# @gemini-wallet/core@0.3.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:06:30.000Z
- Files reviewed: 21
- Findings: 1 medium, 9 low severity findings
- Report: https://security.togoder.click/npm/@gemini-wallet/core
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @gemini-wallet/core@0.3.2 on Oct 4, 2026. An AI review of 21 source files produced 1 medium, 9 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Hardcoded contract addresses and creation bytecode

Finding ID: `NPS-69C730E40655`

File: `dist/index.cjs`

predictProxyAddress embeds raw EVM creation bytecode (nexusProxyCreationCode). Hardcoded contract bytecode and addresses in a wallet SDK are typical for deterministic address prediction but increase risk if the package were tampered with to compute attacker-controlled addresses.

### [low] External network requests to third-party backend

Finding ID: `NPS-4610414F426F`

File: `dist/index.cjs`

The SDK communicates with a Gemini-operated backend at https://keys.gemini.com and https://horizon-api.gemini.com/api/ens. Popup-based message posting uses window.postMessage with origin checks against the SDK backend origin. While typical for a wallet SDK, all user actions (connect, sign, send transaction, typed data) are routed to this external backend, meaning dApp data and user intents are sent off-device.

### [low] RPC URL auto-population from chain defaults

Finding ID: `NPS-8BEF9D666680`

File: `dist/index.cjs`

getDefaultRpcUrl falls back to public RPC endpoints for supported chains. If a custom chain's rpcUrl is missing, requests (including personal_sign output and transaction params) may be sent to third-party RPCs. Not inherently malicious but expands trust surface to external RPC providers.

### [low] PostMessage origin validation

Finding ID: `NPS-54C087EF0C3A`

File: `dist/index.cjs`

Communicator.onMessage validates event.origin against the SDK backend URL origin before trusting message data. This is a positive security control, but any compromise of keys.gemini.com would allow injection of malicious popup messages to the dApp.

### [low] LocalStorage credential/account persistence

Finding ID: `NPS-A2D8F0CA1FE2`

File: `dist/index.cjs`

GeminiStorage persists account addresses, chain configuration, passkey credential keys, and call batch metadata in localStorage under a scoped namespace. Storage of passkey-related keys (STORAGE_PASSKEY_CREDENTIAL_KEY, STORAGE_PRESERVED_PASSKEY_CREDENTIALS_KEY) in localStorage may be sensitive, though these are credential IDs rather than private keys in this file.

### [low] Header-injected JSON-RPC fetch

Finding ID: `NPS-4AA0B08C655E`

File: `dist/index.cjs`

fetchRpcRequest posts arbitrary JSON-RPC requests to a configured RPC URL. Method routing falls through to this for unknown methods, meaning any method not explicitly handled is forwarded to the RPC endpoint. This could leak wallet-related state to external RPC if misused by a dApp.

### [low] No install-time execution

Finding ID: `NPS-516E1D7B8BCD`

File: `dist/index.cjs`

No top-level side effects observed other than module export construction. No npm lifecycle scripts with malicious commands (build uses tsup, dev uses tsup --watch).

### [low] Insecure postMessage targetOrigin

Finding ID: `NPS-FCFC8806B6E4`

File: `src/communicator.ts:41`

The postMessage call uses this.url.origin, which is derived from SDK_BACKEND_URL (imported from ./utils). If SDK_BACKEND_URL can be influenced by environment variables or build-time configuration, this could potentially send sensitive SDK messages to an unintended origin. However, the origin is validated on incoming messages (event.origin !== this.url.origin), which mitigates most risk. The actual value of SDK_BACKEND_URL is not visible in this file and would need to be verified.

### [low] Sensitive window messaging without full validation

Finding ID: `NPS-80242650550C`

File: `src/communicator.ts:60`

The onMessage handler only validates event.origin but does not validate event.source against the expected popup window reference. This could theoretically allow a same-origin or origin-spoofing scenario, though origin checking provides reasonable protection in practice.

### [low] Data transmission to external server

Finding ID: `NPS-C835AB83D109`

File: `src/communicator.ts:112`

The communicator sends app metadata (appMetadata, window.location.origin, sdkVersion) to the popup backend on load. This is expected behavior for an SDK but involves transmitting application context data to an external origin. The data appears limited to non-sensitive metadata (app name, origin, version) and is part of the documented SDK functionality.

## Files reviewed

- `dist/index.cjs` (medium): The package appears to be a legitimate Gemini Wallet SDK with expected external backend communication, localStorage persistence, and hardcoded contract bytecode; no data exfiltration, credential harvesting, obfuscation, or install-time execution was detected.
- `src/communicator.ts` (medium): The code is a legitimate-looking SDK communicator that exchanges messages with a configured backend popup; no malicious patterns such as exfiltration, credential harvesting, shell execution, or obfuscation were found, though standard postMessage origin practices could be tightened.
- `dist/index.js` (safe): This is a legitimate Gemini Wallet SDK that communicates with the official keys.gemini.com backend via popups and RPC; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoor installation are present.
- `src/constants.ts` (safe): No malicious patterns detected; the file only defines constants, chain IDs, and RPC URL helpers without any suspicious behavior.
- `src/index.ts` (safe): This is a standard entry point file that only re-exports modules and symbols; it contains no executable code, network calls, dynamic execution, or other malicious patterns.
- `src/provider/index.ts` (safe): No malicious patterns detected; the file only contains standard ES module re-exports with no runtime logic or side effects.
- `src/provider/provider.ts` (safe): No malicious patterns detected; the code is a legitimate Ethereum wallet provider implementation handling standard RPC methods.
- `src/provider/provider.utils.ts` (safe): No malicious patterns detected; the code performs standard RPC request handling and validation without exfiltration, credential harvesting, or dynamic code execution.
- `src/storage/index.ts` (safe): This is a simple barrel export file re-exporting storage classes, types, and constants with no executable code or malicious patterns.
- `src/storage/storage.ts` (safe): The code implements a standard localStorage wrapper with memory fallback and contains no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or unauthorized network/file operations.
- `src/storage/storageInterface.ts` (safe): No malicious patterns detected
- `src/types.ts` (safe): No malicious patterns detected
- `src/utils/base64.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/calculateWalletAddress.ts` (safe): No malicious patterns detected; the code is a pure off-chain wallet address derivation utility with no network, filesystem, process, or dynamic execution activity.
- `src/utils/constants.ts` (safe): No malicious patterns detected
- `src/utils/ens.ts` (safe): No malicious patterns detected; the code performs a standard, non-sensitive ENS reverse resolution HTTP request with proper error handling.
- `src/utils/index.ts` (safe): No malicious patterns detected
- `src/utils/popup.ts` (safe): The code opens and closes a browser popup window for wallet interactions with no malicious patterns detected.
- `src/utils/strings.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/wallets/index.ts` (safe): No malicious patterns detected
- `src/wallets/wallet.ts` (safe): This appears to be a legitimate Gemini wallet SDK for interacting with Ethereum chains; no malicious patterns such as credential harvesting, exfiltration, obfuscation, or process spawning were detected.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
