Wallet Security Ranking Methodology background image
Home - Coinspect Security

We created a standard security checklist to provide transparent, objective insights into the most secure crypto wallets.

We test, you decide.

dapp permissions

dApp Permissions

We examine if the wallet always asks you before dApps access your balance or suggest transaction, and provides permissions control features such as token approvals management.

We test if the wallet

  • rp-key
    Requires users to unlock it before processing dApp requests when in a locked state.
  • rp-user-check
    Requires user connection approval before granting dApp access to specific RPC methods.
  • rp-user-check
    Requires user confirmation before processing requests for specific RPC methods from dApps loaded by the embedded browser.
  • rp-user-check
    Requires user confirmation before accepting requests to switch the active chain.
  • rp-shield
    Allows users to list and revoke connected dApps.
  • rp-shield
    Restricts the use of deprecated or insecure RPC methods by default.
  • rp-alert
    Alerts users or rejects requests to sign typed structured data (EIP-712) with a chain ID different from the active chain.
  • rp-shield
    Allows users to view and revoke token approvals.
  • rp-alert
    Alerts users of discrepancies or unusual patterns in Sign-in with Ethereum (EIP-4361) requests.
intent verification

Intent Verification

We assess each wallet’s ability to provide clear, human-readable transaction summaries so you know what will happen with your assets before approving.

We test if the wallet

  • rp-connect
    Consistently provides clickable links to reputable explorers for all key blockchain identifiers.
  • rp-eye
    Allows users to preview the exact outcome of the requested signature by simulating the transaction in advance.
  • rp-eye
    Clearly displays all the key details for ERC-20 Approve requests.
  • rp-eye
    Clearly displays human-readable details for typed structured data (EIP-712) signature requests from well-known dApps.
  • rp-eye
    Clearly displays all signature request details without truncating or hiding information.
  • rp-scroll
    Requires users to scroll through all signature request details before being allowed to proceed with signing.
  • rp-alert
    Warns users when they input addresses with invalid EIP-55 checksums.
physical access

Physical Access

We evaluate the wallet’s implementation of device-level security features. This includes biometric authentication (fingerprint, face ID), strong password requirements, and attempts limitations.

We test if the wallet

  • rp-lock
    Automatically locks after a period of inactivity.
  • rp-lock
    Allows users to lock it manually.
  • rp-alert
    Minimizes exposure of secrets by limiting or warning users when copying seed phrases to the clipboard or taking screenshots.
  • rp-key
    Employs the strongest available authentication mechanisms, including biometrics, login attempt rate-limiting, and enforcement of strong passwords.
  • rp-key
    Requires authentication to access seed phrases or private keys.
  • rp-alert
    Warns users of the risk before allowing access to seed phrases or private keys.
threat prevention

Threat Prevention

We check that the wallet is integrated with up-to-date lists of known threats and conducts real-time checks of blockchain addresses and web domains before any transactions or connections.

We test if the wallet

  • rp-eye
    Clearly displays the dApp URL in the connection prompt.
  • rp-alert
    Prevents or alerts users about interactions with known malicious blockchain addresses.
  • rp-eye
    Informs users when interacting with a well-known dApp URL.
  • rp-alert
    Alerts users when attempting to interact with a known malicious URL.
  • rp-eye
    Informs users during the connection prompt that connecting grants dApps access to view balances, transaction history, and to request signatures.
  • rp-shield
    Hides malicious tokens and NFTs by default.
  • rp-alert
    Warns users when interacting with unknown addresses.

FAQ

ranking cta card

Do you want to score 100?

Find out the weaknesses we identified that are holding your wallet back—contact us for the full report.


This ranking is for informational purposes only. It should not be relied on to provide legal, tax, financial, investment, or other types of advice. Coinspect does not guarantee or warrant the accuracy, completeness, timeliness, suitability, or validity of the information provided and will not be responsible for any claim attributable to reliance on errors, omissions, or other inaccuracies of any part of such information.