Step-by-step
- Do not install a random “GaurdWallet” from search ads. There is no official Chrome Web Store listing yet. Sideload CRX files from Telegram are malware. Use https://gaurdwallet.com/app/ for self-custody now.
- When the extension is listed, pick GaurdWallet in the dApp’s EIP-6963 list. The approval UI must show origin, decoded transaction, and full message. Reject blind signing and any page that asks for a seed.
- For swaps without a dApp, use Exchange in the web wallet. LI.FI/Jupiter quotes are proxied; you sign locally. That path does not require EIP-6963.
0 of 5 checked — start small, then scale.
Why EIP-6963 exists
Older dApps grabbed a single window.ethereum. Two extensions overwrote each other. EIP-6963 announces each wallet; the dApp shows a chooser. Rabby and MetaMask already play in that world. We will too when the MV3 build is in the stores — not before, and not via a fake listing.
| Surface | Status |
|---|---|
| Web wallet /app/ | Live — send, receive, Exchange, Trade |
| MV3 extension EIP-1193 + EIP-6963 | Built, not store-published |
| WalletConnect in the web app | Not the connect path documented here |
| Seed in a dApp form | Always a scam |
Phishing dApps mimic Connect buttons. Check the origin in the approval window. We never ask you to type 12 words to “connect”.
What the approval window shows
When the extension is in use: requesting origin, decoded transaction, full message — no blind sign. That is the product claim in llms.txt. It is not Rabby’s simulator and not the retired Wallet Guard Snap.
EIP-6963 → wallet announces itself to the dApp
EIP-1193 → eth_requestAccounts, eth_sendTransaction, …
Approval → origin + decoded tx + full message
Until store publication, keep using MetaMask/Rabby for in-page dApps if you need them, and GaurdWallet web for the vault jobs those extensions do not cover (BTC/SOL/TRX/XRP on one seed, Jupiter, LI.FI).
FAQ
Where do I download the extension today? You do not — not from the Chrome Web Store, not from a GitHub zip a stranger sent. The web wallet is the supported live app.
Is EIP-6963 the same as WalletConnect? No. WalletConnect is a different protocol (usually QR / deep link). EIP-6963 is injected-provider discovery in the browser.
Will connecting a dApp export my seed? A honest EIP-1193 connect shares an account address and then asks you to sign specific txs. A page that wants the mnemonic is not using the provider — close it.