Item logo image for Bare Wallet

Bare Wallet

ExtensionWorkflow & Planning
Item media 5 (screenshot) for Bare Wallet
Item media 1 (screenshot) for Bare Wallet
Item media 2 (screenshot) for Bare Wallet
Item media 3 (screenshot) for Bare Wallet
Item media 4 (screenshot) for Bare Wallet
Item media 5 (screenshot) for Bare Wallet
Item media 1 (screenshot) for Bare Wallet
Item media 1 (screenshot) for Bare Wallet
Item media 2 (screenshot) for Bare Wallet
Item media 3 (screenshot) for Bare Wallet
Item media 4 (screenshot) for Bare Wallet
Item media 5 (screenshot) for Bare Wallet

Overview

Private-key-only wallet for EVM and Solana. Local signing, user-approved RPCs, and no Bare Wallet backend.

BARE WALLET A privacy-first Solana + EVM browser wallet with no backend, no telemetry, no seed phrase, no mandatory RPC, and no automatic account discovery. Private keys stay local. DApps see only the account explicitly approved for that site and network. The wallet that refuses to become a casino, a shopping mall, or a surveillance machine. Most crypto wallets keep growing. More chains. More tokens. More feeds. More swaps. More bridges. More tracking. More cloud services. More dependencies. More code running next to the keys that control your money. Every shiny feature adds another moving part. Another server to trust. Another metadata trail. Another dependency waiting to rot. Another place for something to go catastrophically wrong. Bare Wallet takes the opposite path. It is not a crypto super-app. It is a key vault, a transaction inspector, and a local signer. That is the job—and Bare knows where the job ends. NO MASTER SEED. NO DOMINO EFFECT. Bare Wallet does not use mnemonic phrases, HD wallets, derivation paths, or a single root seed that regenerates your entire financial life. Every account has its own independent raw private key. One account. One key. Bare never silently derives more accounts, never automatically links them through a shared seed, and never reuses an EVM key across chains unless you explicitly choose to. This does not magically eliminate every risk. It does eliminate an enormous hidden relationship that most wallets create by default: One secret sitting above everything. ZERO BARE WALLET SERVERS Bare has no backend. No account system. No email login. No social login. No cloud recovery. No synchronization service. No telemetry. No analytics. No advertising. No crash-reporting company receiving wallet activity. No price server. No token-list server. No NFT API. No explorer API. No remote transaction simulator. No remote security oracle. No hidden fallback RPC. The wallet’s network path is deliberately simple: DApp → Bare Wallet → your approved RPC → blockchain. If your RPC fails, Bare reports the failure. It does not quietly phone home to company infrastructure you never approved. No invisible Plan B. No mystery traffic. WEBSITES DO NOT GET TO DISCOVER YOU FIRST Many browser wallets expose a provider broadly across compatible websites, allowing pages to detect wallet software before the user has chosen to interact with it. Bare takes the opposite approach. You explicitly enable Bare for a website. Only then does that origin receive the wallet interface. Other websites get nothing from Bare—no provider announcement and no passive installation signal from Bare. Even after connection, a DApp does not receive a list of every account in your vault. Bare exposes only the account you selected for that specific site, chain family, and network. Your private labels, other keys, connected-site history, and internal account structure stay inside the encrypted vault. YOUR RPC. YOUR METADATA. YOUR DECISION. Bare ships without a mandatory company RPC. You choose which RPC endpoints the wallet may contact. A DApp cannot silently install its own endpoint, and Bare does not sneak in an undeclared fallback when yours is unavailable. This matters because an RPC provider can observe addresses, balance requests, contract calls, transaction preparation, and network-level information. “Non-custodial” means less than it appears to if the wallet still routes your financial activity through infrastructure chosen by somebody else. Bare removes that contradiction. SIGN LOCALLY. INSPECT LOCALLY. FAIL CLOSED WHERE IT MATTERS. Private keys are generated from the browser and operating system’s cryptographically secure random source, encrypted immediately, and used only inside the trusted extension context. The vault uses scrypt and authenticated AES-256-GCM encryption. Private keys are decrypted only when required for signing or export. Export requires password reauthentication. Signing requests are immutable, short-lived, single-use, and bound to the real browser-provided website, tab, document, account, chain, and payload. A hostile page cannot simply swap the transaction after the approval window opens and expect Bare to sign the replacement. Bare parses supported EVM and Solana transactions locally. It highlights operations it can deterministically recognize and displays raw details when meaning cannot be established. Unknown means unknown. It never means safe. When a security-critical requirement cannot be established—such as the actual signer, chain, approved payload, or required Solana lookup-table resolution—Bare fails closed. Unknown transaction semantics may be shown with an explicit warning or rejected according to wallet policy and Strict Mode. There is no remote AI score, no contract-label oracle, and no corporate server whispering: “Trust us, bro.” LESS CODE NEAR YOUR KEYS Bare is built with: Chromium Manifest V3 TypeScript Vanilla HTML Vanilla CSS No React. No Vue. No Redux. No giant application framework. No remotely hosted code. No CDN scripts. No hand-written cryptography. No massive general-purpose blockchain SDK in the production wallet just for developer convenience. Production dependencies are pinned to exact versions, kept deliberately small, and documented for public review. Larger libraries remain outside the production extension and serve only as independent test references. Network access is deliberately confined to one reviewed subsystem. Automated build checks reject direct network APIs elsewhere in the production source. This is what minimal attack surface means here: Not a minimalist skin wrapped around a giant machine, but fewer mechanisms that must be trusted in the first place. OPEN SOURCE. VERIFY IT. Bare Wallet is open source. Source code: https://github.com/baredev22/Bare-Wallet You do not have to take its privacy model, dependency choices, or network claims on faith. Inspect the source. Inspect the manifest. Inspect the dependencies. Search for network calls. Check what gets stored. Check where private keys can exist. Build it yourself. Bare’s security model is intended to be understandable from the code—not hidden behind claims such as “military-grade security” or a privacy policy nobody reads. Open source is not proof that software is secure. It does mean Bare’s claims are open to inspection, criticism, reproduction, and independent verification. That is how it should be for software holding private keys. WHY OTHER WALLETS CANNOT EASILY BECOME BARE Could another wallet copy one of these ideas? Of course. But copying the complete model would mean removing much of the infrastructure and convenience layers their products were built around: Their backend. Their default RPC. Their account system. Their telemetry. Their portfolio feeds. Their token discovery. Their swap and bridge integrations. Their cloud recovery. Their universal site injection. A large part of their trusted codebase. Bare Wallet starts where that deletion ends. Its advantage is not a secret algorithm or a magical security badge. Its advantage is refusing to accumulate machinery that creates unnecessary trust. WHAT BARE DOES • Holds independent EVM and Solana private keys locally • Connects through standard EVM and Solana wallet interfaces • Supports local message and transaction signing • Provides native and manually tracked token transfers • Inspects requests before signing • Exposes only the account approved for each site and chain • Communicates only with RPC endpoints approved by the user • Lets users revoke enabled sites • Lets users export their own private keys • Locks automatically and clears unlocked session state WHAT BARE DELIBERATELY DOES NOT DO • Seed phrases or HD account trees • Cloud backup or password recovery • Portfolio dashboards • Automatic token or NFT discovery • Price charts • Built-in swaps or bridges • Staking marketplaces • Advertising • Analytics • Remote risk scoring • Hidden network services THE PRICE OF REAL CONTROL Bare Wallet is intentionally less convenient. You must manage independent private keys. You must choose RPC endpoints. You must protect your password and backups. If you lose your secrets, there is no company support desk with a recovery button. That is not an unfinished feature. That is what removing third-party control looks like. Bare Wallet is for people who would rather understand a small, explicit system than blindly trust a polished black box with a thousand moving parts. It does less. It leaks less. It asks you to trust less. And in a wallet, less bullshit can be a serious security feature. SECURITY NOTICE Bare Wallet is software, not magic. It cannot protect private keys on a compromised operating system, browser, or extension environment. It cannot save a user who approves a malicious request. The project has not yet received an independent security audit. Open source does not replace an audit. Review the source. Build it yourself if appropriate. Use a strong, unique passphrase. Verify every signing request. Maintain secure backups of your individual keys. Never store more value in any wallet than your own risk assessment allows.

Details

  • Version
    0.1.0
  • Updated
    September 9, 2026
  • Offered by
    Bare Dev
  • Size
    287KiB
  • Languages
    English
  • Developer
    Email
    hamy22com+barewallet@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes
Google apps