Changelog
Decentralized, zero-knowledge password manager.
All notable changes to this project are documented in this file.
Format: Keep a Changelog
Versioning: Semantic Versioning
1.8.7 — 2026-09-10
Section titled “1.8.7 — 2026-09-10”- Biometric prompt at vault creation, all paths (Android): the biometric probe (write + read with authenticationPrompt) was missing from the 2 remaining vault-creation paths: handleImportBiometric (ImportMethodModal) and the overwrite confirmation for an existing vault. The probe was extracted into lib/biometricProbe.ts and now runs before every creation on all 3 paths: the fingerprint prompt always shows and Keystore auth is established before biometric entries are written
Versioning
Section titled “Versioning”- Android: 1.8.6 -> 1.8.7 (versionCode 40 -> 41)
1.8.6 — 2026-09-10
Section titled “1.8.6 — 2026-09-10”- Biometric prompt at vault creation (Android): handleBiometricCreate triggered no biometric authentication at all: writing Keychain entries with accessControl: BIOMETRY_CURRENT_SET does not prompt on Android (iOS != Android behavior), and biometric entries written without prior auth made biometric unlock silently ineffective (getBiometricCombined failed with an exception that was caught). Fix: biometric probe (write + read with authenticationPrompt, same pattern as SettingsAccessScreen) runs before any creation, so the fingerprint prompt shows at vault creation and biometric unlock works without toggling off/on
Versioning
Section titled “Versioning”- Android: 1.8.5 -> 1.8.6 (versionCode 38 -> 40)
1.8.5 — 2026-09-09
Section titled “1.8.5 — 2026-09-09”Security (Android reviewer audit)
Section titled “Security (Android reviewer audit)”android:allowBackup="false": OS backups (cloud + device transfer) can no longer copy app data. A zero-knowledge vault has no business in an unencrypted backup- Unused permissions stripped: RECORD_AUDIO (declared by expo-camera for video recording, never used), ACCESS_FINE_LOCATION and ACCESS_COARSE_LOCATION removed from the merged manifest via tools:node=“remove”; the withStrippedPermissions prebuild plugin extended accordingly. CAMERA kept (desktop/extension pairing QR scan)
exportedcomponents audit: MainActivity (launcher + vaultkeeper:// deeplink, required), ClipboardFileProvider (restricted paths + temporary grants), RevocationBoundService and ProfileInstallReceiver (protected by signature-level permissions). No unjustified IPC surface- HIBP k-anonymity documentation (apps/android/docs/SECURITY.md): breach checks send only the first 5 characters of the SHA-1 hash (computed locally), the suffix is matched on-device and the response is padded (Add-Padding: true). The password and its full hash never leave the device
Maintenance
Section titled “Maintenance”- APK 189 MB -> 101 MB: restricted to real ABIs armeabi-v7a + arm64-v8a (reactNativeArchitectures in gradle.properties + defensive abiFilters in build.gradle). The x86/x86_64 libs only served the emulator (MLKit OCR, QuickCrypto, barhopper, Hermes duplicated across 4 ABIs)
- Rebuild on Expo SDK 57 / React Native 0.86.3 / React 19.2.3 (chore/expo-57-upgrade branch): resolved the Hermes V1 memory regression (present on SDK 56), New Architecture kept, MLKit OCR + NFC compiled and validated in real native builds (gradle + xcodebuild)
react-native-svgpatched for RN 0.86 (patches/react-native-svg+15.15.4.patch): the observer API ImageResponseObserverCoordinator no longer accepts raw references, pass the shared_ptr directly; patch-package now wired into postinstall (the 6 existing patches were only applied manually)- Signed IPA: iPhone Distribution + App Store profile com.vaultkeeper.app auto-provisioned via Xcode, autofill extension VaultKeeperCredentialProvider included. app-store-connect export ready for TestFlight
MobSF security audit (static + dynamic)
Section titled “MobSF security audit (static + dynamic)”- MobSF 4.4.1 on final builds: IPA 51 -> 73/100 (0 HIGH), APK 61 -> 85/100 (0 HIGH). Official PDF reports (22 + 131 pages) and JSON in release deliverables
- iOS: full ATS: removed the whole NSAppTransportSecurity block (7 no-op exception domains + NSAllowsLocalNetworking) and NSLocalNetworkUsageDescription. Sync traffic (HTTPS relay + public IPFS gateways) needs no exception; TrustKit pinning on VaultKeepR domains is kept
- iOS: microphone permission removed (NSMicrophoneUsageDescription never used); camera (QR sync + secure document photos) and photo library (cloud storage) descriptions documented precisely
- iOS: WalletConnect leftovers purged (account abstraction migration): 3 obsolete exception domains (relay.walletconnect.org, walletconnect.org, gateway.ar.io), never-used rainbow/trust/wc query schemes, dead withYttriumWrapperPatch prebuild plugin removed (no Yttrium pod in Podfile.lock)
- iOS: debug symbols stripped: DEBUG_INFORMATION_FORMAT=dwarf-with-dsym (debug info moved to .dSYM, crash symbolication available) + DEPLOYMENT_POSTPROCESSING/STRIP_INSTALLED_PRODUCT/STRIP_STYLE=all on both Xcode targets
- iOS/Android: bundle scrubbed of
scan.zkfair.io(MobSF hotspot, Hong Kong IP): custom Metro resolver mapping viem/chains -> definitions/base.js. Metro does not tree-shake the barrel, so 50+ chain definitions (zkFair included) ended up as dead strings in the bundle; only BASE chain strings remain - Android: minSdk 24 -> 29 (gradle.properties + expo-build-properties): removes the HIGH “installable on unpatched Android 7.0”. Android 8/9 (~3-4% of devices) dropped, a security-first choice
- Android: release signature verified: upload keystore, SHA-1 0F:1A:BF:09:40:6A… identical to the Play fingerprint; the 2 HIGH “debug certificate” findings were artifacts of an unsigned-upload signature
- Android: WalletConnect leftovers purged: 4 wallet schemes (metamask/trust/rainbow/wc) removed from the block, withWalletQueries plugin removed
- Dynamic analysis (rooted Android 11 emulator, MobSF MITM + frida):
- TrustKit pinning proven effective: traffic to app.vaultkeepr.xyz + IPFS gateways cannot be intercepted (MobSF certificate rejected by the pin); only unpinned domains pass
- HIBP k-anonymity verified in real traffic: api.pwnedpasswords.com/range/<5 characters>, the full hash never leaves the device
- 0 trackers (0/432 known), 0 secrets at rest: shared_prefs and AsyncStorage contain no plaintext password/vaultKey/token/CID
- 1 runtime bug found and fixed: an expo-clipboard assertion requiring ClipboardFileProvider exported=true (crash at startup). The exported=false hardening attempt was reverted and the library constraint documented (to report upstream to expo-clipboard)
- MobSF false positives documented (removed via API or justified in the report): iOS rpath (required for embedded OpenSSL/hermesvm frameworks), iOS “symbols not stripped” warning (MobSF matches radr://5614542, Apple’s stripped-binary marker, an upstream bug), Android base-config system CAs (standard, pinning in place), 92 “hardcoded secrets” (Credential Manager i18n strings)
OpenSSF (public repo vaultkeepr-public)
Section titled “OpenSSF (public repo vaultkeepr-public)”- 3 OpenSSF badges earned on github.com/VaultKeepR/vaultkeepr-public:
- Scorecard 7.8/10 (v5.1.1, 2026-09-09): scorecard.dev. CI/CD, supply-chain security (SLSA, pinned dependencies), branch protection, signed releases
- Best Practices: Silver: bestpractices.dev/projects/14491. Governance, CONTRIBUTING/SECURITY/CODE_OF_CONDUCT/DISCLOSURE, reproducible release process (Passing level exceeded, Silver criteria validated)
- Baseline: minimum project security requirements verified
- Open-source governance already in place: GOVERNANCE.md, ROADMAP.md, minisign.pub (release verification)
HTTP Observatory (website vaultkeepr.xyz)
Section titled “HTTP Observatory (website vaultkeepr.xyz)”- Grade B+ (80/100), 11/12 tests passed (MDN Observatory, scan 2026-09-09): HTTPS + HSTS preload + HTTP/www redirects + CSP (nonce + frame-ancestors ‘none’) + locked Permissions-Policy (empty camera/micro/geolocation) + 0 cookies
- Identified action: duplicated Strict-Transport-Security header (Next.js max-age=31536000; includeSubDomains + Cloudflare edge max-age=63072000); deduplicate keeping the strongest policy (max-age=63072000; includeSubDomains; preload) to reach A
Versioning
Section titled “Versioning”- Android: 1.8.2 -> 1.8.5 (versionCode 37 -> 38)
- iOS: 1.8.0 -> 1.8.5 (build 13 -> 14)
1.8.3 — 2026-08-13
Section titled “1.8.3 — 2026-08-13”Security
Section titled “Security”- SLM engine migrated to on-device (packages/core/src/slm-engine.ts): Removed server proxy (/api/slm → shipdaily.xyz). Auto-tagging (categorizeEntries) now uses a deterministic domain/keyword classifier (FR+EN). Breach summary (summarizeBreach) uses the deterministic local fallback. No vault data (URL, username) leaves the device anymore: true zero-knowledge on iOS + Android
- Extension auto-tag on-device (slm-engine.ts + slm-background.ts + messaging.js): Wired the ASK_SLM_AUTOTAG handler (previously orphaned UI). Deterministic classifier, 0 network, aligned with mobile
SEO / Website
Section titled “SEO / Website”- Sitemap consolidation: robots.txt now points to /new-sitemap.xml (dynamic, complete) instead of the stale static /vk-sitemap.xml (deleted). Broken redirect /sitemap-main.xml removed
- Re-indexed
/delete-account/*pages: Removed robots: index:false on all 4 pages (hub + [service], EN + FR): the #1 impression source (329+/month) is no longer blocked - hreflang in sitemap: buildSitemap.ts now emits (en/fr/x-default) + missing FR pages added (/docs/fr, /security/fr, /privacy/fr, /terms/fr, /shop/fr)
- Semantic sections: /compare/keeper (Keeper vs BeyondTrust PAM), /migrate/vaultwarden (SQLite DB migration): EN + FR
- Sourced SocialProof: “241 tests” stat → “496” (measured via vitest), fictional named testimonials replaced with verifiable open-source/zero-knowledge claims (E-E-A-T + legal risk eliminated)
- Keeper seoTitle: “2025” → “2026”
Maintenance
Section titled “Maintenance”- Comment strip: 1271 files cleaned (babel AST for TS/JS/TSX, regex for Swift/Sol/Shell/YAML/MD/CSS). Type-safe (0 new errors), runtime-safe (496 core tests pass)
- Public open-source repo: Created github.com/VaultKeepR/vaultkeepr-public: 16 packages (enterprise excluded) + 3 Solidity contracts + bilingual EN/FR README + SECURITY.md. 0 comments, 0 internal artifacts, 0 leaks
- knip.json added (dead code analysis, calibrated for the monorepo)
Versioning
Section titled “Versioning”| Platform | Version |
|---|---|
| Chrome/Firefox Extension | 1.8.2 |
| iOS | 1.8.0 |
| Android | 1.8.1 |
| Core SDK | (open-source) |
1.8.2 — 2026-08-09
Section titled “1.8.2 — 2026-08-09”- Backup password (Chrome + Firefox): New recovery mechanism for PRF-only vaults (Touch ID / Face ID unlock without a master password). The user sets a backup password in Settings → Security, which encrypts the unlock secret (prfKey + secretKey) in an Argon2id + XChaCha20-Poly1305 envelope. On authenticator loss, the backup password decrypts the envelope → recovers the secret → unlocks the vault (local backup then IPFS).
- Reminder banner in settings if PRF-only vault has no backup password configured
- “Backup password” link in the unlock screen advanced options
- PRF cache seed after IPFS pull: pollCidAndSyncFromTab now seeds the local PRF cache after a successful pull → next Touch ID unlocks are fast (<50ms) instead of re-pulling IPFS
- Empty vault after rebuild / reload: The password unlock path never seeded the local PRF cache. Since the backup is encrypted with the masterPassword (≠ prfKey), Touch ID could not decrypt it → vault permanently empty after rebuild. Fix applied at all 4 restore points
- Empty entry duplication on login forms: setupCardAndIdentitySubmitCapture matched a single autocomplete=“email” field → silent ADD_IDENTITY created empty entries with no UI on every submit. Fix: now requires ≥3 identity fields and excludes login forms
Versioning
Section titled “Versioning”| Platform | Version | Store |
|---|---|---|
| Chrome Extension | 1.8.2 | Chrome Web Store |
| Firefox Extension | 1.8.2 | Firefox Add-ons |
1.8.0 — 2026-08-08
Section titled “1.8.0 — 2026-08-08”- Light theme (iOS + Android): New runtime theming system (theme.ts + ThemeProvider) with an Appearance toggle in settings and system-level sync (userInterfaceStyle: automatic)
- All iOS/Android screens and components converted to useThemedStyles (styles recomputed for the active theme)
- Contrast fixes: generated passwords now readable in light mode, fixed dark cards made theme-aware (C.surface/C.border)
- Email breach scanner (iOS + Android): Ported email breach monitoring (consent + per-email status, vk_monitored_emails)
- Settings reorganization + Privacy section (iOS + Android + Chrome + Firefox): new Privacy section (sync frequency, clipboard auto-clear, TOS, persist session); Appearance toggle moved to General; Export moved to Storage & Sync
- Demo mode: removed the user-facing toggle (iOS) and the keyboard shortcut (extension) so demo screens can no longer be triggered
- Mobile audit P0-P3 (41 findings): Full security fix pass across iOS/Android
- Crypto: fixed CryptoKit AES-GCM decrypt, cipher||tag, manual CCCryptorGCM prototype
- Native: userCanceled, @import CommonCrypto, extension localization (en/fr).lproj
- iOS extension + main app build; Android prebuild OK (permissions stripped, OTA off)
- AutoFill: Fixed getBiometricRequirement crash (non-iterable destructuring) — callback now robust to scalar or array
- Cloud: Back button now shown in embedded mode (Cloud menu) and aligned with other screens (chevron + label)
- Theme: Fixed residual dark rendering on SyncScreen, DetailScreen, ShareScreen, ReceiveShareScreen, ExportSection (auxiliary style blocks converted to themed factories)
Versioning
Section titled “Versioning”- iOS: 1.7.0 -> 1.8.0 (build 7 -> 8)
- Android: 1.7.0 -> 1.8.0 (versionCode 33 -> 34)
1.7.0 — 2026-07-14
Section titled “1.7.0 — 2026-07-14”Security
Section titled “Security”- Certificate Pinning: withCertPinning plugin activated on iOS and Android
- Leaf pin + ISRG Root X1 (expiration 2027-06-01) in Info.plist
- network_security_config.xml with real pins on Android
- Store Hardening (Sprint 1): Aligned extension host_permissions, removed test-overlays.html from web_accessible_resources, aligned 10 Android permissions (no RECORD_AUDIO), deleted 6 ghost folders
- Logger: New @vault-keeper/logger package (auto-redaction of CIDs V0/V1, addresses, tx hashes, base64 >200 chars, mnemonics). 884 console.* sites migrated to logger.{debug,warn,error,info} across 138 files
- FLAG_SECURE: useSecureScreen applied to 24 vault screens x 2 platforms (iOS + Android)
- Crypto docs: Updated all SECURITY.md / ARCHITECTURE.md / SYNC.md to XChaCha20-Poly1305 (vault) + Argon2id (t=3, m=64 MiB, p=4) + 6 UI badges
- Mobile / Extension: In-app cloud file previews (CloudFilePreviewScreen), settings cleanup, cloud tab embedding and entry selector UI redesign
- Extension: SyncConflictBanner UI (P1-3): visible surface when the remote vault is newer
- Blog: Blog API routes (POST/PATCH/DELETE) + n8n workflow for auto-publishing to website & X
- Dev.to: 4 cover images for dev.to articles (1Password vs VaultKeepR, Bitwarden vs VaultKeepR, Lastpass migration, zero-knowledge encryption)
- Web: /pricing and /fr/pricing pages with FAQPage + Product JSON-LD, inline MiniPricing on home, StickySubNav, dismissible TopBanner, ComparePreview (6 /compare cards), 3 long-tail articles (raspberry-pi, no-email, argon2id-vs-bcrypt), BACKLINK-PLAN.md, 38 new i18n keys EN + FR
- Sync: Full cross-device P0-P2 audit (10 fixes, 0 regression)
- P0-2: restoreIpfsMetadata moved from LWW entry-level to field-level 3-way merge (5 tests)
- P0-4: Mobile pull/upload race condition resolved via shared in-process mutex (9 tests)
- P1-1: CRDT entry-replace staleness fix (mergeDocuments, mergeIndependentDocs): 6 tests
- P1-3: SyncConflict descriptor surface + 2 IPC messages + 5 i18n keys FR/EN (5 storage tests)
- P1-4: Merge base snapshot pre-push in IpfsAutosave (local edit loss cross-device)
- P1-5: getDeviceId() returns a stable UUID v4 per install (instead of buggy “ios-ios”): 12 tests
- P2-1: Cross-device E2E test (crossDevice.e2e.test.ts): 9 scenarios (found 2 real bugs)
- P2-2: purgeTombstones() now called after merge
- SEO: Fixed GSC issues: 301 redirects on /landing and /passkey-auth, noindex on /settings, /turbo-*, /premium/checkout, og/twitter images and _next/static, bug bounty removed from sitemap, real blog dates in sitemap
- Extension: escapeHtml now escapes ” and ’; includesIgnoreAccents via stripDiacritics; simulateUserFill removed element.click(), dispatches beforeinput first, respects defaultPrevented; V1 phishing overlay backward-compat; classifyFormSignals by typed intent (7 call sites); handleFill scoped to nearest form
- Extension: Fixed Rules of Hooks in overlays-v2/generate (useCallback/useMemo before early return) + missing i18n keys generator.copy and generator.strength.*
- n8n: Regenerated workflow JSON with proper escaping (valid JSON)
- Dev.to: Redesigned cover images
Improvements
Section titled “Improvements”- Web: SEO overhaul: HeroSection with visible keyword H1, trust signals, secondary CTA, anchor IDs (#features, #how-it-works, #security, #faq), moved 31 obsolete .md files to archive/
- Tests: Comprehensive security test suite: 1015 tests across all packages; 1529/1529 passing (105 files, 0 failures) after 30 test fixes
Versioning
Section titled “Versioning”- Chrome/Firefox extension: 1.7.0 (already aligned)
- iOS: 1.6.5 -> 1.7.0 (build 6 -> 7)
- Android: 1.6.5 -> 1.7.0 (versionCode 31 -> 33)
1.6.5 — 2026-06-02
Section titled “1.6.5 — 2026-06-02”- Legacy: Cross-device, end-to-end encrypted synchronization of beneficiary metadata via IPFS
- Robust cryptographic mechanism using HKDF and local key derivation to guarantee zero-knowledge privacy
- Server route /api/legacy/beneficiaries-cid to decentralize the storage of the IPFS content identifier (CID)
- Android: Full native implementation of AutofillService (VaultAutofillService.kt) for secure, system-wide credential autofill
- iOS: Fixed UI refresh and state navigation after manual or automatic Legacy activation
- Extension: Enhanced domain matching precision for TOTP and credentials autofill queries
- Mobile / Extension: Fixed visibility and rendering issues of beneficiary labels on secondary devices
1.6.4 — 2026-05-29
Section titled “1.6.4 — 2026-05-29”-
Legacy: New encrypted vault inheritance system for designated beneficiaries
-
Smart Contract: VaultKeeperLegacy.sol (Base Mainnet: Chain ID 8453)
-
On-chain heartbeat with configurable cooldown
-
Multi-beneficiary management with percentage-based shares (must total 100%)
-
Activation by owner or automatic heartbeat expiry
-
Encrypted fragment claiming via ECDSA signature (EIP-712 envelope)
-
Events emitted:
HeartbeatUpdated,VaultActivated,FragmentClaimed -
Foundry deployment script (
DeployLegacy.s.sol): deployed on Base Mainnet -
Package @vault-keeper/legacy: Full TypeScript SDK
-
heartbeat.ts: On-chain heartbeat update + automated scheduling (1x/week) -
beneficiary.ts: Add/remove/list beneficiaries with share validation -
envelope.ts: ECIES encryption of vault fragments per beneficiary -
contract.ts: ABI and helpers for interacting withVaultKeeperLegacy -
legacy.ts: High-level orchestrator (activation, claim, status) -
Test suite: 3 unit test files (heartbeat, beneficiary, envelope)
-
Web: 8 new API routes /api/legacy/*
-
activate: Manual legacy activation (owner only) -
check-expiry: Heartbeat expiry verification -
claim: Fragment claim by a beneficiary (with ECDSA signature) -
claim-invite: Beneficiary invitation link validation -
encode-call: Calldata encoding for on-chain transactions -
invite: Invitation link generation and delivery to beneficiaries -
notify: Telegram + email notification to beneficiaries -
status: Full legacy vault status (heartbeat, beneficiaries, activation state) -
Web: Beneficiary invitation page (/legacy/invite)
-
Dedicated layout with invitation token validation
-
Claim interface with wallet connection and signature flow
-
iOS / Android: New LegacyScreen
-
Legacy configuration dashboard (heartbeat, beneficiary list, status)
-
Add/remove beneficiaries with share allocation
-
Visual heartbeat status indicator (active / expired / not configured)
-
Integrated navigation from
RootNavigatorandSettingsScreen -
Extension: New LegacyPanel
-
Accessible from extension settings (SettingsView)
-
Legacy configuration and heartbeat status visualization
-
Telegram Bot: Legacy notification bot (telegramBot.ts)
-
Sends structured messages to beneficiaries upon vault activation
-
Claim instructions with direct link to /legacy/invite
-
Full setup documentation (docs/TELEGRAM_BOT_SETUP.md)
-
Legacy Emails: Email templates for beneficiary notifications (legacyEmails.ts)
-
Initial invitation email with claim instructions
-
Activation email with secure link and deadline
- Crypto Payments: Refactored /api/premium/crypto/order and /api/premium/crypto/status routes
- Separated order/status responsibilities
- Improved error handling for on-chain polling
- Alias: Updated packages/alias/src/config.ts configuration
- Smart Account: Updated packages/smart-account/src/config.ts configuration
Types & i18n
Section titled “Types & i18n”- Core: Extended packages/core/src/types.ts with Legacy types (LegacyConfig, Beneficiary, LegacyStatus)
- i18n: Added Legacy translation keys in packages/i18n/src/translations.ts (FR + EN)
Infrastructure
Section titled “Infrastructure”- Vercel: Added apps/web/vercel.json for rewrite rules and security headers configuration
- Broadcast: Foundry deployment artifacts on Base Mainnet (contracts/broadcast/DeployLegacy.s.sol/8453/)
- Tests: VaultKeeperLegacy.t.sol test suite for the smart contract
Versioning
Section titled “Versioning”- legacy branch created from release/1.6.4
- VaultKeeperLegacy smart contract deployed on Base Mainnet (Chain ID 8453)
1.6.3 — 2026-05-24
Section titled “1.6.3 — 2026-05-24”Security
Section titled “Security”- HPKP: Added Public-Key-Pins header (report-only) on app.vaultkeepr.xyz with SHA-256 pin of the Let’s Encrypt certificate
- Bundler Relay: Secure proxy /api/relay/bundler for ERC-4337 calls (Pimlico) — API key is no longer exposed client-side
- Extension: Fixed false positive login form detection (login-detect.ts)
- Added 17+ ignore patterns (contact, newsletter, support, chat, feedback, subscribe, etc.)
- hasLoginForm() now requires 2+ signals (autocomplete, pattern, label) instead of 1
- Standalone email fields in non-login forms no longer trigger the overlay
- Extension: Username is now captured at form submit time (snapshot _pendingSaveData)
- Fixes the bug where only the password was saved during credential capture
- Save prompt uses snapshotted credentials instead of re-collecting DOM fields (prevents empty values after SPA navigation)
- Extension: Added automatic save prompt after password generation via the extension button
- 2-second post-generation timer to allow username field completion
- Automatic add/update detection based on existing entries
- Extension: Fixed “Premium required to create email aliases” bug (usePremium.ts)
- Added cross-address discovery (findAnyStoredLicenseKey) when address changes (EOA → Smart Account migration)
- Automatic license migration to the new address
- Extension: Generated passwords are now accessible in the generator history
- getGeneratedHistory() now returns passwords (previously stripped for security but prevented reveal + copy)
Improved
Section titled “Improved”- Extension / iOS / Android: Added reveal/hide toggle (Eye/EyeOff) in password history
- Generator: each generated password is masked by default with individual toggle
- Credential detail: old password history now has a per-item reveal toggle
- Consistent behavior across all 3 platforms
- Notes: Fixed note font color in credentials (white color consistency)
Versioning
Section titled “Versioning”- Chrome/Firefox Extension: 1.6.2 → 1.6.3
- iOS: 1.6.1 → 1.6.3 (build 4)
- Android: 1.6.1 → 1.6.3 (versionCode 26)
1.6.2 — 2026-05-22
Section titled “1.6.2 — 2026-05-22”- QRSync: Fixed vault transfer from iOS to the extension — the received vault is now correctly imported into extension storage (the CustomEvent had no listener)
- QRSync: Fixed AA (Account Abstraction) address mismatch after vault reception — secretKey is now stored before the cached password to prevent a race condition during identity derivation
- QRSync: Settings panel now auto-closes after a successful import
- QRSync: Automatic Premium license transfer during device pairing
Improved
Section titled “Improved”- IPFS Sync: Polling interval reduced from 30s/60s to 10 seconds across all platforms (iOS + Extension)
- Extension: Popup polls IPFS every 10s while open (chrome.alarms limited to 30s in background)
- Extension: Background alarms reduced from 5min/1min to 30s/30s
Versioning
Section titled “Versioning”- Chrome/Firefox Extension: 1.6.1 -> 1.6.2
- iOS: polling interval changed (no version bump)
1.6.1 — 2026-05-19
Section titled “1.6.1 — 2026-05-19”Security
Section titled “Security”-
P0 Audit — In-App Purchase: Complete IAP validation pipeline hardening
-
(P0-#1) Server-side Android IAP validation via Google Play Developer API (purchases.subscriptionsv2.get, JWT RS256)
-
(P0-#2) Cryptographic verification of Apple StoreKit 2 JWS signatures
-
Pinned Apple Root CA - G3 certificate (SHA-256 fingerprint verified)
-
x5c chain validation (DER), ES256 IEEE-P1363 signature verification
-
8 rejection test cases (alg=none, alg=HS256, missing x5c, invalid DER)
-
(P0-#3) Strict productId whitelist (productIdMap.ts) — removed all String.includes() tier inference
-
Apple:
com.vaultkeeper.app.. -
Android:
(productId, basePlanId)tuple — 10 test cases -
(P0-#4) Rejected legacy 0xpasskey signatures (public rawId bypass)
-
Synthetic address derived from rawId is no longer accepted server-side
-
5 tests covering the historical forgery vector
-
Passkey ECDSA: Real cryptographic infrastructure for wallet-less users
-
Phase 2: secp256k1 derivation via WebAuthn PRF extension + HKDF-SHA256
-
Phase 3: Stealth signer wired into VaultView (4 callsites replaced)
-
TOFU (Trust-On-First-Use) binding with anti-squat protection via expectedCid
-
Zero npm dependencies added — uses @noble/hashes, @noble/curves, viem
-
WalletConnect: Complete removal of WalletConnect protocol from the extension
-
walletConnect.js replaced with a deprecated no-op stub (482 -> 72 lines)
-
Removed WalletConnect WSS endpoints from CSP and manifest
-
Identity is now managed exclusively through Account Abstraction (Smart Wallet)
- Sync: Hardened 3-way merge (threeWayMerge) — 4 data-loss bugs fixed
- B1: Cross-device folder deletion propagation via folderTombstones (30-day TTL)
- B2: cloudQuotaUsed recomputed from merged files (no more upward drift)
- B3: Field-level merge for documents and cloudFiles (no more whole-item LWW)
- B4: Deterministic tie-breaker for simultaneous conflicts
- 16 regression tests
- Resilience: Preserved local state on transient server errors (5xx / network)
- cidPointer.ts: Discriminated result type (auth vs network vs corrupted) — no more premature delegation clearing
- PremiumContext: Premium cache preserved on 5xx/network errors (iOS, Android, Web)
- Mobile: Fixed AA address drift after biometric re-authentication
- Replaced getOrCreateSecretKey() with getStoredSecretKey() during biometric unlock (iOS + Android)
- Forced identity initialization even with empty password (Passkey flow)
- Extension: Auto-sign with Hidden Wallet as fallback when no delegation is available
- Extension: Simplified CSP (connect-src ‘self’ https:) — removed WalletConnect whitelist
- iOS: Fixed Restore Purchase on StoreKit 2 (getAvailablePurchases instead of broken restorePurchases in expo-iap v3)
- Mobile: Tag filter in credentials list (iOS + Android)
- Horizontal scrollable bar with dynamic colored chips
- Tap selection/deselection with haptic feedback
Versioning
Section titled “Versioning”- Chrome/Firefox Extension: 1.6.0 -> 1.6.1
- iOS: 1.6.0 -> 1.6.1 (build 1)
- Android: 1.6.0 -> 1.6.1 (versionCode 19)
1.6.0 — 2026-05-17
Section titled “1.6.0 — 2026-05-17”Security
Section titled “Security”- Sharing v2 (SEC-R4): Removed the ECDH self-loop in the secure sharing protocol
- Direct HKDF(ephemeralPrivKey, SHA256(PIN)) derivation instead of redundant ECDH(priv, priv*G)
- URL fragment now carries the private key (32 bytes) instead of the public key (65 bytes) — shorter URLs
- Compact v2 blob (no encrypted private key in the blob, -72 bytes)
- v1 backward compatibility maintained for existing shares
- 8 callers updated across iOS, Android, Extension, and Web
- Extension CSP (SEC-R7): Hardened Content Security Policy with 9 explicit directives
- default-src ‘self’ — everything blocked by default
- connect-src restricted to 5 whitelisted domains + 2 WalletConnect WSS endpoints
- frame-src ‘none’, object-src ‘none’, base-uri ‘self’
- wasm-unsafe-eval preserved (required by Argon2 + Automerge CRDT)
- Audit confirmed: zero eval() / new Function() in the codebase
- Core: Fixed openpgp/lightweight -> openpgp in import.ts
- The ./lightweight subpath lacks a Node-compatible import condition — was blocking tests
- Resolved 2 pre-existing test failures in the core test suite
- Unblocked @vault-keeper/recovery package (tests were unrunnable before)
- P2 Parity: Formalized 6 features already implemented but undocumented
- Android Credential Provider (VaultAutofillService.kt)
- Google Play Billing (PremiumContext.tsx + expo-iap)
- Email Aliases iOS/Android (AliasPanel.tsx + useAlias.ts)
- Password History (3 platforms)
- Passphrase Generator (3 platforms)
- Seed Phrase Manager (Extension EditForm + DetailPane + iOS/Android folders)
- 241 tests, 0 failures (up from 163 tests with 2 failures in 1.5.x)
- @vault-keeper/core: 95 -> 173 tests (+78)
- @vault-keeper/premium: 6 -> 31 tests (+25)
- @vault-keeper/recovery: 0 -> 8 tests (unblocked)
- New test files: sharing.test.ts, passwordHealth.test.ts, passwordStrength.test.ts
Versioning
Section titled “Versioning”- Unified cross-platform version to 1.6.0
- Chrome/Firefox Extension: 1.5.0 -> 1.6.0
- iOS: 1.5.1 -> 1.6.0 (build 8)
- Android: 1.5.2 -> 1.6.0 (versionCode 19)
1.5.2 — 2026-05-05
Section titled “1.5.2 — 2026-05-05”- iOS: Resolved Apple App Store rejection (Guideline 3.1.2(c)) — added Terms of Use and Privacy Policy links in the in-app purchase flow
- iOS: Removed visible license key input field (Guideline 3.1.1) — cross-platform premium now resolves silently via wallet address
- iOS: Added legal footer below purchase button with auto-renewal disclosure
- iOS: Optimized PremiumScreen layout to ensure legal footer visibility for reviewers
- Android: Build AAB 1.5.2 (versionCode 10) for Play Store
- i18n: Replaced all remaining hardcoded French strings with proper translation keys
1.5.1 — 2026-05-04
Section titled “1.5.1 — 2026-05-04”- Web: Achieved functional parity between Webapp and iOS — integrated sync management
- Web: Added Delegation Status Card and Wallet Connection display in Settings Sync tab
- Web: Finalized delegation renewal flow (message signing + persistent storage)
- Web: Removed legacy CRDT synchronization dead code causing JSON compatibility errors
- iOS: Restored IPFS synchronization and recovery flow
- i18n: Fixed missing translation keys for sync status indicators
1.5.0 — 2026-05-03
Section titled “1.5.0 — 2026-05-03”- Premium: New 4-tier subscription model (Free / Premium / Pro / Ultimate)
- Free: 1 document, 5 MB max file size, no cloud storage
- Premium: 2 documents, 25 MB max, 10 MB cloud
- Pro: 5 documents, 25 MB max, 50 GB cloud
- Ultimate: unlimited documents, 50 MB max, unlimited storage
- Cloud: Encrypted multi-node cloud storage with end-to-end encryption
- Crypto Payments: Anonymous multi-chain checkout (BTC, ETH, SOL, USDC) for the Lifetime plan at EUR 299
- Multi-chain HD Wallet with real-time on-chain polling
- CoinGecko live exchange rates
- Flexible timer (2h for BTC, 30min for others)
- Automated license key delivery — zero email required
- Landing Page: Overhaul with new feature cards (Cloud Storage, Quick Share, TOS AI, Password Health), Premium crown badges (Lucide), Android/Play Store link
- Privacy Policy: Updated to reflect new cross-platform data handling practices
- Android: First AAB build 1.5.0 for Google Play Store (internal test track)
- Extension: Published v1.5.0 on Chrome Web Store and Firefox Add-ons
- Extension: Resolved production build dependency issues
- iOS: Synchronized Xcode versions (1.5.0, build 8)
- Legal: Updated Terms of Service with Lifetime plan, Fair Use policy, and non-refundable crypto disclaimers
1.4.0 — 2026-04-29
Section titled “1.4.0 — 2026-04-29”- Extension: Redesigned anti-phishing banners — more visible and informative
- Extension / iOS: Interactive onboarding tour with spotlight guide for new users
- Extension: Improved email alias management panel
- NFC: Full PACE protocol implementation on iOS — encrypted password read/write on NFC tags
- Passkeys: Cross-platform WebAuthn/FIDO2 support (Extension + iOS)
- IPFS Sync: Improved cross-platform synchronization with emoji cleanup in translations
- CRDT Sync: New @vault-keeper/sync package based on Automerge
- Phase 2: Integrated CRDT merge across all platforms
- Phase 3: Dual-format IPFS payloads (JSON + CRDT)
- Phase 5: Cleanup and tombstone management
- CI: Automated workflow to sync public packages to the open-core repository
- Recovery: Fixed type mismatch for decryptVault return type in fragmented vault creation
- Mobile: Resolved spotlight tour coordinate misalignment on Android
- Tests: Updated vault migration tests to reflect new notes and seeds categorization logic
1.3.0 — 2026-04-21
Section titled “1.3.0 — 2026-04-21”- Secure Share: Complete redesign of the secure sharing module
- New secret.vaultkeepr.xyz subdomain for shared links
- Optional personal message with each share
- Full i18n (FR + EN) for all module strings
- Quick Share: New standalone module across all platforms (Web, Extension, iOS, Android)
- Share links, notes, and files (Premium only)
- Upload up to 50 MB with custom message
- Accessible via shortcut button in the extension toolbar
- Extension: Full popup navigation and UI redesign
- Reorganized settings menu into 5 logical categories
- Fixed password generator display
- Extension: CSP bleeding overlay fix (display: none inline)
- Extension: WalletConnect attestation 400 fix (corrected metadata.url)
- Extension: Added public key to manifest to stabilize extension ID across dev browsers
- Extension: declarativeNetRequest to spoof Origin on WalletConnect WebSockets (bypass 403)
- i18n: Removed duplicate title key in generator translations
1.2.0 — 2026-04-20
Section titled “1.2.0 — 2026-04-20”- NFC PACE: Identity document NFC authentication via the PACE protocol (iOS)
- Secure Documents: Encrypted document vault (Premium)
- Upload and encrypt sensitive documents (ID cards, passports, driver’s licenses, bank details, insurance)
- Fragmented across multiple IPFS nodes using XChaCha20-Poly1305
- Blurred thumbnail preview with timed reveal (15-second auto-hide)
- OCR text extraction with NFC-based biometric verification
- Android: First release of the Android mobile application (React Native + Expo 55)
- Extension: Multiple stability fixes
1.1.0 — 2026-04-05
Section titled “1.1.0 — 2026-04-05”- Premium: Complete visual overhaul (Glassmorphism, animations, global UI refresh)
- New Premium subscription modal
- Security tools integration into the Premium interface
- Web: Premium visual overhaul with modal, Password Health and Breach Scanner integration
- iOS/Web: Fixed IPFS sync authentication, removed double Face ID prompt, improved ListScreen performance
- CSP: Added nonce to JSON-LD scripts in layout and blog pages
1.0.0 — 2026-03-30
Section titled “1.0.0 — 2026-03-30”First stable release tag.
- Core: XChaCha20-Poly1305 + Argon2id cryptographic engine (64 MiB, 3 iterations, 4 parallelism)
- HMAC-SHA256 commitment scheme (prevents ciphertext substitution)
- Gzip compression before encryption
- Vault versions 2 and 3 support
- Recovery: Shamir Secret Sharing (3-of-5) with HKDF-encrypted fragments
- Distribution: Device, IPFS, Trusted Contact, Smart Contract, VaultKeepR API
- Premium: HMAC-SHA256 server-signed license key system
- Stripe (Web), In-App Purchase (iOS), license key activation (Extension)
- Premium branded email templates (dark theme, logo, bilingual)
- IPFS: Upload/download with multi-gateway fallback (Promise.any())
- Passkeys: Full WebAuthn/FIDO2 support (ES256, P-256 ECDSA)
- TOTP: Built-in authenticator (SHA-1, SHA-256, SHA-512) with animated countdown
- Password Health: Dashboard with zxcvbn scoring, reuse detection
- Breach Monitoring: HIBP integration with k-anonymity
- Email Aliases: Privacy-focused email alias generation and management (Premium)
- Password Generator: Cryptographically secure generation with rejection sampling (eliminates modulo bias)
- Smart Contract: VaultKeeperFragments.sol — on-chain encrypted fragment storage (EVM)
- Bug Bounty: Bug Bounty Vault Challenge with dedicated page, scripts, and API
- Web App: Next.js 15 (App Router)
- Landing page with particle animations and glassmorphism
- Full vault CRUD (passwords, cards, identities, documents)
- SEO blog (12 articles)
- Bilingual legal pages (Privacy Policy, Terms of Service, Security Policy)
- Sitemap, robots.txt, OpenGraph, JSON-LD
- iOS App: React Native 0.83.2 + Expo 55
- Face ID / Touch ID biometric unlock
- NFC document scanning
- Credential Provider Extension (iOS AutoFill)
- WalletConnect v2 deep linking
- 23 screens
- Chrome Extension: Manifest V3
- Smart login form detection with autofill overlay
- Registration form detection with password generator
- Identity and credit card autofill
- Autosave observer (detects successful form submissions)
- dApp phishing detection (MetaMask, ChainPatrol, Scam Sniffer registries)
- Keyboard shortcuts (Cmd+Shift+L, Cmd+Shift+G)
- Command palette (Cmd+K)
- 39 React components in popup
- Firefox Extension: Chrome codebase port with adapted manifest
- i18n: Full French + English translations (@vault-keeper/i18n)
- CI/CD: GitHub Actions pipeline (lint, type-check, build, test, E2E Playwright)
- Tests: 241+ unit and integration tests across 7 packages
- Legal: ANSSI declaration, BIS Export Control, Chrome Web Store and Firefox Add-ons compliance
- Security:
- Comprehensive pre-bug bounty audit (C1, C2, H1-H4, M3, M5, L1)
- Removed PBKDF2 (v1) — Argon2id only
- Removed unsafe-eval from CSP
- Auto-backup of stores
- Full API hardening (auth + rate limiting on all routes)
- Umami API monitoring via middleware
- Server hardening (SSH key-only, UFW, Fail2Ban, systemd sandboxing)
0.x — 2026-03-03 to 2026-03-29 (Pre-release)
Section titled “0.x — 2026-03-03 to 2026-03-29 (Pre-release)”Initial Infrastructure
Section titled “Initial Infrastructure”- 2026-03-03: Initial commit + Expo 55 dependency sync for iOS
- 2026-03-21: Full monorepo import with Turborepo structure
- GitHub Actions CI configuration (Node 22)
- Resolved workspace lockfile issues
- Build pipeline: core > i18n > ipfs > wallet > premium > alias > cloud > web > extension
Pre-1.0 Development
Section titled “Pre-1.0 Development”- 2026-03-24: Fragments UI, “Coming Soon” landing, Premium system, Solidity contracts
- 2026-03-26: UI/UX modernization + VaultView.tsx refactoring (3670 to 2677 lines, -27%)
- Extracted UI components
- 40 unit tests for extracted modules
- First-run onboarding overlay for extension
- 2026-03-27: Added framer-motion for extension popup animations
- 2026-03-28: Custom IPFS gateway, WalletConnect fix, content script modular architecture
- 2026-03-29: iOS UX modernization — visual alignment with extension
Pre-launch Security Hardening (2026-03-31 to 2026-04-02)
Section titled “Pre-launch Security Hardening (2026-03-31 to 2026-04-02)”- Legal, security, monitoring, and backup audit
- Privacy policy rewrite
- API hardening (auth + rate limiting)
- Real-time TOTP overlay with Fill + Copy buttons
- Overlay performance: reduced latency (30ms debounce, 5s TTL cache, 150ms animations)
- QR code WalletConnect for IPFS save signature
- Complete vault isolation (purge WC SDK keys)
Current Platform Versions —
Section titled “Current Platform Versions —”| Platform | Version | Distribution |
|---|---|---|
| Web App | 1.6.5 | vaultkeepr.xyz |
| Chrome Extension | 1.8.0 | Chrome Web Store |
| Firefox Extension | 1.8.0 | Firefox Add-ons |
| iOS | 1.8.0 (build 8) | App Store |
| Android | 1.8.0 (versionCode 34) | Google Play |
| Smart Contract (Legacy) | Base Mainnet | basescan.org |
VaultKeepR — Decentralized. Private. Yours.