
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
@bitcoin-corporation/brc100-wallet
Advanced tools
Drop-in browser client for the BRC-100 Google Wallet API — sign in with Google, get a Bitcoin SV wallet.
Drop-in browser client for the BRC-100 Google Wallet API. Sign in with Google → get a Bitcoin SV wallet, in about five lines.
Maintained by The Bitcoin Corporation Ltd.
<div id="signin"></div>
<script src="https://YOUR-API-HOST/sdk/brc100-wallet.js"></script>
<script>
const wallet = new BRC100Wallet({ apiBase: 'https://YOUR-API-HOST' })
wallet.mountSignIn('#signin', {
onReady: async (s) => {
console.log('wallet:', s.wallet.identityKey, s.wallet.address)
console.log('balance:', (await wallet.balance()).satoshis, 'sat')
},
})
</script>
That's it. mountSignIn shows the real Google button if the API has a Client ID
configured, or a dev-login form otherwise.
You can also load it from a CDN once published:
<script src="https://cdn.jsdelivr.net/npm/@bitcoin-corporation/brc100-wallet"></script>
npm install @bitcoin-corporation/brc100-wallet
import BRC100Wallet from '@bitcoin-corporation/brc100-wallet'
const wallet = new BRC100Wallet({ apiBase: 'https://YOUR-API-HOST' })
await wallet.mountSignIn('#signin', { onReady: (s) => console.log(s.wallet) })
const wallet = new BRC100Wallet({ apiBase, storageKey?, autoResume?, storage? })
// auth
wallet.mountSignIn(target, { onReady, onError, button })
await wallet.signInWithGoogleCredential(idToken) // if you render your own button
await wallet.devSignIn('user-id') // dev only
wallet.isSignedIn()
wallet.signOut()
// wallet
await wallet.getWallet() // { network, identityKey, address }
await wallet.balance() // { satoshis, outputs, basket }
await wallet.outputs({ limit }) // UTXOs
await wallet.actions({ limit }) // history
await wallet.pay({ to, satoshis, description })
await wallet.sign({ data })
await wallet.encrypt({ plaintext })
await wallet.decrypt({ ciphertext })
await wallet.exportKey() // migrate to self-custody
The session token is persisted (localStorage by default) so users stay signed in.
The package is publish-ready (npm pack --dry-run ships 5 files, ~5 kB).
# one-time: create the @bitcoin-corporation org on npmjs.com, then:
npm login
cd sdk
npm publish # publishConfig.access is already "public"
Notes:
@bitcoin-corporation scope must exist as an npm org you belong to.version in package.json before each publish.https://cdn.jsdelivr.net/npm/@bitcoin-corporation/brc100-walletMIT © The Bitcoin Corporation Ltd
FAQs
Drop-in browser client for the BRC-100 Google Wallet API — sign in with Google, get a Bitcoin SV wallet.
We found that @bitcoin-corporation/brc100-wallet demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.