Skip to main content
btc$86,229+3.21%eth$2,753+2.48%usdt$0.9997+0.01%bnb$776.73+1.37%xrp$1.54+3.28%usdc$0.9999-0.00%sol$121.98+3.47%trx$0.3345-0.86%figr_heloc$1.02-0.47%zec$1,382-2.08%hype$90.08+1.19%doge$0.0971+2.82%link$14.39+1.03%xmr$547.55+0.39%wbt$85.98+3.04%usds$0.9996+0.01%btc$86,229+3.21%eth$2,753+2.48%usdt$0.9997+0.01%bnb$776.73+1.37%xrp$1.54+3.28%usdc$0.9999-0.00%sol$121.98+3.47%trx$0.3345-0.86%figr_heloc$1.02-0.47%zec$1,382-2.08%hype$90.08+1.19%doge$0.0971+2.82%link$14.39+1.03%xmr$547.55+0.39%wbt$85.98+3.04%usds$0.9996+0.01%
CoinPulse

Rabby

Software wallet·2021·Singapore·rabby.io

Rabby is a self-custody wallet for Ethereum and other EVM chains, launched in 2021 by the DeBank team and released as open-source software under the MIT license. It runs as a browser extension and as desktop and mobile apps, and it is built around security: before you sign, Rabby simulates the transaction and shows the balance changes, token approvals and risk flags it detects, so you can catch a malicious contract before it drains you. Your keys stay on your device — DeBank cannot access them. Rabby's own key storage has not been breached, though its Swap contract was exploited in 2022, after which affected users were reimbursed.

Key facts
Launched
2021, by the DeBank team (DeBank Global Pte. Ltd.)2021
Type
Non-custodial (self-custody); keys stored locally, open-source under the MIT license
Platforms
Browser extension (Chrome, Brave, Edge, Firefox) and desktop and mobile apps
Networks
Ethereum and other EVM-compatible chains
Signature feature
Pre-sign transaction simulation and risk checks showing balance changes and approvals before you confirm · source

What is Rabby?

Rabby is a self-custody Web3 wallet for Ethereum and EVM-compatible chains, built and maintained by the DeBank team and launched in 2021. It runs as a browser extension for Chrome, Brave, Edge and Firefox and as desktop and mobile apps, and it is fully open-source under the permissive MIT license, so its code can be inspected by anyone.

Its defining feature is what happens before you sign. Rabby simulates each transaction and shows a plain-language preview of the outcome — the exact balance changes, the token approvals you are granting, and any risk flags it detects on the contract or address — and it switches to the right network automatically. That pre-sign preview is aimed squarely at the way most wallet losses happen: people approving a transaction they could not actually read.

Is Rabby safe?

Rabby is non-custodial, so your private keys are generated and stored locally and DeBank cannot move or recover your funds. Its design leans into safety: the pre-sign transaction simulation, contract and address risk scanning, and built-in approval management exist specifically to help you avoid the phishing and blind-signing traps that account for most wallet drains. Being open-source means the code is public and open to outside review. As always, the recovery phrase is yours to protect — no one at Rabby can ask for it or reset it.

The wallet's key storage has not been breached to drain users. The one real incident sits in a feature: about a month after Rabby's Swap launched in 2022, its swap contract accepted an arbitrary target and calldata without validation, letting an attacker pull tokens from wallets that had approved that contract. Roughly $200,000 was taken; Rabby reimbursed affected users, and anyone who had used the old Swap was urged to revoke the approval. A separate, ongoing hazard is fake 'Rabby' apps and sites built to steal recovery phrases — install only from rabby.io or official stores. The Swap incident is recorded below.

Incident record

Rabby Swap contract exploit2022-10-11

About a month after Rabby's Swap feature launched, its swap contract passed a user-supplied target address and calldata to an external call without validating them, so an attacker could make the contract pull tokens from any wallet that had approved it. Roughly $200,000 was drained (around 114 ETH and 179 BNB). The flaw was in the Swap contract, not in Rabby's key storage. Rabby reimbursed affected users, and users who had approved the old contract were urged to revoke the approval.

Recovery confirmedLoss $200,000Recovered $200,000Source

In our ratings

Where we score Rabby against its peers on open data. The number lives there, not here.

Compare with

Frequently asked

Is Rabby safe?+

Rabby is a non-custodial, open-source wallet whose keys stay on your device, and it adds pre-sign transaction simulation and risk checks to help you avoid malicious approvals. Its key storage has not been breached; the one real incident was a 2022 exploit of its Swap contract (about $200,000), after which affected users were reimbursed. Watch for fake 'Rabby' apps and only install from rabby.io.

How is Rabby different from MetaMask?+

Both are non-custodial EVM wallets, but Rabby is built around pre-transaction safety: before you sign, it simulates the transaction and shows the balance changes, approvals and risk flags it detects, and it switches networks automatically. It is open-source under the MIT license and built by the DeBank team. The trade-off is that it is EVM-only and newer than MetaMask.

Who made Rabby and is it open-source?+

Rabby is built and maintained by the DeBank team (DeBank Global Pte. Ltd.) and launched in 2021. It is fully open-source under the permissive MIT license, so its code is public and can be independently reviewed — one of the reasons it is often described as a security-focused wallet.

What changed

  • 2026-09-28Profile created: what Rabby is (open-source EVM wallet with pre-sign transaction simulation), its non-custodial safety model, and the 2022 Rabby Swap contract exploit with a confirmed-reimbursement verdict.