Skip to content

Latest commit

 

History

History
28 lines (18 loc) · 2.49 KB

File metadata and controls

28 lines (18 loc) · 2.49 KB
title Security Information

Security is not just a feature but a fundamental aspect of WalletConnect's architecture. The infrastructure has undergone multiple rounds of third-party security reviews, audits, penetration testing, and threat modeling to ensure the highest standards of protection. Security is viewed as a continuously evolving discipline, with regular system audits to identify and address potential vulnerabilities. The entire WalletConnect system underwent Threat Modeling by Spearbit in 2024, and then an entire ecosystem audit in 2026 to reach SOC2 Type II Certification.

SOC2 Type II Certification

WalletConnect underwent SOC2 Type II certification in 2026, demonstrating robust security controls and the ability to secure user data from unauthorized access - using it solely for its intended purpose and with confidentiality, as well as providing consistent availability on all systems and processing data appropriately and within time limits. As a Type II certification, WalletConnect displayed its security and data controls work over a period of time rather than simply on the spot.

SDK for Wallets

WalletConnect's SDK for wallets is an open-source SDK, supporting multiple transport methods, from WebSockets to Universal Links. Its design philosophy prioritizes minimizing third-party dependencies to reduce the attack surface area. To ensure its reliability and security, the SDK for wallets was audited by Trail of Bits. The audit report is available here. This comprehensive security review covered the source code and included a lightweight Threat Model covering upstream and downstream dependencies.

Third-Party Reviews

The security infrastructure of Reown has undergone multiple rounds of audits by independent security auditing firms, including Trail of Bits, Halborn, and Spearbit. These audits cover both AppKit and WalletKit, along with a comprehensive company-wide Threat Model.

Audit Scope Auditor Report
WalletConnect SOC2 Type II Certification AICPA
WalletConnect Comprehensive Threat Model Spearbit View Report
SDK for Apps Embedded Wallet Integration Pentest Halborn View Report
SDK for wallets Security Review & Lightweight Threat Model Trail of Bits View Report

Security disclosures

WalletConnect maintains an active bug bounty program to encourage security researchers to responsibly disclose vulnerabilities and help strengthen the systems. To report a vulnerability, please fill out the disclosure form here.