dependency.
- `dist/createCoinbaseWalletSDK.js` (medium): No malicious patterns detected; the code is a legitimate Coinbase Wallet SDK entry point with opt-out telemetry and standard wallet functions, though the telemetry/script-loading behavior is worth noting for privacy.
- `dist/kms/crypto-key/index.js` (medium): The code implements Coinbase WebAuthn-style key management and signing without obvious data exfiltration, shell execution, or backdoor patterns, but handles sensitive cryptographic key material and uses an opaque storage abstraction whose security cannot be fully verified from this file alone.
- `dist/kms/crypto-key/storage.js` (medium): The code is a simple IndexedDB wrapper with no exfiltration, code execution, or credential harvesting, but it stores key-value data in plaintext and lacks validation and error handling, which is a moderate concern for a crypto-key storage module.
- `dist/sign/scw/utils/handleAddSubAccountOwner.js` (medium): The code appears to be a legitimate utility for adding sub-account owners in a wallet SDK, but contains a hardcoded chain ID that could result in transactions being sent to an unintended network.
- `dist/sign/util.js` (medium): No malicious patterns detected; code appears to be legitimate wallet signer configuration for a Coinbase Wallet SDK, though the domain is inherently security-sensitive.
- `dist/sign/walletlink/relay/connection/WalletLinkConnection.js` (medium): The code appears to be a legitimate Coinbase Wallet SDK component with expected network communication and cryptographic operations, but no clear malicious patterns were detected.
- `dist/sign/walletlink/relay/connection/WalletLinkHTTP.js` (medium): No malicious patterns detected; code appears to be a legitimate wallet relay client, but it handles sensitive session data and makes configurable network requests.
- `dist/sign/walletlink/relay/ui/WLMobileRelayUI.js` (medium): No clear malicious code, credential harvesting, or exfiltration was found, but the module performs programmatic external deeplink navigation with user-controlled parameters, which warrants a warning.
- `dist/sign/walletlink/relay/ui/components/util.js` (medium): Utility module for WalletLink relay UI has no clear malicious code but exposes a session secret in a URL and accesses top-level window location; treat as low-risk warning.
- `dist/store/store.js` (medium): No overtly malicious behavior (exfiltration, shell execution, obfuscation, or install-time backdoors) was detected, but the module persists sensitive wallet keys and account data in browser localStorage, posing a high risk of credential theft via XSS.
- `dist/util/cipher.js` (medium): The code implements standard ECDH key exchange and AES-GCM encryption without malicious patterns, but uses extractable private keys and serializes error details, which are low-risk security considerations.
- `dist/util/provider.js` (medium): Wallet SDK code that performs RPC fetch calls and accesses injected provider globals; no direct malicious patterns such as exfiltration, credential harvesting, or code execution were found, but it exposes network and wallet-state primitives that warrant review of how rpcUrl and providers are supplied.
- `dist/util/web.js` (medium): The code is a legitimate wallet SDK UI utility for popup handling; no clear malicious patterns like data exfiltration, credential harvesting, or command execution were found, but it includes telemetry and external popup opening that warrant caution.
- `dist/vendor-js/CCA/ca.js` (medium): The package is a legitimate analytics SDK (Coinbase Client Analytics) that collects and transmits user and device data to external servers; while not overtly malicious, it exhibits extensive data collection and tracking behavior that warrants caution.
- `dist/CoinbaseWalletProvider.js` (safe): No malicious patterns detected; the code is a standard Coinbase Wallet provider implementation with telemetry, RPC calls, and signer management.
- `dist/assets/wallet-logo.js` (safe): No malicious patterns detected
- `dist/core/communicator/Communicator.js` (safe): No malicious patterns detected; the code implements a standard popup-based communication channel with origin validation and no data exfiltration, credential harvesting, or dynamic code execution.
- `dist/core/constants.js` (safe): No malicious patterns detected
- `dist/core/error/constants.js` (safe): No malicious patterns detected
- `dist/core/error/errors.js` (safe): No malicious patterns detected; the code is a standard Ethereum JSON-RPC error handling utility with no exfiltration, credential harvesting, dynamic code execution, or network activity.
- `dist/core/error/serialize.js` (safe): No malicious patterns detected; the code is a legitimate error serialization utility that does not exfiltrate data, run dynamic code, access credentials, or spawn processes.
- `dist/core/error/utils.js` (safe): No malicious patterns detected
- `dist/core/message/ConfigMessage.js` (safe): No malicious patterns detected; the file is an empty module export with only a source map reference.
- `dist/core/message/Message.js` (safe): The file contains only an empty export statement and a source map reference, with no executable or malicious code.
- `dist/core/message/RPCMessage.js` (safe): No malicious patterns detected
- `dist/core/message/RPCRequest.js` (safe): No malicious patterns detected
- `dist/core/message/RPCResponse.js` (safe): No malicious patterns detected
- `dist/core/provider/interface.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/core/rpc/coinbase_fetchSpendPermissions.js` (safe): No malicious patterns detected
- `dist/core/rpc/wallet_addSubAccount.js` (safe): No malicious patterns detected
- `dist/core/rpc/wallet_connect.js` (safe): No malicious patterns detected
- `dist/core/rpc/wallet_getSubAccount.js` (safe): The file contains only an empty export and a source map reference, with no executable code or malicious patterns.
- `dist/core/rpc/wallet_prepareCalls.js` (safe): No malicious patterns detected
- `dist/core/rpc/wallet_sendPreparedCalls.js` (safe): This file is an empty ES module re-export with only a source map comment, containing no executable or suspicious code.
- `dist/core/storage/ScopedLocalStorage.js` (safe): No malicious patterns detected; the code is a straightforward localStorage wrapper with scoped keys.
- `dist/core/telemetry/events/communicator.js` (safe): The file only logs telemetry events via an internal logEvent helper and contains no malicious patterns, external network calls, credential harvesting, or dynamic execution.
- `dist/core/telemetry/events/provider.js` (safe): No malicious patterns detected
- `dist/core/telemetry/events/scw-signer.js` (safe): The code only implements telemetry event logging for SCW signer operations and contains no malicious patterns.
- `dist/core/telemetry/events/scw-sub-account.js` (safe): No malicious patterns detected; the file only contains telemetry event logging functions that use internal store and logEvent imports with no data exfiltration, credential harvesting, obfuscation, process spawning, or suspicious network activity.
- `dist/core/telemetry/events/signer-selection.js` (safe): No malicious patterns detected
- `dist/core/telemetry/events/snackbar.js` (safe): The file contains only straightforward telemetry logging functions with no malicious patterns, external network calls, credential access, or dynamic code execution.
- `dist/core/telemetry/events/walletlink-signer.js` (safe): No malicious patterns detected
- `dist/core/telemetry/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/core/type/index.js` (safe): No malicious patterns detected; the code only defines simple type/utility functions with no I/O, network, process, or dynamic execution behavior.
- `dist/core/type/util.js` (safe): No malicious patterns detected; the code implements standard Ethereum/hex utility functions without data exfiltration, credential harvesting, obfuscation, or process execution.
- `dist/createCoinbaseWalletProvider.js` (safe): No malicious patterns detected
- `dist/index.js` (safe): No malicious patterns detected
- `dist/sdk-info.js` (safe): No malicious patterns detected; the file only exports package name and version constants.
- `dist/sign/interface.js` (safe): No malicious patterns detected
- `dist/sign/scw/SCWKeyManager.js` (safe): No malicious patterns detected; the file implements a straightforward ECDH key manager using local storage without network, process, or filesystem abuse.
- `dist/sign/scw/SCWSigner.js` (safe): This SCWSigner implementation appears to be a legitimate wallet signer with expected encrypted popup communication and RPC forwarding, and no clear malicious patterns were detected.
- `dist/sign/scw/utils.js` (safe): No malicious patterns detected
- `dist/sign/scw/utils/constants.js` (safe): The file contains only hardcoded Ethereum contract addresses and ABI definitions with no executable, network, filesystem, or obfuscated code.
- `dist/sign/scw/utils/createSmartAccount.js` (safe): The code implements a Coinbase Smart Account SDK using viem and ox libraries with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or network calls detected.
- `dist/sign/scw/utils/createSubAccountSigner.js` (safe): No malicious patterns detected; the code implements a legitimate Ethereum sub-account signer RPC handler without any data exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `dist/sign/scw/utils/findOwnerIndex.js` (safe): The code is a legitimate utility for finding an owner index in a smart contract and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `dist/sign/scw/utils/handleInsufficientBalance.js` (safe): No malicious patterns detected; the code handles insufficient balance errors in a cryptocurrency wallet context using expected libraries and APIs without exfiltration, obfuscation, or spawns.
- `dist/sign/scw/utils/presentAddOwnerDialog.js` (safe): No malicious patterns detected; the file only presents a UI dialog and logs telemetry events.
- `dist/sign/walletlink/WalletLinkSigner.js` (safe): No malicious patterns detected; the code is a legitimate Ethereum wallet signer with expected network and storage interactions.
- `dist/sign/walletlink/relay/RelayEventManager.js` (safe): No malicious patterns detected; the file only implements a simple request ID manager for WalletLink relay events.
- `dist/sign/walletlink/relay/WalletLinkRelay.js` (safe): No malicious patterns detected
- `dist/sign/walletlink/relay/connection/HeartbeatWorker.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/sign/walletlink/relay/connection/WalletLinkCipher.js` (safe): No malicious patterns detected; the code implements standard AES-GCM encryption/decryption for WalletLink communication without exfiltration, credential harvesting, or execution of untrusted code.
- `dist/sign/walletlink/relay/connection/WalletLinkWebSocket.js` (safe): No malicious patterns detected
- `dist/sign/walletlink/relay/constants.js` (safe): No malicious patterns detected
- `dist/sign/walletlink/relay/mocks/fixtures.js` (safe): No malicious patterns detected; the file contains only static mock test fixtures with no executable or exfiltration logic.
- `dist/sign/walletlink/relay/mocks/relay.js` (safe): This is a benign mock relay module for testing WalletLink interactions, containing only hardcoded fake responses with no network, file system, process execution, or obfuscated code.
- `dist/sign/walletlink/relay/type/ClientMessage.js` (safe): No malicious patterns detected
- `dist/sign/walletlink/relay/type/EthereumTransactionParams.js` (safe): No malicious patterns detected
- `dist/sign/walletlink/relay/type/ServerMessage.js` (safe): No malicious patterns detected
- `dist/sign/walletlink/relay/type/WalletLinkEventData.js` (safe): No malicious patterns detected in the provided stub file; it only contains a copyright comment, an empty export, and a source map reference.
- `dist/sign/walletlink/relay/type/WalletLinkSession.js` (safe): The code is a legitimate session management implementation for Coinbase WalletLink, with no malicious patterns detected; it uses standard cryptographic hashing and random generation for session IDs and secrets.
- `dist/sign/walletlink/relay/type/Web3Request.js` (safe): No malicious patterns detected
- `dist/sign/walletlink/relay/type/Web3Response.js` (safe): No malicious patterns detected in the provided file
- `dist/sign/walletlink/relay/ui/RelayUI.js` (safe): No malicious patterns detected
- `dist/sign/walletlink/relay/ui/WalletLinkRelayUI.js` (safe): No malicious patterns detected; the file contains legitimate UI code for the Coinbase Wallet SDK relay interface.
- `dist/sign/walletlink/relay/ui/components/RedirectDialog/RedirectDialog-css.js` (safe): The file contains only static CSS styling for a dialog component and exhibits no malicious patterns, dynamic code execution, network activity, or filesystem access.
- `dist/sign/walletlink/relay/ui/components/RedirectDialog/RedirectDialog.js` (safe): No malicious patterns detected; the code is a standard UI component for rendering a redirect dialog with no network, filesystem, or process manipulation.
- `dist/sign/walletlink/relay/ui/components/Snackbar/Snackbar-css.js` (safe): This is a pure CSS-in-JS style string for a Coinbase Wallet SDK snackbar UI component with no executable code, network access, or malicious patterns.
- `dist/sign/walletlink/relay/ui/components/Snackbar/Snackbar.js` (safe): No malicious patterns detected; the file contains only benign UI rendering logic for a Snackbar component with static SVG assets and no network, filesystem, or process manipulation.
- `dist/sign/walletlink/relay/ui/components/cssReset/cssReset-css.js` (safe): This file contains only a static CSS reset string exported via an IIFE, with no network, filesystem, process execution, or other malicious patterns.
- `dist/sign/walletlink/relay/ui/components/cssReset/cssReset.js` (safe): No malicious patterns detected
- `dist/store/chain-clients/store.js` (safe): The file simply creates a Zustand vanilla store with an empty object and contains no malicious patterns.
- `dist/store/chain-clients/utils.js` (safe): No malicious patterns detected
- `dist/store/correlation-ids/store.js` (safe): No malicious patterns detected; the code is a simple Zustand store for managing correlation IDs with no external calls, dynamic execution, or file/process access.
- `dist/util/assertPresence.js` (safe): No malicious patterns detected; the file contains only simple validation utility functions with no network, filesystem, or dynamic execution behavior.
- `dist/util/assertSubAccount.js` (safe): No malicious patterns detected; the file only performs input validation for sub-account fields using trusted viem utilities.
- `dist/util/checkCrossOriginOpenerPolicy.js` (safe): No malicious patterns detected; the code only performs a same-origin HEAD request to check the COOP header and logs an error if misconfigured.
- `dist/util/encoding.js` (safe): No malicious patterns detected; the code is a benign WebAuthn encoding utility with standard cryptographic conversions.
- `dist/util/get.js` (safe): The file contains a simple utility function for safe property access on objects with no malicious patterns, external calls, or dynamic code execution.
- `dist/util/validatePreferences.js` (safe): No malicious patterns detected
- `dist/vendor-js/eth-eip712-util/abi.cjs` (safe): No malicious patterns detected; the code is a legitimate Ethereum ABI encoding utility extracted from ethereumjs-abi with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
- `dist/vendor-js/eth-eip712-util/index.cjs` (safe): No malicious patterns detected; this is a standard EIP-712 typed data signing utility with no network, filesystem, process spawning, or obfuscated code.
- `dist/vendor-js/eth-eip712-util/util.cjs` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
