WafiWallet

Wallet Core

The foundation of WafiWallet: local key derivation, encrypted storage and chain-specific transaction signing.

Architecture reference · Web implementation on test networks

WafiWallet blue and cyan shield

One chain boundary

Networks implement a common ChainAdapter interface for address derivation, balances, fees, transaction building and broadcasting. Network-specific logic stays separate from the vault.

Audited primitives, local secrets

WafiWallet uses @scure, @noble and viem libraries for cryptographic operations. The web vault is encrypted locally; servers never receive recovery phrases or private keys.

Web and native integration

The current native setup is a Capacitor shell around the published wallet. Native keychain integration and independent platform audits remain roadmap work; WafiWallet does not claim a released multi-language Wallet Core SDK.

Integration boundaries

  • Mainnet rollout is gated on security review and testing.
  • RPC-built transactions must be verified before local signing.
  • Backends and administrators cannot recover keys, sign or move user funds.

How it works

  1. 1

    Generate entropy

    BIP-39 phrases are created on the device with audited libraries.

  2. 2

    Derive accounts

    BIP-32/44 paths produce EVM, Bitcoin, Solana and TRON addresses.

  3. 3

    Encrypt and sign

    The vault uses AES-256-GCM; transactions are signed locally.

Multi-chain

EVM networks, Bitcoin, Solana and TRON on test networks today.

Local verification

Node-built TRON payloads are verified before signing.

Testnets only

Mainnet stays disabled until independent audits are complete.

Frequently asked questions