How to connect Trust Wallet to a dApp safely without exposing your keys
Connecting Trust Wallet to a decentralized application (dApp) is done through WalletConnect or the built-in browser, and when done correctly, your private keys and seed phrase never leave your device. The safe method relies on a cryptographic handshake that authorizes the dApp to read certain data and submit transactions on your behalf, without ever transmitting your recovery phrase or raw private key.
How the connection actually works
When you connect Trust Wallet to a dApp, the wallet generates a session key pair. The public part is shared with the dApp; the private part stays in the wallet. The dApp can then request to see your public address, ask you to sign messages, or submit transactions for your approval. Every transaction must be confirmed manually inside Trust Wallet before it is broadcast. The dApp never gains direct access to your wallet’s private keys or seed phrase.
The two main methods are:
- WalletConnect - a QR-code based protocol. The dApp shows a QR code; you scan it with Trust Wallet’s scanner. This is the recommended method for desktop dApps.
- Trust Wallet browser - an in-app browser with Web3 injection. The dApp reads your wallet’s address directly from the browser environment. This is simpler for mobile-native dApps, but carries additional risk from malicious sites.
Steps to connect safely using WalletConnect
- Open the dApp on your desktop or laptop. Look for a “Connect Wallet” button. Choose WalletConnect from the list of options. The dApp will display a QR code.
- Open Trust Wallet on your phone. Tap the WalletConnect icon (usually a small square with a QR symbol) at the top of the main screen. If you cannot find it, go to Settings > WalletConnect and tap “New Connection.”
- Scan the QR code. Point your phone’s camera at the screen. Trust Wallet will show the dApp’s name and the permissions it requests (typically “View your wallet address” and “Request approval of transactions”). Review these carefully.
- Confirm the connection. Tap “Connect” only if you trust the dApp and the permissions look reasonable. After confirmation, the dApp will display your wallet address.
From this point, every action the dApp wants to take on the blockchain must be confirmed by you inside Trust Wallet. Read each transaction prompt: check the network, the amount, and the contract address before approving.
Steps to connect safely using the Trust Wallet browser
- Open the Trust Wallet browser. Tap the browser icon (globe) at the bottom of the app. This opens a Web3-enabled browser.
- Navigate to the dApp’s URL. Type the address carefully. Do not rely on search results or links from untrusted sources.
- Tap “Connect Wallet.” The browser will automatically detect Trust Wallet. A pop-up will ask you to confirm the connection. Tap “Connect” after verifying the dApp name.
- Check the URL bar. A small wallet icon should appear, confirming the connection is active.
Common risks and how to avoid them
- Fake dApps: Scammers create clones of popular dApps with similar URLs. Always double-check the domain. Use bookmarks for sites you visit regularly.
- Phishing via WalletConnect QR codes: A malicious site or person can show you a QR code that connects to a contract designed to drain your wallet. Never scan a QR code from an untrusted source, email, or social media message.
- Malicious “sign” requests: Some dApps ask you to sign a message that, if signed, gives the dApp permission to spend your tokens (approval-based attacks). Read the signing prompt carefully. If it mentions “approve” or a large allowance for an unknown contract, decline.
- Unlimited approvals: When a dApp asks you to approve a token spend, it may request an infinite allowance. This is common practice for many DeFi dApps, but it means the dApp’s contract can spend your tokens indefinitely. Consider using a separate wallet for high-value holdings and revoke unnecessary approvals periodically.
What is NOT safe
- Entering your seed phrase or private key into any website, pop-up, or dApp interface. No legitimate dApp will ever ask for this. Trust Wallet never exposes this information during a normal connection.
- Sharing your private key or seed phrase via WalletConnect or the browser. The connection protocol does not transmit this data. If a site claims to need your seed phrase to “sync” or “restore,” it is a scam.
- Connecting to a dApp that requests permissions beyond “view your address” and “request transactions.” Some malicious sites may ask for “sign any transaction” or “broadcast without confirmation.” Decline immediately.
What to do if you suspect a compromise
If you connected to a dApp and then noticed unexpected transactions or token drainage:
- Transfer remaining funds to a new wallet immediately. Create a fresh Trust Wallet (new seed phrase) and move your assets manually.
- Revoke any token approvals you may have signed. Use a block explorer’s “Token Approval” checker or a dedicated revoke tool.
- Do not reuse the compromised wallet address. The dApp or attacker may still hold the authorization to spend your tokens.
The safest approach is to treat each dApp connection as temporary. Disconnect from dApps you no longer use via Settings > WalletConnect (for WalletConnect sessions) or by clearing the browser cache (for in-app browser sessions). A disconnected session cannot submit new transactions.
Not financial advice. loomprotocol.xyz publishes market data and general information about digital assets. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.