Walletbeat intake form for wallet teams

Thank you for taking the time to fill this out. Your answers help us rate your wallet accurately on walletbeat.eth.

Note: If your answer differs between Browser Extension, Mobile, and Desktop versions of your wallet, please note which platform the answer applies to wherever relevant.


General

  • Wallet name:
  • Website:
  • Supported platforms: (check all that apply)
    • Browser Extension
    • Mobile
    • Desktop
  • Is your wallet designed for general use, or peer-to-peer payments, or some other specific use-case?
  • Which account types does your wallet support? (check all that apply)
    • EOA (externally owned account — standard seed phrase wallet)
    • MPC (multiparty computation — key is split across multiple parties)
    • EIP-7702 (delegating an EOA to act as a smart contract)
    • ERC-4337 smart account
    • Safe multisig
    • Other (please describe):
  • What is the default account type when a new user creates a wallet?

Security

Account Recovery

  • If a user loses their device or seed phrase, can they recover their account? (yes / no)

  • What recovery method(s) do you support?

    • Guardian-based / social recovery
    • Cloud backup (iCloud, Google Drive, etc.)
    • Multifactor / passkey backup
    • Not supported
    • Other:
  • [If guardian-based] Please describe your guardian scheme and link to its documentation.

Chain Verification

  • Do you use a light client to independently verify Ethereum L1 state (without trusting a centralized RPC)? (yes / no)
  • If yes, which implementation? (e.g. Helios)

Passkeys

  • Do you support passkeys (FIDO2/WebAuthn) as an authentication or signing method? (yes / no)
  • If yes, which library do you use for onchain P-256 verification?
    • Smooth Crypto Lib
    • Daimo P256 Verifier
    • OpenZeppelin P256 Verifier
    • WebAuthn.sol
    • Other:

Security Audits

  • Have you had independent security audits? (yes / no)
  • If yes, please provide links to all public audit reports:

Bug Bounty

  • Do you have a bug bounty program? (yes / no)
  • If yes, please provide a link:

Scam Protection

Malicious website warnings:

  • Do you warn users before connecting to potentially malicious websites or apps? (yes / no)
    • If so, which database or external service is used?
    • Does this check send the visited URL to an external service? (yes / no)
    • Does it send the user’s wallet address to an external service? (yes / no)
    • Can the external service learn the user’s IP address? (yes / no)

First-time contract warnings:

  • Do you warn users before interacting with a contract they haven’t used before? (yes / no)
    • Is a database of known-bad contracts or external service involved? If so, which one?
    • Does this check send the contract address to an external service? (yes / no)
    • Can the external service learn the user’s wallet address or IP address? (yes / no)

First-time recipient warnings:

  • Do you warn users when sending funds to an address they’ve never sent to before? (yes / no)
    • Does this check send the recipient address to an external service? (yes / no)

Hardware Wallet Support

  • Can users connect a hardware wallet to sign transactions? (yes / no)
  • Which hardware wallets are supported? Please list ALL supported.

Duress Resistance

  • Which authentication mechanism(s) does your mobile wallet support before granting access? (check all that apply)

    • PIN code
    • Password / passphrase
    • Biometric (Face ID, fingerprint)
    • Swipe pattern
    • None (no lock screen)
  • Does your wallet support a dedicated duress mode (a separate duress PIN or passphrase that, when entered, triggers a protective action)? (yes / no)

    • If yes, what action(s) does it trigger? (check all that apply)
      • Decoy wallet — opens a separate wallet with different accounts and balances
      • Self-destruct — wipes the wallet, preventing access to funds
      • Onchain lockdown — freezes the smart contract to prevent unauthorized transfers
      • Wipe and forward — wipes the wallet and forwards all funds to a preconfigured safe address

Privacy

Privacy Policy

  • URL to your privacy policy:

Multiple Addresses

  • Does your wallet support multiple Ethereum addresses? (yes / no)

Private / Anonymous Transfers

  • Do you support private or anonymous token transfers? (yes / no)
  • Which privacy technology? (check all that apply)
    • Stealth addresses (ERC-5564)
    • Privacy Pools
    • Railgun
    • Tornado Cash Nova
    • Other:

Self-Sovereignty

Account Portability

  • [If EOA] Key derivation:

    • Do you use BIP32 hierarchical deterministic key derivation? (yes / no)
    • Do you use BIP39 seed phrases? (yes / no)
    • Do you use BIP44 derivation paths? (yes / no)
    • Can users configure a custom derivation path? (yes / no)
  • [If EOA] Export:

    • Can users export their seed phrase? (yes / no)
    • Can users export individual private keys? (yes / no)
  • [If MPC or ERC-4337] Can users generate and broadcast transactions using open-source tools, without relying on your wallet application? (yes / no — if yes, please describe)

  • [If ERC-4337] Smart account implementation:

    • Which smart contract or implementation do you use?
    • Has it been audited? If yes, link to the report:

Key Security

  • Where are private keys (or key shares) generated and stored?

    • Generated and stored on the user’s device only
    • Generated on your servers
    • Generated jointly (MPC/threshold) between user device and your servers
    • Other:
  • Can your servers reconstruct or access the user’s private key at any point? (yes / no / only with user consent — please explain)

  • [If MPC] Can users sign transactions without your servers being available? (yes / no)

Transaction Submission

  • Can users broadcast Ethereum L1 transactions without routing through your infrastructure?

    • Yes, via direct P2P gossip (acting as a node on the network)
    • Yes, via a user-configured self-hosted RPC node (connecting to a node and relaying the transaction)
    • No, all transactions go through your servers
  • For Arbitrum: do you support force-inclusion (bypassing the Arbitrum sequencer to submit via L1)? (yes / no / not supported)

  • For OP Stack chains (Optimism, Base, etc.): do you support force-inclusion? (yes / no / not supported)

RPC & Chain Configuration

  • Can users configure a custom Ethereum L1 RPC endpoint? (yes / no)
    • If yes, is this possible before the wallet makes any network requests on first launch? (yes / no)
  • Can users configure custom RPC endpoints for L2 networks? (yes / no)
  • Can users add entirely custom or non-default chains? (yes / no)
  • If a user points the wallet at a self-hosted node, can they do all the following without requests going to your servers?
    • Create new accounts (yes / no)
    • Check balances (yes / no)
    • Send transactions (yes / no)

Transparency

Fee Display

  • Before a user confirms a transaction, do you show the complete fee breakdown — including any convenience fees or routing markups charged by your wallet? (yes / no)
  • Are there any fees your wallet takes that are not explicitly displayed to the user before they confirm? (yes / no — if yes, please describe)

Open Source

  • Is the wallet’s source code publicly available? (yes / no)
  • If yes, under what license?
  • If yes, please share the repository URL and any other relevant links:

Funding & Monetization

  • Is information about how your wallet is funded or monetized publicly available? (yes / no)
  • If yes, please share a link:

Anything Else you want to specifically mention?

Is there anything about your wallet’s security, privacy, or self-sovereignty features that you’d like us to know, or that the questions above didn’t cover?