ZAP Wallet - AI-Powered Solana Wallet
cdiohdbijdajffgccjmbblbikpnnnkeg
Risk Score
5.02
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Crypto wallet with broad <all_urls> host permissions + scripting: can read/inject into every page including banking sites.
- Gmail dev account (genograndino@gmail.com), unknown org 'TGSOC', zero installs — unverifiable identity holding sensitive private keys.
- Dynamic script creation (script_src_dynamic) and new Function() constructor detected — code execution risk even with CSP present.
- Privacy policy fetched but no retention disclosure and third_party_silence=true; inadequate for a wallet handling private keys.
- AI-powered crypto wallet category: high-value target for supply-chain compromise; only 4 installs with broad capabilities.
Evidence
- broad_host_permissions manifest http://*/* and https://*/* granted alongside scripting — full page read/inject on all sites.
- free_webmail_developer store Developer email genograndino@gmail.com with unknown org TGSOC; no verified publisher badge.
- code_finding_function_constructor crx new Function() constructor found in popup-bundle.js — dynamic code execution capability.
- code_finding_script_src_dynamic crx Dynamic <script> element creation in popup-bundle.js — potential remote script loading.
- install_perm_anomaly store Only 4 installs with high-tier permissions (broad host access + scripting) flagged as small_install_high_perm.
- privacy_policy_inadequate api Policy fetched (1253 chars), scope_extension=true but no retention disclosure and third_party_silence=true.
- external_hosts crx Contacts api.coingecko.com, mainnet.helius-rpc.com, solscan.io, zapzip.fun — plausible for Solana wallet.
- ai_crypto_wallet_high_value_target store AI-powered Solana wallet is prime supply-chain compromise target; 4 installs with near-unrestricted page access.
Permissions Breakdown
- storage low Stores local wallet/UI state; low risk alone.
- activeTab low Temporary access to active tab on user gesture only.
- scripting medium Allows programmatic JS injection into pages; elevated with broad host_permissions.
- tabs medium Can read tab URLs/titles across all tabs.
- http://*/* high Broad host access over HTTP — all sites reachable for scripting/data access.
- https://*/* high Broad host access over HTTPS — all sites reachable; pairs with scripting for full read/write.
Pillar Scores
Permissions7.00
Reputation7.50
Network3.50
Webstore4.00
Maintenance1.50
Privacy2.00
Code Quality5.50
CVE Exposure0.00
Scoring History
| sssiedn87cbb958dp727562726963xsx | 5.08 | Medium | review | 2026-09-09 |
| v3.6 | 5.02 | Medium | review | 2026-08-28 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:39
Listing SHA
5982004a52c9…
Force block
— not fired
Score recovered
no
Elapsed
—