uniswaρ.com uses a Greek rho (ρ) instead of a ‘p’. In one attack, 2,400 users connected their wallets before anyone noticed, and $4.7 million was drained in 24 hours. This guide shows you how to protect your users and prevent this kind of attack.
Why dApp Browsers Need Security
URL Protection
Block phishing sites before users connect their wallets
Transaction Preview
Show users what they’re signing before they approve
Contract Verification
Verify the contracts users interact with are safe
- URL phishing detection — Block known phishing and scam sites, and flag lookalikes of known projects
- Transaction simulation — Show users exactly what will happen before signing
- Contract verification — Check if the contract is legitimate or malicious
- Real-time risk scoring — Fast enough for inline warnings without blocking navigation
- Multi-chain support — Protect across all major networks
Prerequisites
Before implementing browser security, ensure you have:- A Webacy API key (sign up here)
- Basic familiarity with REST APIs or the Webacy SDK
- Your browser’s navigation and transaction signing flows identified
URL Security
The first line of defense is stopping users from connecting to malicious sites.Phishing Detection
Check URLs when users navigate to new sites or before they connect their wallet.unknown means Webacy has no verdict for the site, not that it is safe. Treat it as unverified.The TypeScript samples use the
riskLevel response and the UrlRiskLevel type, which need an @webacy-xyz/sdk release newer than 2.0.1. Older SDK versions type this response with fields the API doesn’t return.Mapping the Verdict to an Action
Turn the verdict into a browser action.Homograph Attack Detection
Common homograph substitutions:
The URL check flags lookalikes of known projects spelled with ASCII characters (
medium), but Unicode lookalikes are not reliably flagged and can come back unknown. For any non-ASCII host, show the user its punycode form (xn--…) alongside the verdict.
Transaction Security
Every transaction request is an opportunity to protect users.Pre-Signing Preview
Simulate transactions before users sign them.Session Protection
Monitor the entire browsing session for threats.Connected dApp Monitoring
Track all dApps the user has connected to and periodically recheck their safety.Risk-Scored Connections
Show users the risk level of their connected dApps.Complete Integration Workflow
Navigation Flow
Wallet Connection Flow
Transaction Request Flow
Full TypeScript Implementation
Complete dApp Browser Security Module
Complete dApp Browser Security Module
Example URLs for Testing
Known Phishing Sites
Test with URLs that mimic legitimate sites but use different domains:uniswap-claim.comopensea-claim.xyzmetamask-support.io
Legitimate Sites (for comparison)
Test Addresses
API Quick Reference
Next Steps
Get Your API Key
Start protecting your browser users
API Reference
Complete endpoint documentation
Phishing Guide
Understand phishing attack patterns
Install the SDK
TypeScript SDK for integration
