# @walletconnect/ethereum-provider@2.21.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:19:45.000Z
- Files reviewed: 3
- Findings: 1 medium, 8 low severity findings
- Report: https://security.togoder.click/npm/@walletconnect/ethereum-provider
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @walletconnect/ethereum-provider@2.21.1 on Oct 4, 2026. An AI review of 3 source files produced 1 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Cryptocurrency wallet provider

Finding ID: `NPS-22A28D872D99`

File: `dist/index.native.js`

The package implements an Ethereum JSON-RPC provider that can request signatures (personal_sign, eth_signTypedData, eth_sendTransaction) and accounts. This is legitimate wallet functionality, but such code is inherently sensitive because it handles signing requests on behalf of users; it should be reviewed in the context of its intended use.

### [low] Dynamic module loading based on external input

Finding ID: `NPS-1524F44F4720`

File: `dist/index.cjs.js`

The code dynamically requires the '@reown/appkit/core' module at runtime using `await Promise.resolve().then(function(){return W(require('@reown/appkit/core'))})`. While the module name is fixed, this pattern defers loading and could be used for conditional dependencies. However, the use of a fixed module string reduces the risk of arbitrary code execution from computed inputs.

### [low] Potential information exposure via network requests

Finding ID: `NPS-1110D33111DB`

File: `dist/index.cjs.js`

The code constructs RPC URLs that include a project ID parameter: `https://rpc.walletconnect.org/v1/?chainId=...&projectId=...`. The project ID may be sensitive if hardcoded or mishandled, but in this context it is a user-supplied configuration parameter. No evidence of exfiltration to unknown servers.

### [low] Session data persistence

Finding ID: `NPS-2CE56D707038`

File: `dist/index.cjs.js`

The code uses persistent storage (e.g., `this.signer.client.core.storage.setItem`) to save the chain ID. While this is standard for session management, it represents a minor privacy consideration as it stores user session state. No credentials or sensitive keys are explicitly stored.

### [low] Dynamic import of external module

Finding ID: `NPS-2129B4E31985`

File: `dist/index.es.js`

The code uses a dynamic import for '@reown/appkit/core' inside the initialize method. This is not inherently malicious but could allow loading arbitrary code if the import path were configurable. Here it is a fixed package name, so risk is low.

### [low] Network requests to external RPC endpoints

Finding ID: `NPS-30CE335E151C`

File: `dist/index.es.js`

The code constructs RPC URLs pointing to 'https://rpc.walletconnect.org/v1/' and uses them for blockchain interactions. This is expected behavior for a wallet provider but could potentially leak user data (e.g., IP address, project ID) to a third-party service.

### [low] Dynamic code execution via import()

Finding ID: `NPS-140174894E3D`

File: `dist/index.es.js`

The dynamic import of '@reown/appkit/core' is performed based on configuration flag 'showQrModal'. While not user-controlled directly, it loads code at runtime. No obfuscation or malicious payload detected.

### [low] Third-party dependency and external RPC endpoint

Finding ID: `NPS-FF833C29935B`

File: `dist/index.native.js`

The module relies on the external WalletConnect service and sends RPC requests to the external endpoint https://rpc.walletconnect.org/v1/, including the user's projectId and chainId. While this is expected behavior for a WalletConnect provider, it means blockchain RPC traffic and metadata are transmitted to a third party.

### [low] Dynamic import of optional module

Finding ID: `NPS-EC0839C35A2E`

File: `dist/index.native.js`

The code uses Promise.resolve().then(function(){return et}) to dynamically load an internal appkit helper module and also attempts to load @reown/appkit. This is dynamic module loading, though the target is a fixed internal object rather than computed or external input, so it is not a direct security risk.

## Files reviewed

- `dist/index.cjs.js` (medium): The code is a legitimate WalletConnect Ethereum provider library with no malicious patterns, but it includes dynamic module loading and network requests typical for wallet connectivity.
- `dist/index.es.js` (medium): The code is a legitimate WalletConnect Ethereum provider with expected network interactions and dynamic imports, but no clear malicious patterns such as data exfiltration or credential harvesting were found.
- `dist/index.native.js` (medium): The code appears to be a legitimate WalletConnect/Ethereum provider implementation with no clear malicious patterns, though it depends on external services and handles sensitive wallet signing operations.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
