BlockchainAppMaker

DeFi

DeFi wallet development: custody models, smart accounts and signing safety

A DeFi wallet is a self-custody wallet built for interacting with protocols: it holds keys, connects to dApps, and helps users understand what they are signing. The hardest problems are not storing keys but preventing users from signing transactions that drain them, and recovering access without introducing a custodian.

This guide focuses on wallets for active DeFi use. For general wallet architecture, see cryptocurrency wallet development; for a browser-extension wallet modeled on a familiar product, see MetaMask-like wallet development.

Custody models

ModelHow keys workRecoveryTrade-offs
HD seed phrase (EOA)BIP-39 mnemonic derives keys via BIP-32/BIP-44 paths, e.g. m/44'/60'/0'/0/0 for EthereumSeed phrase backupUniversal and simple; users lose or leak seeds; no spending rules
Hardware-backed keyKey in a secure element or the phone's secure enclaveSeed backup or device-specificStrong against malware; enclave keys use P-256, which needs smart accounts to verify on EVM chains
MPC (threshold signatures)Key split into shares held by device, provider and/or backup; never assembledRe-share using remaining sharesNo seed phrase; depends on provider availability and protocol correctness
Smart contract accountContract wallet with programmable validation (multisig, passkeys, session keys)Guardians or social recoveryMost flexible; deployment cost per chain; some dApps still assume EOAs

MPC and smart accounts are not mutually exclusive: an MPC key can be the signer of a smart account. If an MPC provider or your company can unilaterally move funds, the wallet is custodial in substance, whatever the marketing says, with regulatory consequences.

Smart accounts: ERC-4337 and EIP-7702

ERC-4337 introduced account abstraction without changing Ethereum's consensus rules. Users sign UserOperations; bundlers package them and submit them to a shared EntryPoint contract, which calls each account's validation logic. Paymasters can sponsor gas or accept payment in ERC-20 tokens. This enables:

  • Batching: approve and swap in one action, removing a whole class of leftover unlimited approvals.
  • Gas sponsorship: users without ETH can still transact.
  • Session keys: a limited key that can, say, trade on one DEX up to a cap for an hour, useful for games and trading bots.
  • Passkeys and recovery: validation with WebAuthn keys and guardian-based recovery.

EIP-7702, activated with Ethereum's Pectra upgrade in May 2025, lets an existing EOA delegate to smart contract code, so users keep their address and gain batching and sponsorship. It also created a new phishing vector: a malicious delegation signature hands control of the account to attacker code. A wallet supporting 7702 should only allow delegation to vetted implementations and warn loudly otherwise.

Signing safety: the core DeFi wallet feature

Most DeFi losses suffered by individuals come from signing something harmful, not from key theft. A DeFi-focused wallet earns its place by making signatures understandable.

Transaction simulation

Simulate every transaction against current state and show the result as balance changes: "You send 1,000 USDC, you receive at least 0.31 ETH." Flag transfers to unknown contracts, approvals and ownership changes. Simulation is not perfect (state can change before inclusion, and malicious contracts can detect simulation environments), so pair it with other checks.

Approvals and permits

  • Default to exact-amount approvals and show the spender's identity.
  • Decode EIP-2612 permit and Permit2 signatures. These look like harmless messages but authorize spending; many drainer kits rely on users signing them blindly.
  • Provide an approvals dashboard so users can revoke stale allowances.

Typed data and messages

Render EIP-712 typed data in readable form and refuse or heavily warn on raw eth_sign of hashes, which can authorize anything.

Address and domain checks

Warn on address-poisoning (look-alike addresses inserted into history by dust transfers), known drainer contracts, newly deployed contracts and phishing domains. Maintain block lists and use community threat feeds.

Friction in the right places

Good wallets add friction selectively. A routine swap through a known router should be one confirmation; a signature that grants unlimited spending to a contract deployed yesterday, or an EIP-7702 delegation to unknown code, should require reading a warning and an extra step. Uniform pop-ups train users to click through everything, which is exactly what drainer kits rely on. Log which warnings users override so you can tune them without weakening protection.

DeFi features users expect

  • Swaps, usually through an aggregator API with an integrator fee. See the white-label swap comparison for options.
  • Bridging between chains via aggregators, with clear disclosure of which bridge is used and its risks.
  • Portfolio and positions: LP positions, lending health factors, staking balances, requiring indexing of many protocols.
  • dApp connection via an injected provider (EIP-1193, discoverable via EIP-6963) and WalletConnect for mobile.
  • MEV protection: optional private submission to reduce sandwich attacks.
  • Multichain support: EVM chains share key formats; Solana, Bitcoin and others need separate derivation and signing code.

Form factors

The same wallet core can ship in several shapes, and each one changes the security model:

  • Browser extension. The default for desktop DeFi. It injects a provider into pages and must isolate keys from page scripts. The main risks are malicious updates, compromised build pipelines and look-alike extensions in stores.
  • Mobile app. Can use the device's secure hardware and biometrics, and connects to desktop dApps through WalletConnect or deep links. App-store policies on crypto features vary by region and change, so plan for review delays.
  • Hardware wallet integration. Even if you do not build hardware, supporting established hardware signers lets security-conscious users keep keys offline while using your interface. Clear-signing support, where the device shows decoded transaction details, matters for DeFi because blind signing contract calls on a tiny screen is risky.
  • Embedded or web wallet. Lives inside an app, often with email or passkey login, MPC or smart accounts underneath. Lowest friction; trust shifts toward the provider's infrastructure and recovery process.
  • DeFi dashboard. Some products are less a wallet than a control panel over a smart account: they bundle positions across protocols and execute multi-step actions atomically. Smart contract wallets with modules make this kind of product possible.

Many teams start with one form factor and a shared signing core, then add others. Keep the transaction-decoding and risk-check logic in one library so every surface warns users the same way.

Build process

  1. Choose the custody model and recovery story based on your audience: crypto-natives tolerate seed phrases; mainstream users need passkeys or MPC with recovery.
  2. Select platforms: browser extension, mobile, or embedded in another app. Each has different key storage and review constraints.
  3. Use audited cryptography libraries; never write your own key derivation or signature code.
  4. Build the signing pipeline: decode, simulate, risk-check, display, sign.
  5. Integrate DeFi services: aggregators, price data, indexing, RPC with fallbacks.
  6. Security review: key storage, memory handling, extension permissions, update channel integrity, plus audits of any smart account contracts.
  7. Operate: threat-feed updates, incident response, and a signed update process, since a compromised wallet update can empty every user at once.

Cost and timeline drivers

As a reasoned estimate, a single-platform EVM wallet built on established libraries, with swaps through an aggregator and basic simulation, might take three to five engineers four to six months. A multi-platform wallet with smart accounts, MPC, many chains and rich portfolio tracking is a year-plus effort with ongoing costs for RPC, simulation, indexing and security operations.

DriverWhy it adds cost
Number of platformsExtension, iOS and Android each need native key storage and testing
Non-EVM chainsDifferent curves, derivation paths, transaction formats and RPC infrastructure
MPC or smart accountsProvider fees or contract audits, bundler and paymaster infrastructure
Simulation and threat intelligenceSimulation infrastructure and maintained risk lists
Portfolio coverageEach supported protocol needs position decoding

If you are building an app with an embedded wallet rather than a standalone wallet, the DeFi application guide covers that route, and the Web3 wallet guide discusses wallets beyond DeFi.

General information only, not legal advice. Whether a wallet provider is regulated often turns on whether it can control user funds; custodial and MPC-with-provider-control designs may require licensing in some jurisdictions.

Frequently asked questions

What makes a wallet a "DeFi wallet"?

Any self-custody wallet can use DeFi, but a DeFi wallet adds features for it: dApp connectivity, transaction simulation, approval management, swaps and bridges, and position tracking across protocols.

Is MPC safer than a seed phrase?

It removes the single point of failure of a seed phrase and makes recovery easier, but adds dependence on the MPC protocol's correctness and on the provider holding a share. Neither is strictly safer; they fail differently.

Should I build on ERC-4337 or EIP-7702?

They are complementary. ERC-4337 provides the infrastructure (bundlers, paymasters, EntryPoint); EIP-7702 lets existing EOAs adopt smart account code. Many wallets support both: new users get smart accounts, existing users can upgrade in place.

How do wallets prevent drainer attacks?

By simulating transactions, decoding permits and approvals, checking addresses and domains against threat lists, and warning clearly before risky actions. No check is perfect, so layered defenses matter.

Can a wallet earn revenue?

Commonly through integrator fees on swaps and bridges, premium features, or fiat on-ramp partnerships. Disclose fees in the transaction preview.

How should a wallet store keys on mobile?

In the platform's secure hardware where possible (Secure Enclave or Android Keystore), encrypting seeds with keys that never leave secure storage, with biometric gating for signing.