Rabby against Phantom: who is reading the transaction before you sign it
Two browser wallets that are not MetaMask, judged only on the seconds before you sign. One publishes its whole extension under MIT. The other bought the security team it was already using. What each vendor's own documents will and will not support.
Almost nobody loses a wallet to cryptography. They lose it in the two seconds between a dapp asking for a signature and a thumb hitting approve. That screen is the product. So: two browser wallets that are not MetaMask, on one question only — when the approval sheet appears, who wrote what is on it, and can you check their work?
This is not a news story and does not pretend to be. Nothing below turns on something that happened this week; it turns on two documents that have been sitting in public, and the different bets they describe.
The file on each
Rabby’s bet: you can read it
Rabby’s README opens by calling itself an open-source browser plugin for the DeFi ecosystem, built for a multi-chain experience. The repository’s LICENSE file carries the MIT text, copyright 2021-present Rabby, with one narrow reservation: the brand name and logo stay Rabby’s own. Fork the signing logic all you like; do not ship it wearing the same face.
For a self-custody reader that licence is the argument. The code that renders the approval sheet and decides what to warn you about sits on a public branch. You are not required to read it. Somebody is, and does not need permission.
A candid limit: the wallet’s documentation site did not answer an automated request, and its marketing site returned a script-rendered shell with no readable feature text. So the claims repeated across comparison blogs — pre-sign simulation, contract risk scoring, an approval manager — are not sourced here. That is what we could verify, not a claim the features are absent.
The README is also honest about a security problem in disguise. Many dapps detect a generic injected Ethereum object and label it MetaMask, so a Rabby user clicks “connect to MetaMask” and connects to Rabby. Rabby’s suggested fix is to show both buttons. Live with that mislabelling and you stop reading the connection dialog — the reflex phishing sites exploit.
Phantom’s bet: someone good is reading it for you
Phantom went the opposite direction and bought the eyes. In its own announcement of the Blowfish acquisition the company says it acquired the trust and safety platform offering advanced fraud protection to crypto users, and that the Blowfish team joined Phantom. Its stated record, in Phantom’s words: 2.8 million scams prevented, 1.3 billion transactions scanned, more than $18 billion of assets protected. Those are the acquirer’s figures for the thing it bought, unaudited here.
The announcement names the mechanism, which matters more than the totals: detailed transaction and message previews that warn before you submit, and alerts before you engage with a malicious site. Phantom CEO Brandon Millman said the deal gave the company the best security team in crypto.
Two things follow, both in the same post. Blowfish notified existing customers the service had been sunset — an integration once available to other wallets became one company’s advantage. And the richer approval screen, with simulation previews the company said could be fully relied upon before signing, is described there as what Phantom would build, not as what it had shipped. We have not verified the current state of that screen; do not read this as saying it never arrived.
Verdict
So ask the site’s usual question. If your threat is a malicious contract dressed as a mint and you want the wallet to argue with you, the one with a dedicated fraud team folded into it has the stronger institutional answer. If your threat is the vendor itself — a policy change, a quiet telemetry decision, a company that gets bought — the MIT-licensed extension is the one whose behaviour cannot change behind your back without somebody being able to see it. Do not let a polished approval screen imply anyone has authorised or licensed either of them.
Both bets fail the same way. Install only from the vendor’s own linked listing, and check the publisher before you pin it. Revoke approvals you no longer use. Slow down on the screen: read the contract address, read the amount, treat an unlimited allowance as a decision rather than a default. The seed phrase rules do not change for a browser extension — never typed into a keyboard, never photographed, never stored in a cloud, never given to support — and the same reasoning about whose promise you are holding applies to what “self-custody” is doing in a vendor’s sentence. Crypto assets are high risk and nothing here is financial advice. Read the README, read the announcement, pick the failure mode you can live with.