Open app

NexFlow › Is Rabby safe

Is Rabby safe? The wallet built to warn you before you sign

Rabby is the rare wallet whose safety story is written in public audit PDFs, not marketing copy: DeBank's self-custody MetaMask fork, a security engine that simulates and screens every transaction before you sign — and a published record of real findings (weak password policy, sync issues, an EIP-7702 race) that got fixed and re-audited.

Updated September 28, 2026 · By the NexFlow editorial desk · Sources linked throughout; vendor claims labeled.

What Rabby is

Rabby is the multi-chain EVM wallet built by DeBank, the DeFi portfolio-tracking team — a MetaMask fork re-shaped for the multi-chain DeFi user: it auto-selects the right chain per site, and its headline feature is a pre-signature security engine. Before you approve anything, Rabby simulates the transaction, shows the resulting balance change, and screens the contract against a risk ruleset. Custody shape: classic self-custody — keys live on your device under your password; DeBank holds no copy.

The security engine — and its limits

The engine answers the failure mode this corpus keeps documenting — the signature the user couldn't read. Before signing, Rabby shows what the transaction actually does to your balance and flags risk patterns: unverified contracts, contracts with no prior interaction, addresses matching known-phish lists, sends to addresses you've never touched. That is a genuinely better defense than a raw calldata blob — but it is a warning layer, not a verdict: a novel phish that simulates cleanly sails through, and a flagged transaction can still be signed. It narrows the dominant risk class; it cannot close it.

The audit record — the real differentiator

Rabby's audits are public, dated, and repeated — rare among wallets:

DateAuditor / scopeNotable findings
Aug 2024SlowMist — mobile iOS/AndroidBaseline mobile review
Oct 2024Least Authority — mobile appKey-derivation/password-strength flag
Dec 2024Least Authority — Chrome extensionModular security architecture credited; crypto-method and password-hardening recommendations
Aug 2025SlowMist — extension re-auditPost-change review
Sep 2025Least Authority — extension + mobileAccount-sync issue; EIP-7702 transaction race

The honest reading: findings exist — a missing password-strength check on the key-derivation password, an extension↔mobile account-sync bug, a potential race creating EIP-7702 transactions — and they get remediated across cycles. That is what maintained security looks like; it is not a 'no issues' record, it is a 'issues found and fixed in public' record.

Custody in full

Rabby is self-custody in the plain wallet sense: seed/keys generated and encrypted locally, unlocked by your password, auto-locked when idle, sensitive memory cleared on lock. No Rabby server holds spend authority. The mobile app's optional encrypted cloud backup of the seed is an opt-in convenience — the one place a copy of your key leaves the device, so it deserves an explicit decision, not a default toggle.

The risk stack, ranked

LayerFrequencyFix
Signature phishing (novel phish that simulates cleanly)Dominant daily vector, partially screenedYou — read the simulated outcome, heed flags, verify domains
Extension supply-chainRare but high-impactYou — install only the verified publisher build
Seed/key lossConstant, user-sideYou — offline seed backup; cloud backup as an explicit choice
MetaMask-fork inheritanceContinuous, upstreamRabby-side patch cadence
Custodial drainNot applicable — nothing held—

What self-custody means in practice here

Because Rabby never holds keys, its security story splits cleanly into what the software does and what only you can do. The software side is genuinely better than the class average: simulated outcomes before signing, chain auto-selection removing wrong-network errors, hardware-wallet passthrough for Ledger/Keystone/OneKey, encrypted local storage, auto-lock and memory clearing. The user side is unchanged by any of it: the seed phrase exists exactly once, on whatever you wrote it down on; the signature warnings are advisory — a determined signer can dismiss every flag; and the extension build you installed is the real attack surface, which is why the publisher identity on the store listing is worth checking once rather than trusting search results repeatedly.

The fork caveat

One honest structural note: Rabby is a MetaMask fork, which cuts both ways. It inherits a codebase with the deepest real-world hardening in the wallet class — and it inherits every upstream bug class, plus whatever drift accumulates between fork and upstream. The audit cadence is the answer: repeated third-party reviews against a moving codebase are what keep a fork honest.

Where Rabby stands

No documented user-fund incident, an unusually transparent audit trail with named findings and re-audits, a security engine aimed at the failure that actually drains wallets — and the standing caveats of every self-custody wallet: keys are your problem, phishing is still your problem, and the fork inherits MetaMask's upstream surface. The dated read: the wallet-shape benchmark for 'warn the user before signing' — safer on the dimension it was built for, identical on every dimension it shares.

The verdict in one line: Rabby is self-custody with the best-documented security record in the wallet class — real audits with real findings, fixed — plus a pre-sign warning engine that narrows phishing risk without eliminating it.

Frequently asked questions

Is Rabby a legitimate wallet?

Yes — Rabby is the multi-chain EVM wallet built by DeBank, the DeFi portfolio team. It is a self-custody MetaMask fork whose differentiator is a pre-signature security engine: every transaction gets simulated and screened for threats before you approve it. It has also been audited repeatedly — Least Authority (Oct 2024 mobile, Dec 2024 extension, Sep 2025 both) and SlowMist (Aug 2024 mobile, Aug 2025 extension) — which is a real, checkable security record, not a claim.

Who holds your keys on Rabby?

You do — Rabby is self-custody in the classic wallet shape: keys are generated and encrypted on your device, unlocked by your password, and DeBank/Rabby hold no copy. That means no custodian can be drained — and nobody can recover the wallet if you lose the seed and the device. The mobile app adds an optional encrypted cloud backup of the seed, which is convenience you opt into, not custody.

What is Rabby's pre-sign security engine?

Rabby's defining feature: before you sign, it simulates the transaction and shows the resulting balance change, then runs the contract through a risk engine — flags like unverified contracts, contracts with no prior interaction, known-phish addresses, or a transaction sending tokens to an address you've never touched. It answers the exact failure this corpus documents (the signature you didn't read) by making the outcome legible first. It is a warning layer, not a guarantee — a malicious contract that simulates cleanly can still slip through.

Have there been any Rabby security incidents?

No public user-fund-draining incident is documented. What is documented — unusually, because the audits are public — are audit findings: a weak-password policy flag (no strength check on the key-derivation password), an account-synchronization issue between extension and mobile, and a potential race in EIP-7702 transaction creation. Those get fixed across audit cycles, which is the honest shape of a maintained wallet: findings exist, get remediated, get re-audited.

What are Rabby's real risks?

In order: (1) phishing sites that phish a signature — the security engine warns on flagged patterns but cannot catch a well-made novel phish; (2) extension supply-chain — a browser wallet is only as safe as its installed build, so verify the publisher; (3) seed/key loss — self-custody means no recovery path; (4) the MetaMask-fork inheritance — Rabby inherits MetaMask's codebase, so upstream bugs and fork-drift bugs both apply. The engine narrows the biggest risk class; it doesn't close it.

Is Rabby safer than MetaMask?

On the dimension Rabby was built for — pre-sign legibility — yes: it shows simulated outcomes and risk flags that MetaMask only later began adding. On custody both are the same self-custody shape. The honest differences: Rabby adds the security engine and multi-chain auto-switching; MetaMask has the larger install base and battle-hours. Rabby's public audit record is unusually good for a wallet — but 'safer' ends at 'warns you better', not 'protects you'.

NexFlow is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a NexFlow product