a privacy-focused wallet that does not send wallet data to company servers
The wallet that refuses to become a casino, a shopping mall, or a surveillance machine.
Most crypto wallets keep growing.
More chains. More tokens. More feeds. More swaps. More bridges. More tracking. More cloud services. More dependencies. More code running next to the keys that control your money.
Every shiny feature adds another moving part. Another server to trust. Another metadata trail. Another dependency waiting to rot. Another place for something to go catastrophically wrong.
Bare Wallet takes the opposite path.
It is not a crypto super-app.
It is a key vault, a transaction inspector, and a local signer. That is the job—and Bare knows where the job ends.
NO MASTER SEED. NO DOMINO EFFECT.
Bare Wallet does not use mnemonic phrases, HD wallets, derivation paths, or a single root seed that regenerates your entire financial life.
Every account has its own independent raw private key.
One account. One key.
Bare never silently derives more accounts, never automatically links them through a shared seed, and never reuses an EVM key across chains unless you explicitly choose to.
This does not magically eliminate every risk. It does eliminate an enormous hidden relationship that most wallets create by default: one secret sitting above everything.
ZERO BARE WALLET SERVERS
Bare has no backend.
No account system. No email login. No social login. No cloud recovery. No synchronization service. No telemetry. No analytics. No advertising. No crash-reporting company receiving wallet activity. No price server. No token-list server. No NFT API. No explorer API. No remote transaction simulator. No remote security oracle. No hidden fallback RPC.
The wallet’s network path is brutally simple:
DApp → Bare Wallet → your approved RPC → blockchain.
If your RPC fails, Bare reports the failure. It does not quietly phone home to company infrastructure you never approved.
No bullshit. No invisible Plan B. No mystery traffic.
WEBSITES DO NOT GET TO DISCOVER YOU FIRST
Most browser wallets inject themselves into every compatible website you visit. The page can often detect that a wallet is installed before you have decided to interact with it.
Bare does not globally inject its provider.
You explicitly enable Bare for a website. Only then does that origin receive the wallet interface. Other websites get nothing from Bare—no provider announcement and no passive installation signal.
Even after connection, a DApp does not receive a list of every account in your vault. Bare exposes only the account you selected for that specific site, chain family, and network.
Your private labels, other keys, connected-site history, and internal account structure stay inside the encrypted vault.
YOUR RPC. YOUR METADATA. YOUR DECISION.
Bare ships without a mandatory company RPC.
You choose which RPC endpoints the wallet may contact. A DApp cannot silently install its own endpoint, and Bare does not sneak in an undeclared fallback when yours is unavailable.
This matters because an RPC provider can observe addresses, balance requests, contract calls, transaction preparation, and network-level information.
“Non-custodial” means very little if the wallet still sends your entire financial map through somebody else’s servers.
Bare removes that convenient little contradiction.
SIGN LOCALLY. INSPECT LOCALLY. FAIL CLOSED.
Private keys are generated from the browser and operating system’s cryptographically secure random source, encrypted immediately, and used only inside the trusted extension context.
The vault uses scrypt and authenticated AES-256-GCM encryption. Private keys are decrypted only when required for signing or export. Export requires password reauthentication.
Signing requests are immutable, short-lived, single-use, and bound to the real browser-provided website, tab, document, account, chain, and payload. A hostile page cannot swap the transaction after the approval window opens.
Bare parses supported EVM and Solana transactions locally. It highlights known operations, displays raw details when meaning cannot be established, and refuses to pretend that “unknown” means “safe.”
There is no remote AI score, no contract-label oracle, and no corporate server whispering, “Trust us, bro.”
When Bare cannot verify something required for safe signing, it fails closed.
LESS CODE NEAR YOUR KEYS
Bare is built with Chromium Manifest V3, TypeScript, vanilla HTML, and vanilla CSS.
No React. No Vue. No Redux. No giant application framework. No remotely hosted code. No CDN scripts. No hand-written cryptography. No massive general-purpose blockchain SDK in the production wallet just for developer convenience.
The small cryptographic and transaction-signing dependencies are pinned to exact versions. Larger libraries are kept outside the production extension and used only as independent test references.
Network access is deliberately confined to one reviewed subsystem. Automated build checks reject direct network APIs elsewhere in the production source.
This is what “minimal attack surface” actually means: not a minimalist skin wrapped around a giant machine, but fewer mechanisms that must be trusted in the first place.
WHY OTHER WALLETS CANNOT EASILY BECOME BARE
Could another wallet copy one of these ideas? Of course.
But copying the complete model would mean removing the infrastructure and convenience layers their products were built around:
their backend, their default RPC, their account system, their telemetry, their portfolio feeds, their token discovery, their swap and bridge integrations, their cloud recovery, their universal site injection, and a large part of their trusted codebase.
Bare Wallet starts where that deletion ends.
Its advantage is not a secret algorithm or a magical security badge. Its advantage is refusing to accumulate the machinery that creates unnecessary trust.
WHAT BARE DOES
• Holds independent EVM and Solana private keys locally
• Connects through standard EVM and Solana wallet interfaces
• Supports local message and transaction signing
• Provides native and manually tracked token transfers
• Inspects requests before signing
• Exposes only the account approved for each site and chain
• Communicates only with RPC endpoints approved by the user
• Lets users revoke enabled sites and export their own keys
• Locks automatically and clears unlocked session state
WHAT BARE DELIBERATELY DOES NOT DO
• Seed phrases or HD account trees
• Cloud backup or password recovery
• Portfolio dashboards
• Automatic token or NFT discovery
• Price charts
• Built-in swaps or bridges
• Staking marketplaces
• Advertising
• Analytics
• Remote risk scoring
• Hidden network services
THE PRICE OF REAL CONTROL
Bare Wallet is intentionally less convenient.
You must manage independent private keys. You must choose RPC endpoints. You must protect your password and backups. If you lose your secrets, there is no company support desk with a recovery button.
That is not an unfinished feature.
That is what removing third-party control looks like.
Bare Wallet is for people who would rather understand a small, explicit system than blindly trust a polished black box with a thousand moving parts.
It does less.
It leaks less.
It asks you to trust less.
And in a wallet, less bullshit can be a serious security feature.
SECURITY NOTICE
Bare Wallet is software, not magic. It cannot protect keys on a compromised operating system or save a user who approves a malicious request. The project has not yet received an independent security audit. Review the source, use a strong unique passphrase, verify every request, and never store more value than your own risk assessment allows.