dApp Permissions
- User confirmation before processing requests8.7 / 8.7Description
Requires user confirmation before processing requests from dApps for specific RPC methods.
-
Although the bypass indicates the watch asset endpoint was successful, the asset does not appear in the token list.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- User consent for dApp access0.0 / 7.7Description
Requires user approval before granting dApp access to specific RPC methods.
-
The wallet skips user connection on `eth_signTypedData` and `personal_sign` endpoints.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- Wallet unlock before requests5.6 / 5.6Description
Requires users to unlock it before processing dApp requests when in a locked state.
-
Although the bypass indicates the watch asset endpoint was successful, the asset does not appear in the token list.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- Mismatching EIP-712 chainId detection0.0 / 3.5Description
Alerts users or rejects signing EIP-712 messages with a mismatched chain ID.
-
The wallet blocks transactions to invalid checksum addresses on all networks except Ethereum, where it still allows them.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- eth_sign method disabled3.3 / 3.3Description
Restricts the use of the deprecated and insecure eth_sign method by default.
-
The wallet does not process the request, meaning the `eth_sign` method is disabled by default. Users can enable it in the settings, and the wallet provides a clear explanation of why this is not recommended.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- Mismatching SIWE domain detection0.0 / 1.8Description
Warns users when the domain in a Sign-In with Ethereum (EIP-4361) message does not match the requesting dApp's origin.
-
The wallet does not warn users of a domain or scheme mismatch when signing SIWE message.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- Connected dApp management1.5 / 1.5Description
Allows users to list and revoke connected dApps.
-
The wallet provides a list of connected dApps and offers users the option to revoke access to all of them or revoke them individually. This function works properly, effectively disconnecting from the selected dApp.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- Token approval management1.5 / 1.5Description
Allows users to view and revoke token approvals.
-
The wallet relies on a third-party service and provides a link to revoke.cash within its settings menu to remove token approvals.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- User confirmation before switching chains0.0 / 1.1Description
Requires user confirmation before switching the active chain.
-
The wallet switches chains without requiring user confirmation.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Nov 14, 2025Report an issue with this check -
Intent Verification
- Transaction simulation6.7 / 6.7Description
Previews the expected outcome by simulating the request execution on the blockchain before signing.
-
The wallet does not display incoming or outgoing assets when adding liquidity to a Uniswap pool but does show incomes and outcomes during a swap in Sushiswap.
— Verified by Alejo Sequeira at Coinspect
Evidence · 3 screenshots

Last updated on Oct 21, 2025Report an issue with this check -
- Clear token approval dialog0.0 / 6.7Description
Clearly displays all the key details for ERC-20 Approve requests.
-
The wallet successfully displays critical approval details, including the function call, spender’s contract address, approved amount, and granting account, but the information is not presented in a clear way.
— Verified by Alejo Sequeira at Coinspect
Evidence · 2 screenshots
Last updated on Oct 21, 2025Report an issue with this check -
- Clear message signing dialog3.8 / 3.8Description
Clearly displays all message signature request details without truncating or hiding information.
-
The wallet displays large messages in personal sign requests without truncation and shows the verifying contract in the EIP-712 object.
— Verified by Alejo Sequeira at Coinspect
Evidence · 3 screenshots

Last updated on Oct 21, 2025Report an issue with this check -
- EIP-712 message parsing0.0 / 2.4Description
Displays human-readable details for EIP-712 signature requests from well-known protocols.
-
The wallet displays EIP-712 objects as plain data without parsing them.
— Verified by Alejo Sequeira at Coinspect
Evidence · 2 screenshots
Last updated on Oct 21, 2025Report an issue with this check -
- Invalid address checksum detection2.2 / 2.2Description
Warns users when they input addresses with invalid EIP-55 checksums.
-
The wallet does not allow sending transactions to addresses with invalid checksums, whether entered manually or provided by the dApp.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- Mandatory message review0.0 / 2.1Description
Requires users to review all the details before signing a message.
-
The sign button is available from the start.
— Verified by Alejo Sequeira at Coinspect
Evidence · 2 screenshots
Last updated on Oct 21, 2025Report an issue with this check -
- Links to blockchain explorers1.2 / 1.2Description
Consistently provides clickable links to block explorers for all key blockchain identifiers.
-
The wallet provides clickable links in both historical transactions and transaction previews.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
Physical Access
- Seed phrase access control5.4 / 5.4Description
Requires authentication to access seed phrases or private keys.
-
The wallet requires the user to enter their password before revealing the recovery phrase or private key.
— Verified by Alejo Sequeira at Coinspect
Evidence · 2 screenshots
Last updated on Oct 21, 2025Report an issue with this check -
- Manual wallet lock3.9 / 3.9Description
Allows users to lock it manually.
-
The wallet provides a manual lock button in the settings menu.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- Automatic wallet lock3.4 / 3.4Description
Verifies wallet auto-locks on inactivity.
-
The wallet offers an auto-lock feature, but it is disabled by default.
— Verified by Alejo Sequeira at Coinspect
Evidence · 2 screenshots
Last updated on Oct 21, 2025Report an issue with this check -
- Robust Authentication3.3 / 3.3Description
Uses strong authentication, such as resistance to trivial or commonly-used passwords. Including biometrics and rate limiting in mobile.
-
The wallet enforces an eight-digit password and does not permit easily guessable ones like “12345678.”
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- Clipboard seed phrase leak prevention0.0 / 1.8Description
Limits exposure of secrets by restricting or warning on copying seed phrases or taking screenshots.
-
The wallet allows copying mnemonics or private keys to the clipboard without providing a proper warning about the risks and does not limit the time these secrets remain in the clipboard.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- Seed phrase access warning1.8 / 1.8Description
Warns users of the risk before allowing access to seed phrases or private keys.
-
The wallet displays a clear warning about the risks of sharing mnemonics and private keys before revealing them. It also requires the user to tick a box confirming they won't share them with anyone.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
Threat Prevention
- Phishing dApp detection5.1 / 5.1Description
Prevents or alerts users about interactions with a known malicious URL.
-
The wallet includes a helpful feature that prevents users from connecting to dApps flagged as malicious.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- Malicious address detection5.1 / 5.1Description
Prevents or alerts users about interactions with a known malicious address.
-
The wallet warns users when attempting to send funds to known phishing addresses, such as the Tornado Cash Attacker address when using the dApp only when using Wallet Connect method, but when trying to send transaction using the native methods, it fails to prompt any warnings.
— Verified by Alejo Sequeira at Coinspect
Evidence · 3 screenshots

Last updated on Oct 21, 2025Report an issue with this check -
- Trusted dApp detection3.3 / 3.3Description
Informs users when interacting with a trusted dApp URL.
-
If the connected dApp is verified, the wallet displays a black shield with a checkmark to indicate that the site can be trusted. When attempting to connect to a dApp for the first time that hasn't been verified, a shield with a question mark is shown, warning the user that the site could not be verified. However, if the user has previously interacted with the dApp, the wallet displays a message reassuring them that it's safe to connect.
— Verified by Alejo Sequeira at Coinspect
Evidence · 2 screenshots
Last updated on Oct 21, 2025Report an issue with this check -
- Unknown address detection0.0 / 2.8Description
Warns users when interacting with an unknown address.
-
The wallet does not warn the user when trying to send funds to an unknown address.
— Verified by Alejo Sequeira at Coinspect
Evidence · 3 screenshots

Last updated on Nov 17, 2025Report an issue with this check -
- Full dApp URL display1.5 / 1.5Description
Clearly displays the full dApp URL in the connection prompt.
-
The wallet does not truncate the URL of the dApp the user is attempting to connect to.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- Malicious or spam token filtering1.3 / 1.3Description
Hides malicious tokens and NFTs by default.
-
The wallet effectively filters out spam and scam NFTs.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
- dApp access disclosure dialog1.0 / 1.0Description
Informs dApp access to balances, history, and signing requests on connection.
-
The wallet informs users, within the connection dialog, that by connecting they are allowing the dApp to view their wallet balance and activity, as well as to request transaction approvals.
— Verified by Alejo Sequeira at Coinspect
Evidence · 1 screenshot
Last updated on Oct 21, 2025Report an issue with this check -
This ranking is for informational purposes only. It should not be relied on to provide legal, tax, financial, investment, or other types of advice. Coinspect does not guarantee or warrant the accuracy, completeness, timeliness, suitability, or validity of the information provided and will not be responsible for any claim attributable to reliance on errors, omissions, or other inaccuracies of any part of such information.