WafiWallet
Wallet Core
The foundation of WafiWallet: local key derivation, encrypted storage and chain-specific transaction signing.
Architecture reference · Web implementation on test networks

One chain boundary
Networks implement a common ChainAdapter interface for address derivation, balances, fees, transaction building and broadcasting. Network-specific logic stays separate from the vault.
Audited primitives, local secrets
WafiWallet uses @scure, @noble and viem libraries for cryptographic operations. The web vault is encrypted locally; servers never receive recovery phrases or private keys.
Web and native integration
The current native setup is a Capacitor shell around the published wallet. Native keychain integration and independent platform audits remain roadmap work; WafiWallet does not claim a released multi-language Wallet Core SDK.
Integration boundaries
- Mainnet rollout is gated on security review and testing.
- RPC-built transactions must be verified before local signing.
- Backends and administrators cannot recover keys, sign or move user funds.
How it works
- 1
Generate entropy
BIP-39 phrases are created on the device with audited libraries.
- 2
Derive accounts
BIP-32/44 paths produce EVM, Bitcoin, Solana and TRON addresses.
- 3
Encrypt and sign
The vault uses AES-256-GCM; transactions are signed locally.
Multi-chain
EVM networks, Bitcoin, Solana and TRON on test networks today.
Local verification
Node-built TRON payloads are verified before signing.
Testnets only
Mainnet stays disabled until independent audits are complete.

