Umbra
app.umbra.cashEthereumUmbra is a stealth address protocol on the EVM. It allows users to send payments to a one-time address controlled by a recipient without their interaction, promoting unlinkability (if proper hygiene is followed) without resorting to mixers or pools.
- Homepage:app.umbra.cash
- GitHub:github.com/ScopeLift/umbra-protocol
- Web info:web-check.xyz/check/app.umbra.cash
Umbra Source Code
Author
Description
🌕🌑 Privacy Preserving Shielded Payments On The Ethereum Blockchain
Homepage
https://app.umbra.cashRepository
- LicenseMIT
- Created01 May 20
- Primary languageTypeScript
- Size15,739 KB
- Stars406
- Forks96
- Watchers406
Top Contributors
@mds1 (533)
@apbendi (243)
@garyghayrat (154)
@davidlaprade (71)
@alexkeating (70)
@wildmolasses (42)
@dependabot[bot] (33)
@radchukd (25)
@jferas (22)
@thelostone-mc (5)
@Soptq (5)
@vladbat00 (5)
@marcomariscal (3)
@amritkumarj (1)
@paulmillr (1)
@mozrt2 (1)
@omahs (1)
Recent Commits
Ben DiFrancesco(06 Oct 26)
Upgrade Vue to 3.5.43 Quasar is developed against Vue 3.5, and from 2.34.0 its layout components use APIs that need Vue 3.3 or later, so staying on 3.2.45 would hold Quasar at 2.33.x. vue-router 4.1.6, vue-i18n and the test tooling work unchanged. The newer compiler drops postcss 8.4.31 from the lockfile.
Ben DiFrancesco(06 Oct 26)
Replace the deprecated Sass darken() and lighten() calls Sass 1.80 deprecated the global color functions. app-webpack injects quasar.variables.sass into every stylesheet, so its four calls produced 32 warnings on each build. color.adjust() with $lightness is how darken() and lighten() are defined, and the production build is byte-for-byte identical.
Ben DiFrancesco(06 Oct 26)
Pin browser targets to Quasar's supported floor The "last N versions" queries resolve against the browser-version data in the lockfile. The data that came with app-webpack 3.6.2 was from December 2022 and resolved them to Chrome 99, Safari 15.1 and iOS 13.4. The data that comes with 3.15.1 moves the same queries to Chrome 142, Safari 26 and iOS 18.3, which would stop transpiling for several years of browsers. Quasar 2.28 raised its own minimums to Chrome/Edge 121, Firefox 123 and Safari/iOS 17.2 and doesn't support anything older, so use those as fixed minimums. Opera 107 is the release built on Chrome 121. The Android entries resolve to their latest versions, since the data only tracks those, but they share engines with the desktop entries.
Ben DiFrancesco(06 Oct 26)
Upgrade Quasar to 2.33.1 and @quasar/app-webpack to 3.15.1 Quasar 2.22.0 fixed prototype pollution in extend() (GHSA-3r53-75j5-3g7j). Umbra never calls extend(), and Quasar itself only uses it in the Meta plugin and QEditor, neither of which we use, so the advisory doesn't reach us. Staying on 2.10.2 would block every later fix, though. Quasar 2.16 removed files that app-webpack 3.6.2 loads, so the two have to move together. 3.15.1 is the last 3.x release. The new app-webpack needed three follow-on changes: - Its @quasar/babel-preset-app 2.0.4 depends on babel-loader 10, which yarn nests under the preset where webpack can't find it. Declare babel-loader directly, and raise @babel/core to the ^7.29.0 the preset requires so both use one copy. - The preset adds core-js imports for its own core-js 3.50, but the app resolved core-js 3.26.1, which lacks some of those modules. Refresh core-js to 3.50.0 within the existing range. - Quasar is now an ES module package with an exports map, which Jest 27 ignores, so quasar/wrappers resolved to its ESM file and two suites failed to load. Map quasar and quasar/wrappers to their CommonJS builds. The new toolchain also brings newer browser-version data, which moves the browserslist targets. The next commit pins them.
Ben DiFrancesco(06 Oct 26)
Remove the dead vue-i18n-loader config and unused yaml-loader quasar.conf.js defined chainWebpack twice in the build object, so the second definition replaced the first and its @intlify/vue-i18n-loader rules never ran. They had nothing to do anyway: the locales are JSON, which webpack loads natively, and no component has an <i18n> block. Delete the dead block and remove @intlify/vue-i18n-loader, which nothing else used, along with yaml-loader, which nothing referenced. The lockfile drops eight packages and no other version changes. With the loader's @intlify/shared 9.2.2 gone, vue-i18n's 9.14.5 is hoisted, so the bundle now ships one copy of it instead of two. Every other bundled module is unchanged.
Ben DiFrancesco(05 Oct 26)
Pin various dependencies to bump minor versions
Ben DiFrancesco(05 Oct 26)
Minor version bumps on a handful of packages
Ben DiFrancesco(01 Oct 26)
Bump to the last 5.x release of ethers.js in umbra-js
Ben DiFrancesco(30 Sept 26)
Build umbra-js in prepack instead of prepare
Ben DiFrancesco(24 Sept 26)
Remove the y18n resolution 65f351b forced every y18n range to ^4.0.1 to avoid a vulnerable version. Each range in the tree now resolves to a patched release on its own: ^3.2.1 to 3.2.2, ^4.0.0 to 4.0.3, and ^5.0.5 to 5.0.8. None of them have advisories. Removing the override also lets yargs 16 and 17 use the y18n 5 they declare instead of 4.
Ben DiFrancesco(24 Sept 26)
Mark the contract workspaces as private Neither @umbra/contracts-core nor @umbra/contracts-periphery is published to npm. Mark both as private so Yarn and npm refuse to publish them by accident.
Ben DiFrancesco(24 Sept 26)
Fix the umbra-js package name in the FAQ The FAQ's developer snippets installed and imported @umbra/umbra-js, which doesn't exist on npm. Use the published name, @umbracash/umbra-js, in both the English and Chinese locales.
Ben DiFrancesco(24 Sept 26)
Link internal dependencies with the workspace protocol Declare frontend's dependency on umbra-js and umbra-js's dev dependency on contracts-core with workspace:^. They previously linked to the local packages only because their version ranges matched the workspace versions, so bumping umbra-js meant also updating frontend's exact pin by hand. Otherwise Yarn would resolve umbra-js from npm instead. yarn npm publish and yarn pack replace workspace:^ with the actual version range.
Ben DiFrancesco(24 Sept 26)
Disable dependency install scripts Stop running the install scripts of dependencies, which is Yarn 4's default. None of them are needed: - Native modules load prebuilt binaries or fall back to their JavaScript implementations. The frontend bundle always uses the JavaScript versions, and in Node only hardhat's tests load keccak and secp256k1, with no measurable difference in test time. - esbuild and sharp find their binaries through their platform-specific optional packages. - The rest only print messages or have unwanted side effects. The postinstall of @stellar/stellar-sdk, for example, sets blame.ignoreRevsFile in the enclosing repository's git config, which breaks git blame because the file it names doesn't exist.
Ben DiFrancesco(24 Sept 26)
Require dependencies to be at least two weeks old Set npmMinimalAgeGate to 14d so Yarn only resolves package versions that have been published for at least two weeks. The gate applies when versions are resolved, not to entries already in the lockfile. Re-resolve node-gyp's undici dependency from 8.11.2, which the Yarn 4 lockfile conversion picked up the day it was published, to 8.10.2. The other lockfile entries newer than two weeks came from master and will age past the gate by Oct 2.
Ben DiFrancesco(24 Sept 26)
Migrate to Yarn 4 and replace Lerna with workspaces foreach Move the monorepo from Yarn 1.22.22 to Yarn 4.18.0 using the node-modules linker, which Netlify requires and which hardhat and the Quasar/webpack toolchain expect. Replace Lerna with Yarn's built-in workspaces foreach command. - Pin Yarn 4.18.0 in mise.toml and in the packageManager field of package.json, which Netlify uses in place of YARN_VERSION - Convert yarn.lock to the Yarn 4 format. Resolved versions are unchanged, apart from node-gyp, which Yarn 4 adds for packages with native builds - Resolve [email protected]'s GitHub dependency on ethereumjs-abi to the npm 0.6.8 release, which ships the same code, so installs no longer fetch from git - Keep Yarn 4's defaults that block git dependencies and versions published less than a day ago. Keep dependency install scripts enabled until we audit which ones the project needs - Bump contracts-core's typescript to ^4.0.3. Yarn 4 enforces @typechain/ethers-v5's requirement of TypeScript 4.3+, where Yarn 1 let it use the root's hoisted copy - Run the root scripts with yarn workspaces foreach, in dependency order including dev dependencies, and remove lerna.json and the lerna dependency - Switch CI to yarn install --immutable and drop the Yarn 1-only flags and the yarn list step - Update .gitignore and the README for Yarn 4
Ben DiFrancesco(24 Sept 26)
Prepare workspace scripts for the Yarn 4 migration Yarn 4 doesn't run the root prepare script on install, and a workspace's scripts can only run binaries from that workspace's own dependencies. Fix the places that relied on Yarn 1 behavior so the migration can land without breaking builds, lint, or Netlify. - Stop building on install: remove the root prepare script and have umbra-js's build generate contracts-core's typechain itself, so build-frontend (Netlify) works without the contracts packages - Add a root build-umbra-js script and run it before lint in CI and before dev:netlify, since the type-aware ESLint rules and the frontend need its output - Declare eslint, prettier, and rimraf in frontend and umbra-js, whose scripts call them but only the root declared them. The ranges match the root's, so the lockfile is unchanged - Drop frontend's unused postinstall-postinstall dependency - Update the README setup and linting instructions
Ben DiFrancesco(23 Sept 26)
Remove CNS name support from the frontend and umbra-js Stop resolving Unstoppable Domains (CNS) names, both name to address and address to name. ENS resolution is unchanged. - Drop CNS resolution from utils.toAddress, so lookupRecipient and the send, withdraw, and payment link flows accept only ENS names and addresses - Drop CNS reverse lookups for the wallet display name, receive table senders, and the withdrawal privacy check - Remove CNS from the tutorial, FAQ, and README copy, and delete the CNS withdrawal warning string - Remove the @unstoppabledomains/resolution dependency from both packages, along with the CNS tests and now-unused helpers This changes the behavior of the public utils.toAddress and utils.lookupRecipient methods, and ships in umbra-js 0.3.0.
Ben DiFrancesco(23 Sept 26)
Bump umbra-js to 0.3.0 The previous commit removes public exports, so bump the minor version while the package is pre-1.0. Update the frontend's exact pin to match so it keeps resolving to the workspace package.
Ben DiFrancesco(23 Sept 26)
Remove legacy ENS/CNS stealth key lookups from umbra-js Stealth keys have been read from the StealthKeyRegistry since 2021, and the frontend no longer checks for keys stored on ENS resolvers or CNS records. Remove the SDK's remaining support for that lookup path. - Remove the ens and cns modules and utils.getPublicKeysLegacy - Remove the resolver ABI constants and unused ABI JSON files - Delete the legacy ENS and CNS tests, moving the CNS registry lookup test into utils.test.ts This is a breaking change: the ens and cns exports and utils.getPublicKeysLegacy are no longer part of the public API. Resolving ENS and CNS names to addresses is unchanged.
Ben DiFrancesco(23 Sept 26)
Remove legacy name resolution + warning from frontend
Ben DiFrancesco(22 Sept 26)
Add mounted regression test for account address copying Configure Jest for Vue components and mount WalletRow with mocked stores and copyAddress, stubbing unrelated child components. Click the rendered copy control and verify the full address and provider reach the helper. This exercises template bindings without a wallet or real clipboard. Verified the test catches both the missing handler and omitted provider.
Ben DiFrancesco(22 Sept 26)
Fix copy address in account dropdown The dropdown called a helper that was no longer exposed to the template. Import and expose the shared copyAddress helper and pass the wallet provider it requires.
Ben DiFrancesco(17 Sept 26)
Remove unneeded Yarn nohoist exclusions for Mocha and Jest
Ben DiFrancesco(16 Sept 26)
Replace Git hooks with explicit lint and formatting workflows - Remove Husky, lint-staged, and unused commit-message tooling - Add yarn lint:fix to fix, format, and check all workspaces - Include frontend and SDK Prettier checks in CI's lint command - Exclude generated files from Prettier and fix remaining formatting - Document lint commands and require checks before submitting changes - Prune unused dependencies from the lockfile
Ben DiFrancesco(15 Sept 26)
Migrate from volta to mise for dev tooling configuration
Ben DiFrancesco(14 Sept 26)
Freeze the lockfile for all CI jobs
Ben DiFrancesco(14 Sept 26)
Improve local development with ponder/netlify
Ben DiFrancesco(11 Sept 26)
Update Node to version 24.21.0
Ben DiFrancesco(11 Sept 26)
chore: upgrade Yarn to 1.22.22
Umbra Website
Website
Umbra
Send and receive stealth payments with the Umbra protocol
Redirects
Does not redirect
Security Checks
1 security checks failed (64 passed)
- Top-Level Domain Highly Abused
Server Details
- IP Address18.208.88.157
- Hostnameec2-18-208-88-157.compute-1.amazonaws.com
- LocationAshburn,Virginia,United States of America,NA
- ISPAmazon Technologies Inc.
- ASNAS14618
Associated Countries
US
Safety Score
Website marked as risky
70%
Blacklist Check
app.umbra.cash was found on 0 blacklists
- AntiSocial Blacklist
- Artists Against 419
- Badbitcoin
- Bambenek Consulting
- CERT Polska
- CoinBlockerLists
- CRDF
- CryptoScamDB
- EtherAddressLookup
- EtherScamDB
- Fake Website Buster
- MetaMask EthPhishing
- NABP Not Recommended Sites
- OpenPhish
- PetScams
- PhishFeed
- PhishFort
- Phishing.Database
- PhishStats
- PhishTank
- Phishunt
- RPiList Not Serious
- Scam.Directory
- SecureReload Phishing List
- Spam404
- StopGunScams
- Suspicious Hosting IP
- ThreatFox
- ThreatLog
- TweetFeed
- URLhaus
- ViriBack C2 Tracker
Website Preview
Umbra Reviews
More Crypto Tools
⚠️ This section is still a work in progress ⚠️
Check back soon, or help us complete it by submiting a pull request on GitHub.
Or submit an entry here
About the Data: Umbra
Change History
- Added #832
Edit Umbra Data
You can edit Umbra's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external
sources, a list of these can be found data documentation.
Origin Data
Modify Data
API
You can access Umbra's data programmatically via our API. Simply make a GET request to:
https://api.awesome-privacy.xyz/v1/services/umbraThe REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.
Share Umbra
Help your friends compare Crypto Tools, and pick privacy-respecting software and services.
Share Umbra and Awesome Privacy with your network!