WalletConnect Phishing: How Session Hijacking Drains Wallets
WalletConnect phishing session hijacking is a sophisticated attack where criminals use fake WalletConnect sessions to silently drain wallets. Unlike classic signature phishing that steals individual approvals, session hijacking grants persistent access, allowing attackers to siphon assets repeatedly. This guide dissects the mechanics, real-world examples like Pink Drainer, and concrete defenses.
As WalletConnect becomes the bridge between thousands of decentralized applications and mobile wallets, attackers have crafted convincing fake dApps that request session links or QR codes. Victims unknowingly authorize a malicious session, and from that moment, the attacker can initiate transfers without repeated approvals. Understanding the difference between a legitimate session request and a hijack is critical for anyone holding significant crypto.
- WalletConnect phishing session hijacking grants attackers persistent access, not just one-time approvals.
- Attackers use fake dApps, QR code replay, and blind-signing to trick users into signing malicious payloads.
- Hardware wallets with blind-signing disabled and session revocation tools like Revoke.cash are the strongest defenses.
- Always verify dApp URLs by typing them manually; never use ads or search links for critical dApps.
- After connecting to any dApp, revoke the WalletConnect session immediately once done.
- Regularly audit your wallet’s approvals and active sessions using Etherscan or Revoke.cash.
What Is WalletConnect Phishing Session Hijacking?
WalletConnect phishing session hijacking occurs when a victim scans a QR code or clicks a deep link that establishes a WalletConnect session with a malicious dApp. The attacker then uses that session to request signatures (e.g., eth_signTypedData) that approve token transfers or delegate permissions. Once approved, the attacker can drain the wallet without further user interaction.
The key difference from traditional phishing is persistence: a single hijacked session can be reused for multiple transactions. Attackers often use drainer kits like Pink Drainer or Angel Drainer, which automatically sweep approvals and tokens. The session remains active until the user manually disconnects it or the bridge relays expire.
How Attackers Create Fake WalletConnect Sessions
Attackers typically deploy lookalike dApp interfaces—fake exchanges, NFT mints, or airdrop claim sites—that prompt users to connect via WalletConnect. The malicious dApp generates a session proposal with a legitimate-looking URI. When the user scans the QR code with their wallet (e.g., MetaMask Mobile, Trust Wallet), they unknowingly approve a session that grants the dApp the ability to request signatures.
Common tricks include:
- Creating URLs that mimic real dApps (e.g., unic0rnswap.com instead of uniswap.org).
- Using social media shills with time-limited offers to create urgency.
- Embedding fake WalletConnect QR codes in paid Google ads.
Once connected, the attacker sends transaction requests that appear harmless (e.g., “Approve ERC-20 spending”) but are actually unlimited approvals. Since the wallet shows only a gas fee prompt, victims often sign without verifying the payload.
Real-World Pattern: Fake Airdrop Drainer Campaigns
Fake airdrop drainer campaigns have repeatedly impersonated major token distributions, including Optimism's OP airdrop. Victims visit a site claiming to distribute tokens and are asked to connect via WalletConnect to "verify eligibility." After connecting, the fake dApp requests a signature—often a token approval, or a blind eth_sign message that can be used to construct a signed transaction—that the attacker uses to move ETH and tokens out of the victim’s wallet.
These campaigns have collectively drained large sums from victims, and an individual drain can complete within minutes of a malicious signature. Security researchers have repeatedly documented how even experienced users fall prey when blind-signing is enabled.
The Role of Signature Types: Blind Signing vs. Structured Data
WalletConnect session hijacking exploits the gap between user understanding and signature semantics. Wallets like MetaMask present two main signing methods:
- eth_sign: Dangerous blind signing of arbitrary hash. Rarely used legitimately.
- eth_signTypedData: Structured data that displays human-readable fields (e.g., permit, permit2).
Attackers rarely use eth_sign because modern wallets warn users. Instead, they craft malicious eth_signTypedData messages, such as a Permit2 approval that grants unlimited token spending. The wallet shows the contract address and spender, but many users approve without checking the spender is a known aggregator.
Hardware wallets like Ledger and Trezor can be configured to reject blind signatures, but structured data approvals often bypass warnings, making session hijacks particularly insidious.
Comparison: Traditional Signature Phishing vs. Session Hijacking
| Feature | Traditional Signature Phishing | WalletConnect Session Hijacking |
|---|---|---|
| Access model | One-time approval per transaction | Persistent session allows ongoing requests |
| User interaction | Requires signing each transaction | Single sign initializes many subsequent actions |
| Detection difficulty | Easier to spot (unexpected popup) | Harder (session stays active in background) |
| Common payload | Approve token spending for a specific contract | Approve unlimited spending or delegate ownership |
| Example tool | Fake Uniswap approval request | Fake WalletConnect QR code with Permit2 blind sign |
How Attackers Exploit QR Code Replay and Session Persistence
An advanced technique used in WalletConnect phishing session hijacking is QR code replay. Attackers capture a QR code from a legitimate dApp (e.g., an ongoing airdrop claim) and embed it in a phishing page. When the victim scans, they establish a session with the real dApp, but the attacker intercepts the session topic and encryption keys. With these, the attacker can inject malicious transaction requests into the same session.
Even if the dApp is legitimate, the attacker piggybacks on the user’s trust. This was seen in attacks on Snapshot.org proposals where malicious messages were injected into legitimate voting sessions. To defend against this, users should only scan QR codes from domains they independently verify and use one-time session connections.
Detecting a Compromised WalletConnect Session
Early detection of WalletConnect phishing session hijacking is crucial. Signs include:
- Unexpected “connect” requests from unfamiliar dApps in your wallet’s active sessions list.
- Repeated low-value transactions that seem to fail—attackers may test limits.
- In MetaMask Mobile, a session appears under “Connected dApps”. If you see a name you don’t recognize, revoke it immediately.
Tools like Revoke.cash allow you to view and disconnect all WalletConnect sessions. You can also use Ethereum transaction history to spot approvals to unknown contracts. Rabby Wallet shows session permissions in detail. If you notice an approval to a contract with no code or a mismatched symbol, it’s a red flag.
Essential Prevention: 7 Security Practices
Protecting against WalletConnect phishing session hijacking requires both technical and behavioral controls:
- 1. Always verify the dApp URL – Type it manually or use bookmarks. Never click ads for well-known dApps.
- 2. Use a hardware wallet – Ledger and Trezor can be set to require physical approval for each transaction, even within a session.
- 3. Disable blind signing – On hardware wallets, enable “Structured Data Only” or disable
eth_signentirely. - 4. Revoke sessions regularly – Use Revoke.cash or your wallet’s settings to disconnect all sessions after each interaction.
- 5. Check the signing payload – On MetaMask, expand the data field. Look for suspicious function selectors like
0x095ea7b3(approve) with unlimiteduint256values. - 6. Block known drainer domains – Use security browser extensions like Wallet Guard or Scam Sniffer.
- 7. Use a multisig or cold wallet – For high-value holdings, never connect a hot wallet to unknown dApps.
What to Do If You Suspect a Session Hijack
If you believe you’ve fallen victim to WalletConnect phishing session hijacking, act fast:
- Immediately disconnect all WalletConnect sessions via your wallet settings or Revoke.cash.
- Transfer remaining funds to a new wallet that has never connected to any dApp. Use a hardware wallet for the new address.
- Revoke all token approvals for the compromised address using Etherscan’s “Token Approvals” tool or Revoke.cash.
- Notify the community – Report the fake dApp domain to PhishFort or Chainabuse.
- Check if the attacker has set up a “potential” session with a relayer – Some drainers use relayers to bypass disconnect. If you see pending transactions, use a block explorer to cancel them via the same nonce.
Future-Proofing: WalletConnect v2 and Improved Security
WalletConnect v2 introduced session-scoped permissions and expiration, which can limit hijack damage. In v2, a session can specify allowed methods (e.g., eth_sendTransaction) and chains. Attackers can still request broad methods, but users can now see the permission scope before connecting.
Future improvements include mandatory human-readable signing payloads (EIP-712), wallet-level rate limiting, and session connection history. Leading wallets like Rainbow and Rabby already display the full permissions request. As the ecosystem matures, users must adopt a “trust but verify” mindset: always check dApp identity, permissions, and use session-specific wallets.
Common mistakes to avoid
- Scanning a QR code without verifying the domain matches the expected dApp.
- Blindly signing any prompt that appears after connecting to a WalletConnect session.
- Assuming that disconnecting the wallet from the dApp also revokes the session (it doesn’t—you must revoke the session itself).
- Using the same wallet for both high-value storage and frequent dApp interaction (hot wallet vs cold wallet).
- Ignoring the ‘Show Data’ option in MetaMask before signing a transaction or typed data message.
Frequently asked questions
Can WalletConnect session hijacking happen even if I don’t sign anything?
Not directly. A WalletConnect session by itself does not let a dApp move your funds—every transfer or approval still requires you to sign a request in your wallet. The danger is that connecting to a malicious dApp sets up the signature requests that follow: it will ask you to sign something that looks benign but isn’t. If you sign even a single malicious approval, your assets can be drained.
How do I revoke a WalletConnect session on mobile?
In MetaMask Mobile, go to Settings > Connected dApps and tap the disconnect button next to the suspicious session. Alternatively, use Revoke.cash on desktop by connecting your wallet and removing the session under ‘WalletConnect Sessions’.
Are hardware wallets completely safe against WalletConnect phishing?
No. While hardware wallets require physical confirmation, if you sign a malicious approval while blind-signing is enabled, the operator can drain tokens. Always disable blind signing and approve only structured data with known contract addresses.
What is a ‘drainer kit’ and how does it relate to session hijacking?
Drainer kits like Pink Drainer and Angel Drainer are pre-built scripts that automatically scan a victim’s wallet after a session is hijacked, calculating the most valuable assets to drain via approved spending limits or direct transfer signatures.
Related reading
Track the entities behind the concepts
DeFi Intel maps 11,000+ protocols, tokens and companies to a typed knowledge graph — with live data, incidents and regulation.