# @walletconnect/core@2.21.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:54:44.000Z
- Files reviewed: 2
- Findings: 3 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/@walletconnect/core@2.21.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @walletconnect/core@2.21.1 on Oct 4, 2026. An AI review of 2 source files produced 3 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Telemetry and data collection

Finding ID: `NPS-F366F00C8AF5`

File: `dist/index.cjs.js`

The package includes an EventClient (EventClient class) that sends telemetry events to https://pulse.walletconnect.org/batch and registers device tokens to https://echo.walletconnect.com. This includes client ID, user agent, app domain, and other metadata. While this appears to be legitimate WalletConnect infrastructure, it represents data exfiltration to external servers.

### [medium] File system/storage manipulation

Finding ID: `NPS-7F5D71FC67E3`

File: `dist/index.cjs.js`

The package uses keyvaluestorage to persist data including private keys, sym keys, and session data. It stores sensitive cryptographic material. While this is expected for a wallet connection library, improper storage could lead to credential theft. Storage is scoped to the application's storage (localStorage/IndexedDB).

### [medium] Telemetry and network requests at runtime

Finding ID: `NPS-917C34F2599A`

File: `dist/index.es.js`

The EventClient class (`Bi`/`EventClient`) sends POST requests containing the client_id, user_agent, project ID, domain, and event traces to `https://pulse.walletconnect.org/batch`. It also registers device tokens with `https://echo.walletconnect.com/${projectId}/clients`. While this is documented WalletConnect telemetry for the official SDK, it is still outbound data transmission to third-party servers that runs on import/initialization.

### [low] Network requests to external servers

Finding ID: `NPS-B001B020D6B1`

File: `dist/index.cjs.js`

Multiple external network requests are made to WalletConnect-controlled domains: relay.walletconnect.org (WebSocket), verify.walletconnect.com, verify.walletconnect.org, echo.walletconnect.com, and pulse.walletconnect.org. These are expected for a WalletConnect library but represent potential data exfiltration vectors if the domains were compromised or if the package were malicious.

### [low] Dynamic code execution via crypto operations

Finding ID: `NPS-92595D0C0A5A`

File: `dist/index.cjs.js`

The code uses crypto.subtle.digest and other cryptographic operations. It also uses JWT signing and verification with Ed25519. These are standard for WalletConnect but could theoretically be abused. No eval, new Function, or similar dynamic code execution was found.

### [low] Global object manipulation

Finding ID: `NPS-D6C52A9BB08C`

File: `dist/index.cjs.js`

The code sets global variables on globalThis (e.g., _walletConnectCore_<prefix>) and may override window.downloadLogsBlobInBrowser. This could lead to namespace pollution or unexpected global state, but is not inherently malicious.

### [low] Attestation iframe / postMessage handler

Finding ID: `NPS-F8927FCEE8FC`

File: `dist/index.es.js`

The Verify class creates an iframe pointing to `https://verify.walletconnect.com/v3/attestation` and listens for `message` events, parsing JWT attestations. This is part of the official WalletConnect Verify feature, but the mechanism (iframe + postMessage + JWT parsing) could be a vector if the endpoint were compromised or MITM'd.

### [low] Dynamic module / globalThis manipulation

Finding ID: `NPS-25E8EA22001D`

File: `dist/index.es.js`

The Core class stores and retrieves a global singleton via `globalThis['_walletConnectCore_...']` and reads `process.env.DISABLE_GLOBAL_CORE`. This is not obfuscation but does interact with the global environment and process environment variables (read-only).

### [low] Cryptographic key material handling in memory

Finding ID: `NPS-0A3F947ED7D0`

File: `dist/index.es.js`

The Crypto class generates and stores private keys, symmetric keys, and client seeds in a KeyChain (default in-memory / keyvaluestorage). This is expected for a wallet-connect library, but the library does handle sensitive key material that could be targeted by malicious actors if the package were compromised.

## Files reviewed

- `dist/index.cjs.js` (medium): The package is the legitimate WalletConnect Core library and performs expected networking, cryptographic operations, and telemetry to WalletConnect-controlled servers; no malicious patterns such as credential harvesting, obfuscated payloads, shell execution, or wallet draining were detected, but its telemetry and key storage practices warrant caution.
- `dist/index.es.js` (medium): This is the legitimate @walletconnect/core package; it contains expected telemetry, attestation, and key-management code, but no evidence of malicious exfiltration, credential harvesting, obfuscation, or backdoor behavior beyond the SDK's documented network calls.

## Version ranges

None of the 3 scanned versions of @walletconnect/core are flagged high or critical. The latest scanned version, 2.25.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.21.0 – 2.25.0 (`>=2.21.0 <=2.25.0`): medium (Telemetry and data collection +4 more)
- 2.19.0 – 2.19.1 (`>=2.19.0 <=2.19.1`): not scanned

## Scanned versions

- [2.25.0](https://security.togoder.click/npm/@walletconnect/core@2.25.0): medium, 2026-10-04T21:17:38.000Z
- [2.21.1](https://security.togoder.click/npm/@walletconnect/core@2.21.1): medium, 2026-10-04T16:54:44.000Z
- [2.21.0](https://security.togoder.click/npm/@walletconnect/core@2.21.0): medium, 2026-10-04T16:54:41.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
