HostDeFi › Is Rabby safe
Is Rabby safe? The wallet built to warn you before you sign
Rabby is the rare wallet whose safety story is written in public audit PDFs, not marketing copy: DeBank's self-custody MetaMask fork, a security engine that simulates and screens every transaction before you sign — and a published record of real findings (weak password policy, sync issues, an EIP-7702 race) that got fixed and re-audited.
What Rabby is
Rabby is the multi-chain EVM wallet built by DeBank, the DeFi portfolio-tracking team — a MetaMask fork re-shaped for the multi-chain DeFi user: it auto-selects the right chain per site, and its headline feature is a pre-signature security engine. Before you approve anything, Rabby simulates the transaction, shows the resulting balance change, and screens the contract against a risk ruleset. Custody shape: classic self-custody — keys live on your device under your password; DeBank holds no copy.
The security engine — and its limits
The engine answers the failure mode this corpus keeps documenting — the signature the user couldn't read. Before signing, Rabby shows what the transaction actually does to your balance and flags risk patterns: unverified contracts, contracts with no prior interaction, addresses matching known-phish lists, sends to addresses you've never touched. That is a genuinely better defense than a raw calldata blob — but it is a warning layer, not a verdict: a novel phish that simulates cleanly sails through, and a flagged transaction can still be signed. It narrows the dominant risk class; it cannot close it.
The audit record — the real differentiator
Rabby's audits are public, dated, and repeated — rare among wallets:
| Date | Auditor / scope | Notable findings |
|---|---|---|
| Aug 2024 | SlowMist — mobile iOS/Android | Baseline mobile review |
| Oct 2024 | Least Authority — mobile app | Key-derivation/password-strength flag |
| Dec 2024 | Least Authority — Chrome extension | Modular security architecture credited; crypto-method and password-hardening recommendations |
| Aug 2025 | SlowMist — extension re-audit | Post-change review |
| Sep 2025 | Least Authority — extension + mobile | Account-sync issue; EIP-7702 transaction race |
The honest reading: findings exist — a missing password-strength check on the key-derivation password, an extension↔mobile account-sync bug, a potential race creating EIP-7702 transactions — and they get remediated across cycles. That is what maintained security looks like; it is not a 'no issues' record, it is a 'issues found and fixed in public' record.
Custody in full
Rabby is self-custody in the plain wallet sense: seed/keys generated and encrypted locally, unlocked by your password, auto-locked when idle, sensitive memory cleared on lock. No Rabby server holds spend authority. The mobile app's optional encrypted cloud backup of the seed is an opt-in convenience — the one place a copy of your key leaves the device, so it deserves an explicit decision, not a default toggle.
The risk stack, ranked
| Layer | Frequency | Fix |
|---|---|---|
| Signature phishing (novel phish that simulates cleanly) | Dominant daily vector, partially screened | You — read the simulated outcome, heed flags, verify domains |
| Extension supply-chain | Rare but high-impact | You — install only the verified publisher build |
| Seed/key loss | Constant, user-side | You — offline seed backup; cloud backup as an explicit choice |
| MetaMask-fork inheritance | Continuous, upstream | Rabby-side patch cadence |
| Custodial drain | Not applicable — nothing held | — |
What self-custody means in practice here
Because Rabby never holds keys, its security story splits cleanly into what the software does and what only you can do. The software side is genuinely better than the class average: simulated outcomes before signing, chain auto-selection removing wrong-network errors, hardware-wallet passthrough for Ledger/Keystone/OneKey, encrypted local storage, auto-lock and memory clearing. The user side is unchanged by any of it: the seed phrase exists exactly once, on whatever you wrote it down on; the signature warnings are advisory — a determined signer can dismiss every flag; and the extension build you installed is the real attack surface, which is why the publisher identity on the store listing is worth checking once rather than trusting search results repeatedly.
The fork caveat
One honest structural note: Rabby is a MetaMask fork, which cuts both ways. It inherits a codebase with the deepest real-world hardening in the wallet class — and it inherits every upstream bug class, plus whatever drift accumulates between fork and upstream. The audit cadence is the answer: repeated third-party reviews against a moving codebase are what keep a fork honest.
Where Rabby stands
No documented user-fund incident, an unusually transparent audit trail with named findings and re-audits, a security engine aimed at the failure that actually drains wallets — and the standing caveats of every self-custody wallet: keys are your problem, phishing is still your problem, and the fork inherits MetaMask's upstream surface. The dated read: the wallet-shape benchmark for 'warn the user before signing' — safer on the dimension it was built for, identical on every dimension it shares.
The verdict in one line: Rabby is self-custody with the best-documented security record in the wallet class — real audits with real findings, fixed — plus a pre-sign warning engine that narrows phishing risk without eliminating it.
Frequently asked questions
Is Rabby a legitimate wallet?
Yes — Rabby is the multi-chain EVM wallet built by DeBank, the DeFi portfolio team. It is a self-custody MetaMask fork whose differentiator is a pre-signature security engine: every transaction gets simulated and screened for threats before you approve it. It has also been audited repeatedly — Least Authority (Oct 2024 mobile, Dec 2024 extension, Sep 2025 both) and SlowMist (Aug 2024 mobile, Aug 2025 extension) — which is a real, checkable security record, not a claim.
Who holds your keys on Rabby?
You do — Rabby is self-custody in the classic wallet shape: keys are generated and encrypted on your device, unlocked by your password, and DeBank/Rabby hold no copy. That means no custodian can be drained — and nobody can recover the wallet if you lose the seed and the device. The mobile app adds an optional encrypted cloud backup of the seed, which is convenience you opt into, not custody.
What is Rabby's pre-sign security engine?
Rabby's defining feature: before you sign, it simulates the transaction and shows the resulting balance change, then runs the contract through a risk engine — flags like unverified contracts, contracts with no prior interaction, known-phish addresses, or a transaction sending tokens to an address you've never touched. It answers the exact failure this corpus documents (the signature you didn't read) by making the outcome legible first. It is a warning layer, not a guarantee — a malicious contract that simulates cleanly can still slip through.
Have there been any Rabby security incidents?
No public user-fund-draining incident is documented. What is documented — unusually, because the audits are public — are audit findings: a weak-password policy flag (no strength check on the key-derivation password), an account-synchronization issue between extension and mobile, and a potential race in EIP-7702 transaction creation. Those get fixed across audit cycles, which is the honest shape of a maintained wallet: findings exist, get remediated, get re-audited.
What are Rabby's real risks?
In order: (1) phishing sites that phish a signature — the security engine warns on flagged patterns but cannot catch a well-made novel phish; (2) extension supply-chain — a browser wallet is only as safe as its installed build, so verify the publisher; (3) seed/key loss — self-custody means no recovery path; (4) the MetaMask-fork inheritance — Rabby inherits MetaMask's codebase, so upstream bugs and fork-drift bugs both apply. The engine narrows the biggest risk class; it doesn't close it.
Is Rabby safer than MetaMask?
On the dimension Rabby was built for — pre-sign legibility — yes: it shows simulated outcomes and risk flags that MetaMask only later began adding. On custody both are the same self-custody shape. The honest differences: Rabby adds the security engine and multi-chain auto-switching; MetaMask has the larger install base and battle-hours. Rabby's public audit record is unusually good for a wallet — but 'safer' ends at 'warns you better', not 'protects you'.