Offizielles MASTR Logo MASTR
Menü

Smart Accounts und Governance

EIP-6963: choosing between browser wallets without trusting the icon

Provider discovery solves a coordination problem; names and icons remain self-reported.

Aktualisiert am 30. September 2026 · MASTR Labs

Artikeltexte und technische Grafiken sind auf Englisch. Die Navigation ist in 7 Sprachen verfügbar.

Fachartikel
  1. Why one injected provider was awkward
  2. An announcement is not an identity certificate
  3. Discovery is not permission
  4. What to examine when something feels wrong
  5. Konkretes Beispiel
  6. Quellen und Originale

Why one injected provider was awkward

Several wallet extensions historically competed to expose a provider through window.ethereum. Loading order could determine which one a site saw, producing confusing connections for users with multiple wallets installed. EIP-6963 defines event-based discovery so a page can learn about several injected providers and let the user choose. It preserves the underlying provider interface rather than inventing a new chain protocol. 1

An announcement is not an identity certificate

Providers announce information including a name, icon, session identifier and reverse-domain-style identifier. These fields are useful for presenting options, but they are self-attested. The standard explicitly warns that provider metadata can imitate another wallet. A familiar logo inside a connection chooser is not independent proof that the expected extension produced it.

Discovery is not permission

Finding a provider should not be confused with receiving account access, signing a message or authorising a transfer. Those are later interactions with their own consent and security requirements. A well-designed chooser preserves the user’s selected wallet and makes a changed account or chain visible. It should not silently substitute the last provider to announce itself. 2

What to examine when something feels wrong

Check the installed extension through the browser’s own extension management, the selected account and the destination website. A changed icon or duplicate name deserves investigation, but does not by itself prove theft. For developers, render provider imagery as images rather than active markup and treat metadata as untrusted input. For users, the meaningful review happens again in the wallet’s own signing interface.

Discovery is only the first step
Erklärende Grafik. In voller Grösse öffnen. Credits ↗ Wallet metadata is self-reported, not an identity certificate.

Konkretes Beispiel

Two wallet extensions are installed. A site displays both providers and you select one. That solves selection. It does not mean a later request from the site is safe; the chosen wallet still needs to show what account, chain and action you are authorising.

Quellen und Originale

  1. EIP-6963: multi-provider discovery
  2. EIP-1193: Ethereum provider API

Weiterlesen

Smart Accounts und Governance →

MASTR

Unabhängige Recherche unterstützen

Die Untersuchungen, Originalbelege und Anleitungen hier sind frei zugänglich. Freiwillige Spenden finanzieren die Recherche mit und helfen, die MASTR-Tools weiterhin anzubieten.

Wallet öffnen