Ethereum Wallet ToolkitCAUTION
Python toolkit for Ethereum wallets: CLI tools + Model Context Protocol (MCP) servers for wallet generation, BIP39/BIP44 HD wallets, Web3 Secret Storage V3 keystores, and EIP-712 typed data signing
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A collection of Ethereum wallet tools: Python CLI utilities (eth_toolkit.py, wallet.py, keystore.py, sign.py, transaction.py, typed_data.py, validate.py, vanity.py), five Model Context Protocol (MCP) servers exposing wallet functionality to AI assistants, a fully offline single-file HTML wallet (offline.html), and an x402 payment facilitator. See the sections below for each component.
Offline Build - Official Ethereumjs Libraries
This directory contains the build system to create offline1.html using official ethereumjs libraries.
Libraries Used
All libraries are from the official Ethereum ecosystem:
@ethereumjs/tx- Transaction signing (legacy + EIP-1559)@ethereumjs/util- Utilities (address validation, checksums, etc.)@ethereumjs/rlp- RLP encoding@ethereumjs/wallet- Wallet utilitiesethereum-cryptography- Official cryptographic primitives (secp256k1, keccak256)@scure/bip39- BIP39 mnemonic (used by ethereumjs)@scure/bip32- BIP32 HD derivation (used by ethereumjs)
Build Instructions
# Navigate to this directory cd offline-build # Install dependencies npm install # Build offline1.html npm run build
The output file offline1.html will be created in the parent directory.
What Gets Bundled
The build process uses esbuild to:
- Bundle all ethereumjs libraries and their dependencies
- Minify the code for smaller file size
- Inline everything into a single HTML file
Typical bundle size: ~400-600 KB (varies by version)
Features
All features match the CLI tool:
- Wallet Generation - Random keypair generation
- Mnemonic Support - Create/restore BIP39 mnemonics, derive accounts
- Vanity Addresses - All vanity options (prefix, suffix, regex, etc.)
- Message Signing - EIP-191 personal_sign
- Signature Verification - Recover signer from signature
- Validation - Address and key validation
- Keystore - V3 keystore encry
ad293a8d4effOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ethereum-wallet-mcp -- uvx ethereum-wallet-mcp==1.0.0
claude mcp add keystore-mcp-server -- uvx keystore-mcp-server==1.0.0
claude mcp add signing-mcp-server -- uvx signing-mcp-server==1.0.0
Exposed tools (62)
59 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_transaction | read | |
batch_encrypt_keystores | read | |
batch_validate_addresses | read | |
build_transaction | read | |
calculate_gas_for_data | read | |
calculate_storage_slot | read | |
change_keystore_password | read | |
compare_addresses | read | |
compare_transactions | read | |
compose_signature | read | |
convert_gas_units | read | |
decode_calldata | read | |
decode_function_selector | read | |
decode_raw_transaction | read | |
decompose_signature | read | |
decrypt_keystore | read | |
derive_address_from_private_key | read | |
derive_address_from_public_key | read | |
derive_multiple_accounts | read | |
encode_approve | read | |
encode_function_call | read | |
encode_function_selector | read | |
encode_transfer | write | |
encode_transfer_from | write | |
encrypt_keystore | read | |
estimate_transaction_cost | read | |
generate_typed_data_template | read | |
generate_vanity_address | read | |
generate_vanity_check | read | |
generate_wallet | read | |
generate_wallet_with_mnemonic | read | |
get_gas_estimate | read | |
get_keystore_info | read | |
get_typed_data_template | read | |
hash_typed_data | read | |
keccak256_hash | read | |
keystore_to_private_key_file | read | |
load_keystore_file | read | |
normalize_signature | read | |
recover_signer | read | |
recover_transaction_signer | read | |
recover_typed_data_signer | read | |
restore_wallet_from_mnemonic | read | |
restore_wallet_from_private_key | read | |
save_keystore_file | write | |
sign_hash | read | |
sign_message | read | |
sign_message_hex | read | |
sign_transaction | read | |
sign_transaction_object | read | |
sign_typed_data | read | |
to_checksum_address | read | |
validate_address | read | |
validate_ens_name | read | |
validate_hex_data | read | |
validate_keystore | read | |
validate_private_key | read | |
validate_signature | read | |
validate_signature_format | read | |
validate_transaction | read | |
verify_message | read | |
verify_typed_data | read |
Trust audit
CAUTIONgrade C · trust 73/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
print(f"Private Key: {result.private_key}")print(f"Private Key: {result.private_key}")print(f"Private Key: {result.private_key}")print(f" Key: {acc.private_key}")print(f"Private Key: {result.private_key}")token: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913' as Address,
token: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913' as Address,
.commit
.keep
.keep
.keep
.commit
dangerous_path = "/home/user/../../../etc/passwd"
import type { X402Payment } from '../../src/types/index.js';vi.mock('../../src/config/env.js', () => ({vi.mock('../../src/utils/logger.js', () => ({vi.mock('../../src/utils/metrics.js', () => ({extraData: "0x22466c6578692069732061207468696e6722202d204166726900000000000000e0a2bd4258d2768837baa26a28fe71dc079f84c70000000000000000000000000000000000000000000000000000000000000000000000000000000000
extraData: "0x22466c6578692069732061207468696e6722202d204166726900000000000000e0a2bd4258d2768837baa26a28fe71dc079f84c70000000000000000000000000000000000000000000000000000000000000000000000000000000000
key_bytes = bytes.fromhex(private_key)
tx_bytes = bytes.fromhex(raw_transaction)
addr_bytes = bytes.fromhex(address[2:])
addr_bytes = bytes.fromhex(account.address[2:])
return bytes.fromhex(msg_hex)
eth-account
Gates applied: no_behavioural_pass.
ad293a8d4efffull audit observations/trust-audit/mcp-server/nirholas__ethereum-wallet-toolkit.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | ad293a8d4eff | CAUTION | C | 73 | first audit |
Questions
What is the Ethereum Wallet Toolkit MCP server?
Python toolkit for Ethereum wallets: CLI tools + Model Context Protocol (MCP) servers for wallet generation, BIP39/BIP44 HD wallets, Web3 Secret Storage V3 keystores, and EIP-712 typed data signing
What tools does Ethereum Wallet Toolkit expose?
62 in total: 59 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Ethereum Wallet Toolkit safe to connect to an agent?
With care. The audit graded it C (73/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Ethereum Wallet Toolkit need?
No credential environment variables were found in its source, so it appears to need none.
How does Ethereum Wallet Toolkit run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as x402-facilitator at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (ad293a8d4eff), read on 2026-10-09. The repository is watched and re-audited when it changes.