Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 1349

WalletConnect Security

¿Qué es WalletConnect Security?

WalletConnect SecurityThe security properties and known weak points of the WalletConnect open protocol, which lets dApps pair with mobile and hardware wallets over a relay network using QR codes or deep links to exchange signed messages.


WalletConnect is the dominant open protocol (v2 is the current generation, by Reown) for pairing decentralized applications with mobile and hardware wallets. The dApp displays a QR code or deep link encoding a pairing URI; the wallet scans or opens it, derives a shared session key, and from then on the two parties exchange JSON-RPC messages over a public relay network. The wallet remains in custody of all keys; the dApp can only request signatures, which the wallet displays for explicit user approval. Security properties depend on three things working: end-to-end encryption between dApp and wallet through the relay (so the relay sees only opaque payloads), strict scoping of the session's methods and chains (a session approved for `eth_sendTransaction` shouldn't be able to sneak in `personal_sign`), and the wallet's UI clearly rendering what is being signed. Known weak points include fake pairing pages that capture the QR-code URI and replay it against the user's wallet, session-hijack research, and phishing dApps that exploit weak signing-display in older wallets. Defenses: always pair from inside the wallet (not by typing a URI), verify the dApp's displayed domain, and prefer wallets with strong EIP-712 display.

Ejemplos

  1. 01

    A user pairs MetaMask with a Uniswap dApp via WalletConnect; subsequent EIP-712 signature requests display the dApp domain and the typed-data structure before the user approves.

  2. 02

    A security researcher publishes a proof-of-concept where a phishing site replays a captured WalletConnect URI against the user's wallet, recommending wallets warn on QR codes scanned from non-pairing pages.

Preguntas frecuentes

¿Qué es WalletConnect Security?

The security properties and known weak points of the WalletConnect open protocol, which lets dApps pair with mobile and hardware wallets over a relay network using QR codes or deep links to exchange signed messages. Pertenece a la categoría de Web3 y blockchain en ciberseguridad.

¿Qué significa WalletConnect Security?

The security properties and known weak points of the WalletConnect open protocol, which lets dApps pair with mobile and hardware wallets over a relay network using QR codes or deep links to exchange signed messages.

¿Cómo funciona WalletConnect Security?

WalletConnect is the dominant open protocol (v2 is the current generation, by Reown) for pairing decentralized applications with mobile and hardware wallets. The dApp displays a QR code or deep link encoding a pairing URI; the wallet scans or opens it, derives a shared session key, and from then on the two parties exchange JSON-RPC messages over a public relay network. The wallet remains in custody of all keys; the dApp can only request signatures, which the wallet displays for explicit user approval. Security properties depend on three things working: end-to-end encryption between dApp and wallet through the relay (so the relay sees only opaque payloads), strict scoping of the session's methods and chains (a session approved for `eth_sendTransaction` shouldn't be able to sneak in `personal_sign`), and the wallet's UI clearly rendering what is being signed. Known weak points include fake pairing pages that capture the QR-code URI and replay it against the user's wallet, session-hijack research, and phishing dApps that exploit weak signing-display in older wallets. Defenses: always pair from inside the wallet (not by typing a URI), verify the dApp's displayed domain, and prefer wallets with strong EIP-712 display.

¿Cómo defenderse de WalletConnect Security?

Las defensas contra WalletConnect Security combinan habitualmente controles técnicos y prácticas operativas, como se detalla en la definición.

¿Cuáles son otros nombres para WalletConnect Security?

Nombres alternativos comunes: WalletConnect v2, Reown protocol.

Términos relacionados