# @walletconnect/core@2.21.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:54:41.000Z
- Files reviewed: 2
- Findings: 3 medium, 7 low severity findings
- Report: https://security.togoder.click/npm/@walletconnect/core@2.21.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @walletconnect/core@2.21.0 on Oct 4, 2026. An AI review of 2 source files produced 3 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Network requests to external services

Finding ID: `NPS-C920F11DCD03`

File: `dist/index.cjs.js:1`

The code makes several HTTP fetch requests to external WalletConnect infrastructure (verify.walletconnect.com, pulse.walletconnect.org, echo.walletconnect.com). These are expected for a WalletConnect SDK but represent telemetry and attestation data being sent externally. The event client sends telemetry to pulse.walletconnect.org including client ID, user agent, and event traces.

### [medium] Telemetry and data collection

Finding ID: `NPS-8A168A42A627`

File: `dist/index.cjs.js:1`

The EventClient class collects and sends telemetry data (client ID, user agent, app domain, event traces) to https://pulse.walletconnect.org/batch. While this is a known feature of WalletConnect v2.21.0, it represents data exfiltration to an external server.

### [medium] Cryptographic key handling

Finding ID: `NPS-E470A3477163`

File: `dist/index.cjs.js:1`

The Crypto class generates and stores private keys, seeds, and symmetric keys in a keychain backed by storage. It uses ed25519 key pairs and JWT signing. While this is expected for a wallet SDK, any compromise of this code could lead to key theft. The keychain is stored in the configured storage (default in-memory).

### [low] Dynamic iframe creation and postMessage handling

Finding ID: `NPS-B59D8C754EE4`

File: `dist/index.cjs.js:1`

The Verify class creates a hidden iframe pointing to verify.walletconnect.com for attestation and listens for window postMessage events. It parses incoming messages and extracts JWT attestations. This could potentially be abused if the verify endpoint were compromised, but the URLs are hardcoded to trusted domains.

### [low] Global variable manipulation

Finding ID: `NPS-5B1DC525CA69`

File: `dist/index.cjs.js:1`

The Core class sets global variables (globalThis._walletConnectCore_) and injects a downloadLogsBlobInBrowser function onto the window object. This modifies the global environment, which could potentially interfere with other applications but is not inherently malicious.

### [low] Network requests to external services

Finding ID: `NPS-9437383791A6`

File: `dist/index.es.js`

The code makes network requests to external URLs including https://verify.walletconnect.com, https://verify.walletconnect.org, https://echo.walletconnect.com, and https://pulse.walletconnect.org/batch. These are part of expected WalletConnect functionality (attestation verification, echo client for push notifications, and telemetry/event collection) but represent external data transmission.

### [low] Telemetry and event data collection

Finding ID: `NPS-7EF0CFBC9586`

File: `dist/index.es.js`

The EventClient class collects and sends telemetry data (events, traces, errors) to https://pulse.walletconnect.org/batch including client ID, user agent, domain, and other metadata. This is opt-in but enabled by default (telemetryEnabled parameter defaults to true).

### [low] Dynamic iframe creation and message handling

Finding ID: `NPS-3C3361A21DC1`

File: `dist/index.es.js`

The Verify class creates an iframe pointing to a verify URL and listens for postMessage events to receive attestation JWTs. While this is standard WalletConnect verification flow, it involves dynamic DOM manipulation and cross-origin message handling.

### [low] Local storage of cryptographic material

Finding ID: `NPS-024964CC2B50`

File: `dist/index.es.js`

Cryptographic keys (symmetric keys, private keys, client seeds) are stored in local storage via KeyChain and Crypto classes. This is expected for a wallet connectivity library but means sensitive material is persisted in browser storage.

### [low] Global state manipulation

Finding ID: `NPS-CC6A37D7DF91`

File: `dist/index.es.js`

The Core class sets global variables on globalThis (e.g., _walletConnectCore_) and can modify window.downloadLogsBlobInBrowser. This is for singleton pattern implementation but does modify global scope.

## Files reviewed

- `dist/index.cjs.js` (medium): This appears to be the legitimate WalletConnect Core SDK (v2.21.0) which makes expected network requests to WalletConnect infrastructure for relay, verify, echo, and telemetry services, with no evidence of malicious backdoors, code execution, or credential harvesting beyond what is normal for this SDK.
- `dist/index.es.js` (medium): This is the official WalletConnect Core library (v2.21.0) with expected network communications to WalletConnect infrastructure for relay, verification, and telemetry; no malicious patterns, obfuscation, credential harvesting, or backdoors were detected.

## Version ranges

None of the 3 scanned versions of @walletconnect/core are flagged high or critical. The latest scanned version, 2.25.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.21.0 – 2.25.0 (`>=2.21.0 <=2.25.0`): medium (Telemetry and data collection +4 more)
- 2.19.0 – 2.19.1 (`>=2.19.0 <=2.19.1`): not scanned

## Scanned versions

- [2.25.0](https://security.togoder.click/npm/@walletconnect/core@2.25.0): medium, 2026-10-04T21:17:38.000Z
- [2.21.1](https://security.togoder.click/npm/@walletconnect/core@2.21.1): medium, 2026-10-04T16:54:44.000Z
- [2.21.0](https://security.togoder.click/npm/@walletconnect/core@2.21.0): medium, 2026-10-04T16:54:41.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
