How apps are checked
Apps and games on token pages are built and run by their developers, not by Chain Daddy. Here is exactly what we check, and what we can't. Read both before you sign anything an app asks for.
What we check
- Each version is reviewed. A reviewer approves every version of an app before any token page can add it or run it.
- The code you run is the code we reviewed. Each time an app loads, its code is checked against the fingerprint (SHA-256) of the reviewed version.
- Apps are kept apart from your account. An app runs in a sandbox, apart from Chain Daddy: it can't read your Chain Daddy session or act as Chain Daddy.
- Your wallet hears from us first. When an app asks for a signature or a transaction, Chain Daddy shows you on its own screen what is being asked and which contract it is for, before your wallet sees it.
- Token-moving signatures stay with the contracts an app declared. A signature that could move your tokens (a permit, a transfer authorization, an order, a delegation) for a contract the app didn't declare is blocked: you see "Signature blocked", and the app can't reach your wallet again on that page.
- You see what you're signing. An allowed request is spelled out in plain words, in red when it grants something: the amounts in token units, who receives them, and what Chain Daddy checked and can't. Continue waits a moment (a little longer for a grant) so a stray tap can't approve it.
- No blind signatures. An app can't ask your wallet for a raw
eth_signorpersonal_sign. - Unreviewed builds can't ask. A developer's unreviewed build can't ask for signatures or transactions at all.
- Your tap, every time. An app goes fullscreen only on your tap, and for its first three seconds a strip names the app, says it's a third-party app and offers Exit. Uploading and copying to your clipboard need your tap and a permission the app declared. Leaving the page needs your tap, and links open in a new tab.
What we can't check
- The app's own servers. An app may talk to its developer's own servers, and its page lists them. What those servers do is up to the developer.
- What a contract does. We can see which contracts an app asks you to sign for or send to. We can't tell you what a contract will do with your signature or your tokens.
- What an app loads later. We review the version you run, but an app can load content from its own servers after that review.
- The developer's intent. A review can't tell us what a developer means to do.
What that means for you
- Whatever you sign or send from your wallet is your decision, and a blockchain transaction can't be undone. Read what your wallet and the page show you before you approve.
- Our review isn't an endorsement, an audit or a guarantee. The Terms say so, and say that each app's developer answers for it.
- If an app looks wrong, write to support@chaindaddy.io. We can turn an app off on every page at once.
Found a vulnerability? See Reporting a security issue.