Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions astro.config.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -152,6 +152,7 @@ export default defineConfig({
{ label: 'Transaction safety', slug: 'wallets/transaction-safety' },
{ label: 'Market safety', slug: 'wallets/market-safety' },
{ label: 'Private chat verification', slug: 'wallets/chat-verification' },
{ label: 'Universe Web and Shielded Wallet', slug: 'wallets/universe-web-and-shielded' },
],
},
{
Expand Down
7 changes: 7 additions & 0 deletions src/content/docs/wallets/connecting.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,13 @@ mobile-specific destination instead.

Wizz is shown as **Wizz**, never as UniSat.

### Two web wallets, not yet available

Two more choices, **Universe Web Wallet** and **Universe Shielded Wallet**,
have been built. They run in a web page and need no extension. They are not
yet available and do not appear in the list today. See
[Universe Web Wallet and Universe Shielded Wallet](/docs-core/wallets/universe-web-and-shielded/).

## Three states

| State | What it means | What to do |
Expand Down
89 changes: 89 additions & 0 deletions src/content/docs/wallets/universe-web-and-shielded.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,89 @@
---
title: Universe Web Wallet and Universe Shielded Wallet
description: >-
Two extension-free wallet choices built for Core, why they are not yet
available, what they will and will not do, and the risks of a wallet that
runs in a web page.
sidebar:
order: 5
---

import Provenance from '../../../components/Provenance.astro';

<Provenance
repo="bitcoinuniverseio/core (private), bitcoinuniverseio/wallet (private)"
source="frontend/src/util/universe-web-wallet-provider.js, frontend/src/components/wallet/WalletModal.js"
chain="bitcoin"
network="mainnet, signet"
lifecycle="not released"
verified="2026-09-29"
/>

**These two wallets are not yet available.** They do not appear in the Core
wallet list today, and the address they will run from,
`wallet.bitcoinuniverse.io`, is not live. This page describes what has been
built so you know what to expect, and what to distrust, when they are offered.

## What they are

**Universe Web Wallet** is a Bitcoin wallet that runs in a web page instead of
a browser extension. You open it from **Connect Wallet** in Core, and it opens
in its own window on its own address. Nothing needs to be installed.

**Universe Shielded Wallet** uses the same window and a separate recovery
phrase. It is meant for shielded token protocols. No shielded protocol it could
use is usable today, so it refuses every connection.

Both are separate choices from the **Universe** browser extension. Connecting
one does not connect the other.

## What the web wallet does

- Creates a new 12 or 24 word recovery phrase, and asks you to confirm three of
the words before anything is saved.
- Imports a recovery phrase, a single private key, or an export from the
Universe extension. An imported phrase gives the same addresses as the
extension.
- Shows a Bitcoin payment address and an ordinals address, each with a QR code.
- Sends bitcoin. Before you approve, the wallet shows what leaves, the fee, and
the change coming back to you.
- Locks itself after 15 minutes without use.
- Lets you download an encrypted backup file and restore it in another browser.

It only spends coins that Universe has checked carry no inscription, rune, or
Atomicals asset. Other actions, such as protocol trades, are not enabled for
this wallet.

## What Core can and cannot see

Core never sees your recovery phrase, your password, or your keys. They stay
inside the wallet window. Connecting shares your public addresses only.

Connecting never approves a signature. Every signature request opens in the
wallet window, where you review it before approving.

## Risks of a web wallet

- **It is a hot wallet.** A compromised device, a malicious browser extension,
or a tampered copy of the wallet page could steal your funds.
- **Your browser holds the only copy of the encrypted keys.** Clearing site
data, a private window, or the browser reclaiming storage can erase it. Write
down your recovery phrase and keep the backup file somewhere else.
- **Encrypting keys is not privacy.** Your Bitcoin addresses and payments are
public on the chain, as with any wallet.
- **Check the address.** Only enter a recovery phrase into the wallet window on
`wallet.bitcoinuniverse.io`, and only after Core offers the wallet.

## Shielded wallet status

The two shielded protocols it was built for are not usable:

| Protocol | Why it is not usable |
| --- | --- |
| SBRC-20 | The official specification is a draft that is not live. No circuit, verifying key, or source code is published. |
| Bitshield (BSH) | No licensed source code is published. Its transfers and market start only at a future mainnet block, and its market runs on servers Bitshield operates. |

## Next

- [Connecting a wallet](/docs-core/wallets/connecting/)
- [Transaction safety](/docs-core/wallets/transaction-safety/)