Atlas / MCP servers / nirholas / Ethereum Wallet Toolkit

Ethereum Wallet ToolkitCAUTION

mcp/nirholas/ethereum-wallet-toolkit

Python toolkit for Ethereum wallets: CLI tools + Model Context Protocol (MCP) servers for wallet generation, BIP39/BIP44 HD wallets, Web3 Secret Storage V3 keystores, and EIP-712 typed data signing

Verdict
CAUTION
Grade
C
Trust score
73 /100
Exposed tools
62 59r · 3w · 0d
Transport
stdio
License
NOASSERTION
Stars
25
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A collection of Ethereum wallet tools: Python CLI utilities (eth_toolkit.py, wallet.py, keystore.py, sign.py, transaction.py, typed_data.py, validate.py, vanity.py), five Model Context Protocol (MCP) servers exposing wallet functionality to AI assistants, a fully offline single-file HTML wallet (offline.html), and an x402 payment facilitator. See the sections below for each component.

Offline Build - Official Ethereumjs Libraries

This directory contains the build system to create offline1.html using official ethereumjs libraries.

Libraries Used

All libraries are from the official Ethereum ecosystem:

  • @ethereumjs/tx - Transaction signing (legacy + EIP-1559)
  • @ethereumjs/util - Utilities (address validation, checksums, etc.)
  • @ethereumjs/rlp - RLP encoding
  • @ethereumjs/wallet - Wallet utilities
  • ethereum-cryptography - Official cryptographic primitives (secp256k1, keccak256)
  • @scure/bip39 - BIP39 mnemonic (used by ethereumjs)
  • @scure/bip32 - BIP32 HD derivation (used by ethereumjs)

Build Instructions

# Navigate to this directory
cd offline-build

# Install dependencies
npm install

# Build offline1.html
npm run build

The output file offline1.html will be created in the parent directory.

What Gets Bundled

The build process uses esbuild to:

  1. Bundle all ethereumjs libraries and their dependencies
  2. Minify the code for smaller file size
  3. Inline everything into a single HTML file

Typical bundle size: ~400-600 KB (varies by version)

Features

All features match the CLI tool:

  • Wallet Generation - Random keypair generation
  • Mnemonic Support - Create/restore BIP39 mnemonics, derive accounts
  • Vanity Addresses - All vanity options (prefix, suffix, regex, etc.)
  • Message Signing - EIP-191 personal_sign
  • Signature Verification - Recover signer from signature
  • Validation - Address and key validation
  • Keystore - V3 keystore encry
Read from source at commit ad293a8d4effOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add ethereum-wallet-mcp -- uvx ethereum-wallet-mcp==1.0.0
claude-code (pypi)
claude mcp add keystore-mcp-server -- uvx keystore-mcp-server==1.0.0
claude-code (pypi)
claude mcp add signing-mcp-server -- uvx signing-mcp-server==1.0.0
03

Exposed tools (62)

59 read · 3 write · 0 destructive.

ToolRiskDescription
analyze_transactionread
batch_encrypt_keystoresread
batch_validate_addressesread
build_transactionread
calculate_gas_for_dataread
calculate_storage_slotread
change_keystore_passwordread
compare_addressesread
compare_transactionsread
compose_signatureread
convert_gas_unitsread
decode_calldataread
decode_function_selectorread
decode_raw_transactionread
decompose_signatureread
decrypt_keystoreread
derive_address_from_private_keyread
derive_address_from_public_keyread
derive_multiple_accountsread
encode_approveread
encode_function_callread
encode_function_selectorread
encode_transferwrite
encode_transfer_fromwrite
encrypt_keystoreread
estimate_transaction_costread
generate_typed_data_templateread
generate_vanity_addressread
generate_vanity_checkread
generate_walletread
generate_wallet_with_mnemonicread
get_gas_estimateread
get_keystore_inforead
get_typed_data_templateread
hash_typed_dataread
keccak256_hashread
keystore_to_private_key_fileread
load_keystore_fileread
normalize_signatureread
recover_signerread
recover_transaction_signerread
recover_typed_data_signerread
restore_wallet_from_mnemonicread
restore_wallet_from_private_keyread
save_keystore_filewrite
sign_hashread
sign_messageread
sign_message_hexread
sign_transactionread
sign_transaction_objectread
sign_typed_dataread
to_checksum_addressread
validate_addressread
validate_ens_nameread
validate_hex_dataread
validate_keystoreread
validate_private_keyread
validate_signatureread
validate_signature_formatread
validate_transactionread
verify_messageread
verify_typed_dataread
04

Trust audit

CAUTIONgrade C · trust 73/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
eth_toolkit.py:880
print(f"Private Key: {result.private_key}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
eth_toolkit.py:906
print(f"Private Key: {result.private_key}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
eth_toolkit.py:911
print(f"Private Key: {result.private_key}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
eth_toolkit.py:931
print(f"    Key:  {acc.private_key}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
eth_toolkit.py:1027
print(f"Private Key: {result.private_key}")
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
x402-facilitator/tests/fixtures/payments.ts:10
token: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913' as Address,
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
x402-facilitator/tests/unit/settler.test.ts:60
token: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913' as Address,
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.commit
.commit
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.keep
.keep
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
ethereum-wallet-mcp/.keep
.keep
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
keystore-mcp-server/.keep
.keep
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
offline-build/.commit
.commit
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
keystore-mcp-server/tests/test_file_ops.py:133
dangerous_path = "/home/user/../../../etc/passwd"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
x402-facilitator/tests/fixtures/payments.ts:3
import type { X402Payment } from '../../src/types/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
x402-facilitator/tests/unit/facilitator.test.ts:3
vi.mock('../../src/config/env.js', () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
x402-facilitator/tests/unit/facilitator.test.ts:20
vi.mock('../../src/utils/logger.js', () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
x402-facilitator/tests/unit/facilitator.test.ts:24
vi.mock('../../src/utils/metrics.js', () => ({
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
offline-build/offline.html:9654
extraData: "0x22466c6578692069732061207468696e6722202d204166726900000000000000e0a2bd4258d2768837baa26a28fe71dc079f84c70000000000000000000000000000000000000000000000000000000000000000000000000000000000
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
offline-js-build.html:9654
extraData: "0x22466c6578692069732061207468696e6722202d204166726900000000000000e0a2bd4258d2768837baa26a28fe71dc079f84c70000000000000000000000000000000000000000000000000000000000000000000000000000000000
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
eth_toolkit.py:261
key_bytes = bytes.fromhex(private_key)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
eth_toolkit.py:402
tx_bytes = bytes.fromhex(raw_transaction)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
eth_toolkit.py:546
addr_bytes = bytes.fromhex(address[2:])
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
eth_toolkit.py:691
addr_bytes = bytes.fromhex(account.address[2:])
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
ethereum-wallet-mcp/src/ethereum_wallet_mcp/tools/signing.py:220
return bytes.fromhex(msg_hex)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
eth-account
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha ad293a8d4efffull audit observations/trust-audit/mcp-server/nirholas__ethereum-wallet-toolkit.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09ad293a8d4effCAUTIONC73first audit
06

Questions

What is the Ethereum Wallet Toolkit MCP server?

Python toolkit for Ethereum wallets: CLI tools + Model Context Protocol (MCP) servers for wallet generation, BIP39/BIP44 HD wallets, Web3 Secret Storage V3 keystores, and EIP-712 typed data signing

What tools does Ethereum Wallet Toolkit expose?

62 in total: 59 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Ethereum Wallet Toolkit safe to connect to an agent?

With care. The audit graded it C (73/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Ethereum Wallet Toolkit need?

No credential environment variables were found in its source, so it appears to need none.

How does Ethereum Wallet Toolkit run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as x402-facilitator at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (ad293a8d4eff), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement