نسخهٔ فارسی

Transparent, non-custodial, yours

What you agree to when you scan that QR code

Scanning a QR code opens an encrypted session between a site and your wallet. It can request signatures. It cannot sign, and cannot move funds.

What it is An encrypted request channel between a site and your wallet
It can Propose transactions and signature requests
It cannot Sign anything, read your key, or move funds

FBT Swap

What you should know

WalletConnect is a messaging channel, not a permission grant. It lets a website propose transactions to a wallet on another device, and lets the wallet send back signatures it produced itself.

The distinction matters because people treat connecting as the dangerous step. It is not — the dangerous step is always what you approve afterwards.

How the session works

The site generates a pairing URI, your wallet reads it, and the two establish an end-to-end encrypted session through relay servers that cannot read the contents. The site learns the address and chain you approved for the session.

From then on the site can send requests: switch chain, sign a message, send a transaction. Each one surfaces in your wallet as a prompt you must explicitly accept.

What a connection reveals

Your public address and therefore your on-chain history and balances, which are public anyway. A site can read everything your address has ever done, because so can anybody with a block explorer.

It does not reveal your private key, your recovery phrase or any other account in the same wallet that you did not approve.

Where the real risk is

In the approval prompts. A malicious site connected over WalletConnect is exactly as dangerous as a malicious site in a browser extension wallet: it can request an unlimited allowance or a transfer, and it depends entirely on you reading the prompt.

Signature requests deserve the same care as transactions. An off-chain signature can authorise a token transfer under permit-style standards without any on-chain approval step.

Session hygiene

Disconnect sessions you are not using, from the wallet side. A long-lived session to a site you no longer visit costs nothing but adds a channel that can propose requests at any time.

FBT Swap uses WalletConnect for external wallets and shows the chain and the proposed transaction before anything reaches your wallet. The signature always happens in your wallet, never here.

At a glance

At a glance

What it is

An encrypted request channel between a site and your wallet

It can

Propose transactions and signature requests

It cannot

Sign anything, read your key, or move funds

Real risk

Approving a harmful request — including off-chain signatures

FAQ

Frequently asked questions

Clear answers before you decide.

Can a connected site drain my wallet?

Only if you approve a request that lets it. A connection alone grants no spending power; an unlimited token approval or a permit signature does, which is why the prompt is the thing to read.

Is the relay able to see my transactions?

The session payload is end-to-end encrypted between the site and the wallet, so the relay forwards ciphertext. Metadata such as timing and session existence is inherently visible to it.

Should I disconnect after every use?

It is good hygiene and costs nothing. At minimum, review active sessions periodically and remove ones belonging to sites you no longer use.

Risk notice

Crypto assets are volatile and on-chain transactions cannot be reversed. You can lose money, including all of it. Nothing here is financial advice.