SlowMist said that it is necessary to be alert to the phishing risk of Web3 wallet WalletConnect. On January 30, 2023, the SlowMist security team discovered that the improper use of WalletConnect on the Web3 wallet may have a security risk of being phished. This problem exists in the scenario of using the built-in DApp Browser + WalletConnect in the mobile wallet app. When some Web3 wallets provide WalletConnect support, there is no restriction on which area the WalletConnect transaction pop-up window will pop up, so a signature request will pop up on any interface of the wallet. When the user leaves the DApp Browser interface and switches to other interfaces of the wallet such as Wallet and Discover in the example, in order not to affect the user experience and avoid repeated authorization, the connection of Wallet Connect is not disconnected at this time, but at this time the user It may be misoperation due to the sudden signature request pop-up window initiated by the malicious DApp, which may lead to the transfer of assets by phishing. The core of this security issue is whether the user should continue to automatically pop up windows to respond to requests from the DApp Browser interface after switching the DApp Browser interface to other interfaces, especially sensitive operation requests. Because the blind pop-up response after crossing the interface can easily lead to user misoperation. This involves a security principle: after WalletConnect is connected, after the wallet detects that the user has switched the DApp Browser interface to another interface, it should not process the pop-up request from the DApp Browser.