Skip to content
RepoRanker
Medtabka

Medtabka/monero-web

Credits + grant $3Live in production

Open-source, non-custodial Monero web wallet. Your keys never leave your browser.

Open-source non-custodial Monero web wallet — runs entirely in your browser, supports BIP-39, Polyseed, MyMonero, and standard 25-word seeds.

★10▲ 1 since joining⑂ 4JavaScriptPush 2mo agoListed 1mo ago1 open issueMIT

monero-web.com/

bip39browser-walletcryptocurrencycryptographymoneromymoneronon-custodialpolyseed
  • JavaScript88.1%
  • HTML10.5%
  • Shell0.6%
  • CSS0.5%
  • Python0.2%
View on GitHub

$3

$2.20 from converted credits; $0.80 granted by RepoRanker. Credits and grants are not card payments. This placement does not expire. Its rank holds until another repo spends more, and then this one moves down, never off. Taking the top of the board from here costs $15.

Report a problem

1 Review

Monero Web is an unusually transparent browser wallet project with a clearly documented threat model. It supports standard Monero seeds, legacy MyMonero seeds, Polyseed, BIP-39, watch-only wallets, subaddresses, encrypted session storage, QR handling, light-wallet scanning, and client-side transaction signing through vendored MyMonero WASM. The code separates key derivation, Ed25519 operations, word lists, storage, RPC, scanning, and sending into focused modules. Security work is visible throughout the repository: a restrictive CSP, self-hosted assets, a hashed deployment manifest, server-side RPC allowlists, session-gated light-wallet requests, private vulnerability reporting, and explicit warnings about browser extensions, compromised systems, phishing, and in-memory spend keys. CI checks cryptographic paths across all supported languages, validates the manifest, checks inline-script syntax, and rejects unexpected external assets.

The most important issue is a conflict between the privacy claims and the implementation. The README and privacy page repeatedly state that the service collects or stores nothing, but server/login-tracker.py stores each primary wallet address with its last-login timestamp in SQLite. A scheduled script then uses those records to hide inactive accounts. Even if this exists only for operational cleanup, a Monero address and activity timestamp are sensitive wallet data and should be disclosed with retention, access, deletion, and threat details. The site also loads Cloudflare Turnstile, despite broad statements that it has no third-party scripts. Those claims should be narrowed and corrected.

Testing should be expanded before significant funds are encouraged. The current suite covers many newer derivation paths but provides limited independent known-answer vectors, browser integration coverage, proxy tests, or complete restore, scan, send, and broadcast scenarios. A wallet handling custom cryptography would benefit greatly from an independent security audit, differential tests against established Monero implementations, fuzzing malformed seeds and RPC responses, and reproducible end-to-end tests. The README also still marks network selection complete although a recent commit intentionally removed it from the interface. Aligning that documentation, clarifying that “zero dependencies” excludes vendored libraries and external infrastructure, and resolving the privacy contradiction would materially improve trust in an otherwise thoughtful project.