WalletConnect is an open protocol that connects your mobile or browser wallet to a decentralized application. When you scan a QR code or approve a connection request, your wallet and the dapp open a secure channel so the app can ask you to sign transactions. WalletConnect itself never holds your keys and never moves funds on its own.
Where the risk actually is
The protocol is safe. The danger is what you connect to. A phishing site can display a genuine WalletConnect prompt, because the prompt is the same everywhere. If the site behind it is fake, the very first signature it asks for may be a token approval or a Permit that drains your wallet. WalletConnect faithfully relays whatever the site requests, including malicious requests.
How to use WalletConnect safely
- Verify the site first. Confirm the domain is the real one before you scan any QR code or approve any session.
- Read every signature. A connection request only shares your address. A signature request can move assets. Treat them differently.
- Watch for approvals. If the first thing a new site asks for is setApprovalForAll or an unlimited token approval, stop.
- Disconnect old sessions. Review active WalletConnect sessions in your wallet and remove ones you no longer use.
The bottom line
WalletConnect is a bridge, not a bodyguard. It will connect you to whatever site you point it at — safe or not. A browser security layer that checks the domain and explains each signature before you approve it is what turns a blind connection into a safe one.