Developers

How WafiWallet is built.

Architecture reference for contributors, auditors and integration partners.

Documentation

Product Requirements

What WafiWallet is, who it serves, and what each phase ships.

Technical Architecture

Clients own keys and signing; services provide public data, quotes and risk intelligence.

App Sitemap

Every screen in the mobile app and how they connect.

User Flows

Entry, validation, security checks, errors and recovery for each major feature.

Threat Model

Threats, impact and mitigations across clients, backend and supply chain.

Blockchain Support Matrix

Curves, derivation paths and features per network.

ChainAdapter Specification

One interface every chain implements; chain logic stays behind it.

Key Management Design

How secrets are created, stored, unlocked and destroyed.

API Architecture

Public, versioned REST APIs behind the gateway. No endpoint accepts secrets.

Database Schema

PostgreSQL holds public data only.

Backend Services

Go for chain-critical services, TypeScript for admin, CMS and composition.

Mobile Architecture

Swift/SwiftUI and Kotlin/Compose with a shared audited crypto core.

Browser Extension Architecture

Manifest V3 for Chrome, Brave, Edge and other Chromium browsers.

Admin Architecture

Operations console with RBAC and audit logs — and no path to user funds.

Website Architecture

Server-rendered marketing site with one route per section.

Deep Links

The wafiwallet:// scheme and how every link is validated.

Testing Strategy

Correctness of cryptography first, then flows, then UI.

DevOps, Observability & Audits

Pipeline, monitoring, audits and responsible disclosure.

Implementation Roadmap

Security foundations before features.

iOS & Android Apps — Build and Store Submission

How to turn the WafiWallet web wallet into installable iOS and Android apps with Capacitor, and submit them.

System architecture

Clients hold keys and sign locally. Backend services are stateless with respect to secrets: they serve public chain data, quotes and risk intelligence only.

┌──────────── Clients (keys + signing) ────────────┐
│ iOS (Keychain/SE) · Android (Keystore) · Ext · Web │
└──────────────┬───────────────────────────────────┘
               │ HTTPS (no secrets)
        ┌──────▼──────┐
        │ API Gateway │  auth · rate limit · WAF
        └──┬───┬───┬──┘
   ┌───────┘   │   └────────────┐
┌──▼───┐ ┌─────▼─────┐ ┌────────▼────────┐
│ RPC  │ │ Portfolio │ │ Swap / Bridge / │
│Router│ │ Price/Tx  │ │ Fiat aggregators│
└──┬───┘ │ Indexer   │ └────────┬────────┘
   │     └─────┬─────┘          │
 Alchemy · QuickNode · Infura · Ankr · own nodes
               │
     PostgreSQL · Redis · Kafka (events)

ChainAdapter specification

Every chain implements one interface. Adding a network means adding an adapter — no changes to key storage.

interface ChainAdapter {
  getAddress(): string
  getBalance(addr): Promise<Balance>
  getTokenBalances(addr, tokens): Promise<TokenBalance[]>
  getGasEstimate(tx, from): Promise<GasEstimate>
  buildTransaction(input): Promise<UnsignedTx>
  simulateTransaction(tx, from): Promise<Simulation>
  signTransaction(tx, key): Promise<SignedTx>   // device only
  broadcastTransaction(signed): Promise<TxHash> // verifies chainId
  getTransaction(hash): Promise<TxStatus>
  getTransactionHistory(addr): Promise<NormalizedTx[]>
  validateAddress(addr): boolean
  getTokenMetadata(contract): Promise<TokenRef>
}

Wallet Core

  • BIP-39 mnemonics, BIP-32 HD derivation, BIP-44/84 paths; SLIP-10 for ed25519 chains.
  • Vault: AES-256-GCM, key from PIN via PBKDF2-SHA256 (310k iterations) on web; hardware-backed keys (Secure Enclave / StrongBox) wrap the vault key on mobile.
  • Audited libraries only: @scure/bip39, @scure/bip32, @noble/curves, @noble/hashes, viem; Trust Wallet Core (Apache-2.0) on native, kept behind a WafiWallet signer boundary.
  • EIP-155/1559 chain IDs on every EVM signature; RPC chain ID verified before broadcast (replay protection).

Backend services

Go for chain-critical services (RPC Router, Indexer, Blockchain Service); TypeScript for aggregators, CMS and admin APIs.

RPC Router: per-provider health checks, p95 latency scoring, timeouts (3s read / 10s broadcast), exponential-backoff retries on idempotent calls only, circuit breakers that open after 5 consecutive failures.

Services: API Gateway, Blockchain, RPC Router, Transaction Indexer, Portfolio, Token Metadata, Price, Swap Aggregator, Bridge Aggregator, Fiat Provider, Staking, NFT, Security (WafiShield), Notification (APNs/FCM), Analytics, CMS.

Database design

PostgreSQL stores public data only. No table may contain seed phrases, private keys or unencrypted wallet credentials.

networks(id, chain_id, family, name, symbol, decimals, enabled)
rpc_providers(id, network_id, url, priority, healthy, p95_ms)
tokens(id, network_id, contract, symbol, decimals, verified, spam)
transactions(id, hash, network, type, from, to, asset, amount,
             network_fee, status, timestamp, metadata jsonb)
watch_addresses(device_id, network, address)   -- public addresses only
push_tokens(device_id, platform, token)
scam_domains(domain, source, added_at)
risky_contracts(network, address, reason, severity)
feature_flags(key, enabled, rules jsonb)
admin_audit_log(admin_id, action, target, at)

Threat model (summary)

  • Device malware / clipboard hijack — re-validate pasted addresses, show full address on review, lookalike detection.
  • Address poisoning — compare head/tail with history and address book; warn before send.
  • Malicious dApps / drainers — simulation, unlimited-approval warnings, phishing domain list.
  • Malicious deep links — every wafiwallet:// payload is parsed, validated and shown for confirmation; never auto-signs.
  • Compromised RPC — multi-provider, chain ID verification, simulation cross-check.
  • Insider / backend breach — servers hold no secrets; admins cannot view keys, sign or move funds.
  • Logging leaks — log scrubbing forbids seed, key, PIN and decrypted keystore fields.

Repository structure

apps/      ios · android · extension · website · admin
core/      wallet-core · signer · chains · security
services/  api · blockchain · portfolio · transaction · swap · price · security · notification
packages/  types · ui · config
infrastructure/  docker · terraform · kubernetes

Roadmap

  1. Wallet foundation: create/import, multi-wallet, secure storage, EVM chains, Bitcoin, Solana, Tron, send, receive, history.
  2. Swap, fiat buy, WalletConnect, NFTs, custom networks/tokens, notifications, WafiShield.
  3. Cross-chain swaps, bridges, staking, approval manager, address book, price alerts.
  4. Browser extension.
  5. Smart wallet (ERC-4337), passkeys, social recovery, gas sponsorship, hardware wallets.

Testing & CI/CD

BIP-39/32 official test vectors, address derivation per chain, signing and encoding tests, vault round-trips, fuzzing of parsers, dependency/secret/static scans, mobile and extension pen-tests.

PR → lint → unit → static analysis → secret scan → dependency scan
   → integration → build → security tests → staging → manual approval → production

Observability: OpenTelemetry traces, structured logs, metrics and alerts — with mandatory redaction of all sensitive signing material.