[{"data":1,"prerenderedAt":44},["ShallowReactive",2],{"blog-content-en-how-to-connect-wallet-to-dapp":3},{"slug":4,"title":5,"excerpt":6,"description":7,"bodyHtml":8,"faqItems":9,"howToSteps":25},"how-to-connect-wallet-to-dapp","How to Connect Your Wallet to a dApp (and Stay Safe)","Connecting your wallet to a dApp is how you use Web3 — and where many scams happen. Here is how connection works, how to read approvals, how to revoke them, and a safe step-by-step.","How to connect a crypto wallet to a dApp safely: WalletConnect vs browser extension, reading and revoking token approvals, spotting drainers, and a safe checklist.","\u003Cp>To connect your wallet to a dApp safely, reach the official site yourself rather than through an ad or link, click the dApp's connect button, choose your connection method (a browser extension or WalletConnect QR code), approve only the read-only connection, and then read every signature and token approval carefully before confirming. A plain connection is harmless and gives the site no power over your funds. The risk starts the moment you sign something, so the whole game is knowing the difference between connecting, signing, and approving, and never granting an approval you do not understand.\u003C\u002Fp>\n\u003Cp>This guide explains what connecting actually does, the two main ways to connect, what a token approval is and why unlimited ones are dangerous, how wallet drainers and fake dApp sites trick people, a numbered safe-connection checklist, and how to revoke approvals you no longer want.\u003C\u002Fp>\n\u003Ch2>What connecting to a dApp actually does\u003C\u002Fh2>\n\u003Cp>A dApp, or decentralized application, is a website that talks to a blockchain. Exchanges, lending markets, NFT marketplaces, and games are all dApps. To use one you connect your wallet, which is the bridge between the site and the chain. If the idea of decentralized apps is new, our overview of \u003Ca href=\"\u002Fblog\u002Fwhat-is-web3\">what Web3 is\u003C\u002Fa> sets the scene, and our primer on \u003Ca href=\"\u002Fblog\u002Fwhat-is-a-crypto-wallet\">what a crypto wallet is\u003C\u002Fa> explains the tool doing the connecting.\u003C\u002Fp>\n\u003Cp>The single most important thing to understand is that connecting happens in three very different layers, and they carry very different risk.\u003C\u002Fp>\n\u003Ch3>1. The read-only connection\u003C\u002Fh3>\n\u003Cp>When you first connect, the dApp simply learns your public wallet address and reads your balances from the chain. That is it. It cannot move a single token, and it cannot sign anything on your behalf. A read-only connection is roughly as sensitive as telling someone your account number: they can look you up, but they cannot withdraw.\u003C\u002Fp>\n\u003Ch3>2. Signing a message\u003C\u002Fh3>\n\u003Cp>Many dApps ask you to sign a message to prove you control the address, often called \"sign in with your wallet.\" A plain message signature usually costs no gas and does not move funds. But signatures are not all harmless. Some malicious sites ask you to sign an off-chain message that is actually a permit granting away your tokens. The danger is that it looks like a harmless login when it is really an authorization, which is why you must read what a signature says.\u003C\u002Fp>\n\u003Ch3>3. Approving a transaction or token allowance\u003C\u002Fh3>\n\u003Cp>This is where real money is at stake. A transaction signature actually executes something on-chain: a swap, a transfer, a mint, or a token approval. A token approval is the one to watch most closely, and it deserves its own section.\u003C\u002Fp>\n\u003Ch2>What a token approval is and why unlimited ones are risky\u003C\u002Fh2>\n\u003Cp>On EVM chains like Ethereum, Arbitrum, Optimism, Polygon, and Base, a dApp cannot spend your tokens unless you first grant it an allowance. When you approve a token, you are telling the chain: this specific contract is allowed to move up to this much of this token from my wallet. That permission is what lets a decentralized exchange pull your USDC into a swap, for example.\u003C\u002Fp>\n\u003Cp>The trap is the amount. Many dApps request an \u003Cstrong>unlimited\u003C\u002Fstrong> approval by default, so you only ever have to approve once. That convenience is also the risk: if that contract is later exploited, or if it was malicious from the start, it can drain the entire balance of that token whenever it wants, without asking you again. An unlimited approval is a standing permission that outlives the single transaction you thought you were doing.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Approvals persist.\u003C\u002Fstrong> They do not expire when you disconnect your wallet or close the tab. They stay live on-chain until you revoke them.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Unlimited means unlimited.\u003C\u002Fstrong> A drained or compromised contract with unlimited allowance can take everything of that token, even tokens you acquire later.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Prefer exact amounts.\u003C\u002Fstrong> Where your wallet lets you, approve only the amount you are about to spend. You will approve a little more often, but a leaked approval can only ever touch that small amount.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Approvals are an EVM concept. On Solana and TON the permission model differs, but the same instinct applies everywhere: read what you are authorizing, and do not grant blanket power you do not need. This habit is core to \u003Ca href=\"\u002Fblog\u002Fcrypto-wallet-security-best-practices\">crypto wallet security best practices\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>The two main ways to connect\u003C\u002Fh2>\n\u003Cp>There are two paths most people use, and the right one depends on whether you are on a computer or a phone.\u003C\u002Fp>\n\u003Ch3>Browser extension\u003C\u002Fh3>\n\u003Cp>On a desktop, the cleanest path is a wallet that lives in your browser. The \u003Ca href=\"\u002Fchrome-extension\">WATS Chrome Extension\u003C\u002Fa> works on Chromium browsers (Chrome 120+, Edge, and Brave), handles one-click dApp connection, and signs transactions in-browser. It is free and fully non-custodial, meaning you hold your own keys and no one else can move your funds. When a dApp shows a connect prompt, the extension pops up, you pick the account, and you approve the read-only connection. Every later signature surfaces in the same extension window so you can read it before confirming.\u003C\u002Fp>\n\u003Ch3>WalletConnect or QR code\u003C\u002Fh3>\n\u003Cp>On mobile, or when you want to use a desktop dApp with a phone wallet, WalletConnect is the standard. The dApp shows a QR code, you scan it with your mobile wallet, and an encrypted session links the two. The \u003Ca href=\"\u002Fhot-wallet\">WATS Hot Wallet\u003C\u002Fa> and the WATS Mobile App (iOS and Android) connect to dApps this way. The key safety point is to scan only a QR code you raised yourself on the real site, and to disconnect the session when you are finished rather than leaving it open indefinitely.\u003C\u002Fp>\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\u003Cth>Method\u003C\u002Fth>\u003Cth>Best for\u003C\u002Fth>\u003Cth>How it links\u003C\u002Fth>\u003Cth>Watch out for\u003C\u002Fth>\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\u003Ctd>Browser extension\u003C\u002Ftd>\u003Ctd>Desktop use\u003C\u002Ftd>\u003Ctd>Injected into the browser\u003C\u002Ftd>\u003Ctd>Fake extensions; only install from official sources\u003C\u002Ftd>\u003C\u002Ftr>\n\u003Ctr>\u003Ctd>WalletConnect \u002F QR\u003C\u002Ftd>\u003Ctd>Mobile, or desktop dApp with a phone\u003C\u002Ftd>\u003Ctd>Encrypted QR session\u003C\u002Ftd>\u003Ctd>Only scan a QR you raised on the real site\u003C\u002Ftd>\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003Ch2>Wallet drainers and fake dApp sites\u003C\u002Fh2>\n\u003Cp>Most stolen funds in Web3 do not come from broken cryptography. They come from people being tricked into connecting to a fake site and signing one bad approval. It is worth being blunt about how this works.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Fake front-ends.\u003C\u002Fstrong> Scammers clone a popular dApp pixel for pixel and buy search ads so the fake ranks above the real one. The site looks perfect, but the connect button is wired to a drainer contract.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Drainer signatures.\u003C\u002Fstrong> Once connected, the fake site asks you to sign what looks like a routine action. In reality the signature is a token permit or a transfer approval that hands your assets to the attacker in a single click.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Urgency and bait.\u003C\u002Fstrong> Drainers thrive on pressure: a fake airdrop closing soon, a \"claim your reward\" banner, a support DM with a link. The urgency exists to stop you reading the signature.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The defense is not technical wizardry. It is slowing down, reaching sites yourself, and reading every prompt your wallet shows you. A non-custodial wallet cannot un-sign a transaction you approved, so the protection has to happen before you click confirm.\u003C\u002Fp>\n\u003Ch2>How to connect to a dApp safely: the step-by-step\u003C\u002Fh2>\n\u003Cp>Follow these in order, even for a dApp you use every day. The discipline is the point.\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Reach the dApp through a source you trust.\u003C\u002Fstrong> Type the URL yourself, use a bookmark you saved, or follow a link from the project's verified channels. Never click ads, search results you have not vetted, or links from DMs. Confirm the domain character by character before connecting.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Click the dApp's connect button and choose your method.\u003C\u002Fstrong> Use the connect button on the page itself, then pick your path: the WATS Chrome Extension on desktop, or WalletConnect by scanning a QR code with the WATS Mobile App or Hot Wallet on your phone. Make sure the connection request actually came from the tab you opened.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Approve only the read-only connection first.\u003C\u002Fstrong> The initial prompt should just share your address. It should not ask to spend tokens. If a first-time connection immediately demands a token approval or an unusual signature, stop and close the tab.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Read every signature before confirming.\u003C\u002Fstrong> Your wallet shows you what you are signing. Check whether it is a plain message or a transaction, which contract it touches, and what permission it grants. If the request is a permit or an approval you did not initiate, do not sign it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Limit token approvals to what you need.\u003C\u002Fstrong> When a dApp needs an allowance, set an exact amount instead of unlimited where your wallet allows. Approving a little more often is a small price for capping how much any single contract can ever touch.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Disconnect and revoke when you are done.\u003C\u002Fstrong> Disconnect the session or extension when you finish, and periodically review and revoke approvals you no longer use. Disconnecting ends the session, but it does not remove approvals, so revoking is a separate, important step.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch2>How to revoke token approvals\u003C\u002Fh2>\n\u003Cp>Revoking is the cleanup step almost everyone forgets. Because approvals live on-chain until you remove them, an old allowance to a contract you used once years ago is still a live risk today. Clearing them is straightforward.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Find your approvals.\u003C\u002Fstrong> Use a reputable approval-checker tool or a block explorer's token-approval view. Connect read-only and look at the list of contracts that currently have permission to spend each of your tokens.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Spot the dangerous ones.\u003C\u002Fstrong> Pay closest attention to unlimited allowances and to any contract you do not recognize or no longer use. Those are the standing doors you want to close.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Send a revoke transaction.\u003C\u002Fstrong> Revoking sets the allowance back to zero. It is an on-chain transaction, so it costs a small amount of gas, but it permanently removes that contract's ability to move your tokens.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Make it a routine.\u003C\u002Fstrong> Review your approvals every so often, and especially after using a new or unfamiliar dApp. A few minutes of cleanup closes off the most common path a future exploit would use.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>One honest note: revoking costs gas because it is a real transaction. Some wallets let you pay that fee in a single token rather than stocking each chain's native coin, which makes routine cleanup less of a chore. That is a convenience around how you pay, not a discount on the network cost itself.\u003C\u002Fp>\n\u003Ch2>Bottom line\u003C\u002Fh2>\n\u003Cp>Connecting your wallet to a dApp is the everyday gateway to Web3, and the connection itself is safe because it only shares your public address. The risk lives entirely in what you sign afterward, especially token approvals, which persist on-chain and can be exploited if you grant unlimited power to a contract that turns malicious. Protect yourself by reaching dApps through trusted sources, approving only the read-only connection first, reading every signature, limiting approvals to exact amounts, and revoking allowances you no longer need. The \u003Ca href=\"\u002Fchrome-extension\">WATS Chrome Extension\u003C\u002Fa> handles one-click connection and in-browser signing on desktop, while the WATS Mobile App and \u003Ca href=\"\u002Fhot-wallet\">Hot Wallet\u003C\u002Fa> connect over WalletConnect on the go, all fully non-custodial so your keys, and the final decision to sign, stay with you.\u003C\u002Fp>",[10,13,16,19,22],{"q":11,"a":12},"Is it safe to connect my wallet to a dApp?","Yes, the connection itself is safe because it only shares your public wallet address and lets the site read your balances. It cannot move funds or sign anything on its own. The risk begins only when you sign a message or approve a transaction, so the key is to read every prompt your wallet shows you and never approve something you do not understand. Connecting is harmless; signing carelessly is not.",{"q":14,"a":15},"What is a token approval and why are unlimited approvals risky?","A token approval is permission you grant a contract to move a certain amount of one of your tokens, which is how a decentralized exchange can pull your tokens into a swap. Many dApps request an unlimited approval so you only approve once, but that permission persists on-chain and does not expire. If that contract is later exploited or was malicious, it can drain your entire balance of that token without asking again. Approving an exact amount instead caps how much can ever be taken.",{"q":17,"a":18},"What is the difference between connecting with a browser extension and WalletConnect?","A browser extension like the WATS Chrome Extension lives in your desktop browser, injects directly into the page, and surfaces every signature in its own window for one-click connection and in-browser signing. WalletConnect links a dApp to a mobile wallet by scanning a QR code, creating an encrypted session, and is the standard for phones or for using a desktop dApp with a phone wallet. Both are safe when you only connect to sites you reached yourself.",{"q":20,"a":21},"How do wallet drainers steal funds, and how do I avoid them?","Wallet drainers usually rely on a fake clone of a real dApp, often promoted through ads or urgent messages, that asks you to sign what looks like a routine action but is actually a token permit handing assets to an attacker. You avoid them by reaching dApps through trusted sources rather than ads or DMs, refusing to connect on a first visit that immediately demands an approval, and reading every signature before confirming. A non-custodial wallet cannot reverse a transaction you signed, so the protection happens before you click confirm.",{"q":23,"a":24},"How do I revoke a token approval I no longer want?","Use a reputable approval-checker tool or a block explorer's token-approval view to list the contracts that currently have permission to spend your tokens, then send a revoke transaction that sets the allowance back to zero. Focus first on unlimited approvals and any contract you no longer recognize. Revoking is an on-chain action that costs a small amount of gas, but it permanently removes that contract's ability to touch your tokens, and doing it periodically closes off the most common path an exploit would use.",[26,29,32,35,38,41],{"title":27,"body":28},"Reach the dApp through a source you trust","Type the URL yourself, use a saved bookmark, or follow a link from the project's verified channels. Never click ads, unvetted search results, or links from DMs, and confirm the domain character by character before connecting.",{"title":30,"body":31},"Click the dApp's connect button and choose your method","Use the connect button on the page itself, then pick your path: the WATS Chrome Extension on desktop, or WalletConnect by scanning a QR code with the WATS Mobile App or Hot Wallet on your phone. Make sure the request came from the tab you opened.",{"title":33,"body":34},"Approve only the read-only connection first","The initial prompt should just share your address, not ask to spend tokens. If a first-time connection immediately demands a token approval or an unusual signature, stop and close the tab.",{"title":36,"body":37},"Read every signature before confirming","Check whether the request is a plain message or a transaction, which contract it touches, and what permission it grants. If it is a permit or approval you did not initiate, do not sign it.",{"title":39,"body":40},"Limit token approvals to what you need","When a dApp needs an allowance, set an exact amount instead of unlimited where your wallet allows. Approving a little more often caps how much any single contract can ever touch.",{"title":42,"body":43},"Disconnect and revoke when you are done","Disconnect the session or extension when you finish, and periodically review and revoke approvals you no longer use. Disconnecting ends the session but does not remove approvals, so revoking is a separate step.",1784634270280]