ChainCensus
ChainCensus · BestChecked July 2026

Best Software Wallets in 2026

Five software wallets scored on evidence you can open in a browser tab: licence files, audit reports, package manifests and incident postmortems. We haven't tested them, and we say so.

Daniel Merritt · Data desk, ChainCensusPublished 16 Jul 2026 · 13 min read
No affiliate links on this page — every link goes straight to the official product site.How we rank →

Every "best wallet" list tells you which one feels nicest to use. That is the one thing we cannot tell you, because we have not installed, funded or tested any of these wallets. What we did instead: open the licence files, count the audit reports and check their dates, read the package manifests, and pull the incident postmortems. Everything below links to the document it came from.

That method has an obvious blind spot and one real advantage. It cannot judge how a wallet feels. It also cannot be charmed by a nice onboarding flow — and it surfaces things a hands-on review never would, like the fact that the most popular crypto wallet on earth is not open source, or that one of these wallets names four audit firms on one page and four different firms on another.

Key takeaways
  • MetaMask is not open source — its licence caps free use at 10,000 monthly active users, "as reasonably determined by ConsenSys in its sole discretion"
  • Rabby is the only wallet here that commits its audit reports to its own repo, in dated year folders running 2021 to 2025
  • Zerion names four auditors on its security page and four different auditors in its README, and links no report from either
  • One browser bug, CVE-2022-32969, hit MetaMask, Phantom, Brave and xDefi at once — the flaw was in Chromium and Firefox, not in any wallet
  • Swap fees are the real price: MetaMask charges 0.875%, Phantom 0.85%, Zerion 0.67%. Sparrow has no swap at all

MetaMask is not open source

This is the finding that surprised us most, and it takes ten seconds to check. Open MetaMask's LICENSE file. It is not MIT. It is a proprietary licence, copyright ConsenSys Software Inc., 2022, that grants you rights only for "Non-Commercial Use" — defined as meeting one of three tests, the third being that "the number of monthly active users of the Resulting Program across all versions thereof and platforms globally do not exceed 10,000 at any time." Each test is "reasonably determined by ConsenSys in its sole discretion."

The source code is public. That is not the same as open source, and the distinction matters: you may read MetaMask's code, but you may not fork it into anything that gets popular. The independent tracker Walletbeat marks MetaMask as failing its FOSS test for exactly this reason. Phantom fails it too, and more comprehensively — "The source code for Phantom is not available to the public."

Rabby's LICENSE is an MIT body with a trademark clause bolted on: "Brand name and logo of Rabby is copyright reserved. You can not use brand name or logo of Rabby for your re-publish software." Walletbeat declines to count that as FOSS. We think that is harsh — the clause restricts the brand, not the code — but it is a judgement call, and you should know a serious tracker made the opposite one.

The cleanest licences here belong to the two wallets nobody argues about: Sparrow is Apache 2.0, and Zerion's extension is GPL-3.0.

When was the last audit, and can you read it?

"Audited by leading security firms" is the cheapest sentence in crypto. The useful questions are narrower: audited when, by whom, and where is the PDF?

Rabby is the only wallet here that answers all three without you having to ask. Its audits/ folder sits in the repo with year subfolders from 2021 to 2025. The 2025 folder holds two reports — a SlowMist audit dated 21 August 2025 and a Least Authority extension audit dated 3 September 2025. There is no 2026 folder, so the most recent audit is about ten months old.

Phantom publishes an audit-reports repo too. It contains two PDFs: Kudelski Security from 2021 and Least Authority from July 2024. Two reports, five years, latest two years old — for a wallet whose code you cannot read yourself.

MetaMask has by far the longest history: 15 audits listed stretching from a Cure53 pentest in August 2017 to a Consensys Diligence review of the mUSD contract in August 2025. Curiously, that page is not complete. Least Authority published a MetaMask seed-phrase implementation audit in October 2025 that does not appear on MetaMask's own list. The newest MetaMask audit is one the vendor doesn't advertise.

Then there is Zerion, which is where documentation-based scoring earns its keep. Its README says: "Leading security firms have independently audited the Zerion Extension: Cure-53, Secfault, SlowMist, and Zokyo." Its security page says the wallet was "audited by professional security firms, including Cube53, Secfault Security, Peckshield, and Trail of Bits." Two official Zerion surfaces, two different four-firm lists, overlapping on exactly one name — and neither links a single dated report. We are not going to guess which list is right, or whether "Cube53" is a typo. We are going to note that you cannot verify either.

Audit trails compared, July 2026
WalletReports you can openMost recentWhere they live
RabbyYear folders, 2021–20253 Sept 2025In the repo
MetaMask15 listed, 2017–2025Oct 2025 (not on its own list)Vendor page
Phantom2, everJuly 2024Public repo
Zerion0UndatedFirms named, reports absent
Sparrow0 foundNo audit page found

Read the Sparrow row carefully. "None found" is not "none exist" and it is certainly not "clean" — it means we could not find one, and we are telling you that instead of quietly leaving the row blank.

What your wallet tells its own servers

A wallet can be perfectly self-custodial and still narrate your entire financial life to a company. These are separate properties, and the marketing conflates them constantly.

MetaMask is the honest-by-necessity case. The Consensys privacy notice states that it processes "your wallet address which is processed as part of API requests (in URL parameters or bodies) when making API calls required to support the user experience" — adding that this "applies where you utilise MetaMask's default settings and configurations, which you may disable or opt-out of at any time." So: it leaks, by default, and you can turn it off. Walletbeat is blunter about the mechanism — MetaMask's unfamiliar-address warning "leaks your IP, your Ethereum address, and the recipient's Ethereum address to an external provider which can correlate them."

Rabby has the more interesting problem, because its privacy policy argues with itself. The body, written by OPCODE LABS PTE. LTD., says: "We collect device data such as information about your computer, phone, tablet, or other device you use to access the Services…your IP address (or proxy server)…" The California disclosure table on the same page marks Identifiers: NO, Commercial information: NO, Geolocation: NO. Wallet addresses and blockchain transaction data are not mentioned anywhere in the document at all. That silence is doing a lot of work for a wallet whose headline features — pre-transaction risk scanning and balance-change previews — cannot function without sending an API your addresses. Walletbeat confirms the dependency: Rabby "still critically depends on external services" to look up your ETH balance, look up ERC-20 balances, and send tokens, even when you point it at your own node.

Sparrow is the only wallet in this set that does not have to leak, and it is worth being precise about why. It rejects SPV "which has privacy implications" in favour of your own node, or an Electrum server you choose — "Fulcrum, ElectrumX, Electrs, Electrs-Esplora, EPS and BWT are all supported over SSL and built in Tor," per its features page. And it does not phone home for the one thing every other wallet phones home for: Sparrow fetches an exchange rate, then multiplies it by your balance locally. In its own words, "Your wallet balance is never shared externally."

On custody the field is level, and that is fine: Phantom ("Self-custodial means you control your funds. We never have access"), Zerion ("Your seed phrase is stored locally on your device so Zerion does not have access"), Rabby (Walletbeat: "Private key material never leaves Rabby") and MetaMask all hold keys on your device. None of these are MPC or custodial products. Self-custody is table stakes in 2026 — it is not a differentiator, and any list that scores it as one is padding.

The swap fee is the actual price

Software wallets are free. The business model is the swap button, and the spread between these numbers is larger than most people assume.

MetaMask states it plainly: "MetaMask fee: 0.875%" on its Swaps guide. On a $10,000 swap that is $87.50, on top of gas and on top of whatever the underlying route costs. That same page names 19 networks for Swaps — Ethereum, Bitcoin, Linea, Base, Solana, Tron, Polygon, BNB Chain, Arbitrum, Monad, Robinhood Chain, OP, Sei, Avalanche, zkSync Era, MegaETH, HyperEVM, Arc and Tempo — which is a Swaps list, not a wallet list; MetaMask also takes arbitrary custom EVM RPCs. It is also unusually open about routing, disclosing that it sources bridges "through aggregators (Li.fi and Socket) and providers (Hop, Celer cBridge, Polygon PoS Bridge, Squid (Axelar), Across, Stargate, Relay, Mayan, and CCTP)."

Phantom charges 0.85%, "charged on select swap pairs." Zerion charges 0.67% on both swaps and bridges, drops that to 0.25% for Premium subscribers, and exempts Gold DNA holders "completely… forever," per its fees page. Zerion then does something we have not seen another wallet do: it publishes the multisig treasury addresses the fees flow into — 0x7d20Ab6D8aF50d87A5E8DeF46e48F4d7dC2Ea5c7 for Avalanche and Optimism, 0x4a183b7ED67B9E14b3f45Abfb2Cf44ed22c29E54 everywhere else. You can audit its revenue on-chain. That is a genuinely unusual disclosure and it is why Zerion outranks MetaMask despite the audit mess.

Rabby is the gap. There is no fee documented on rabby.io, which bills itself only as "Your Go-to Wallet for Ethereum and EVM." The single figure we could find anywhere was a 0.25% claim in a Rabby post on X from July 2024. A two-year-old tweet is not a price list, so our table says "not documented" — which is itself the finding. Sparrow, meanwhile, has no swap feature at all: nothing on its features page or FAQ offers one. No swap, no swap fee, and no router contract to exploit — which brings us to the incidents.

The incidents, and what they were actually about

Every wallet old enough to matter has an incident. What separates them is where the failure was.

Rabby's is the one that should worry a #1 pick, so read it closely. On 11 October 2022, ~$200,000 was stolen — not from the wallet, but from the Rabby Swap router contract, launched less than a month earlier on 14 September. The bug had been missed by a PeckShield audit of that contract. Rabby's response was the right shape: "If you have used it, please revoke all existing approvals on all chains for Rabby Swap. For those who haven't used Swap, your wallet is safe and unaffected." Key handling was never implicated; only users with live token approvals were exposed. It remains a real mark against them, and a reminder that an audit is a snapshot, not a guarantee.

Separately, in February 2024, Apple approved a fake App Store listing called "Rabby Wallet & Crypto Solution" — a drainer that went live while the genuine Rabby app was still in review and survived four days. Reported individual losses ran to $5,000, ~14 ETH and a $40,000 ETH drain. That is an app-store failure, not a wallet vulnerability, and we score it as such.

MetaMask and Phantom share their incident with each other, and with Brave and xDefi. CVE-2022-32969, nicknamed "Demonic," is rated Moderate at CVSS 5.9 by the GitHub Advisory Database, which describes it as: "MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fields to disk." The root cause, found by Halborn in September 2021 and disclosed in June 2022, was in the browsers — they write non-password input fields to disk to support Restore Session. Type a seed phrase into a normal text field and it lands in plaintext on your drive. Exploiting it needed all three of: the phrase imported on a device no longer in your possession or already compromised, an unencrypted hard drive, and the user having ticked "Show Secret Recovery Phrase" during import. BleepingComputer reported the fixes: MetaMask 10.11.3, xDefi 13.3.8, Phantom patched in April 2022. One bug, four wallets, and the defect belonged to Chrome and Firefox. This is why we do not score wallets on whether an incident exists.

Documented wallet incidents and where the fault actually sat
IncidentDateFault sat inVerified impact
Rabby Swap routerOct 2022A swap contract audited by PeckShield~$200k; users with live approvals only
"Demonic" CVE-2022-32969Jun 2022Chromium & Firefox session restoreModerate, CVSS 5.9; hit MetaMask, Phantom, Brave, xDefi
Trust Wallet PRNGNov 2022Mersenne Twister seeded with 32 bits~$30M at risk; ~$170k lost
Trust Wallet extension v2.68Dec 2025Chrome Web Store release process2,520 addresses drained; voluntary reimbursement
Slope → Phantom seedsAug 2022Slope logging keys to a monitoring service9,231 wallets, ~$4.1M — seeds reused from Slope

The Slope row is the one people still get wrong. In August 2022, 9,231 wallets were drained of ~$4.1M over about four hours. Many victims were Phantom users, which produced a lot of "Phantom hacked" coverage. Solana's incident report is unambiguous: "Private key material from these Slope users was inadvertently transmitted by the Slope app to an application monitoring service." The affected Phantom users had reused seed phrases originally generated in Slope. Phantom's code was not at fault, and neither was Solana's — "This was not a protocol-level vulnerability."

The two we didn't rank

Trust Wallet was excluded for a specific reason: two documented incidents, three years apart, in the same browser extension.

In November 2022, Ledger's Donjon security team found that the extension's key generation used a Mersenne Twister PRNG seeded with a single 32-bit value — "the PRNG used is a Mersenne Twister, and it should not be used for cryptographic purposes." That is 2³² possible mnemonics instead of 2¹²⁸. Attackers could compute every resulting address in "a couple of hours in a single computer." Around $30 million was at risk; actual losses came to about $170,000, and Binance paid Ledger a $100,000 bounty — its maximum.

Then, on 24 December 2025, "an unauthorized and malicious version of the Trust Wallet Browser Extension (version 2.68) was published to the Chrome Web Store outside of our standard release process (without mandatory review)," per Trust Wallet's own postmortem. The company says its "Developer GitHub secrets were exposed," giving the attacker its extension source and Chrome Web Store API key, and that it has "high confidence" the incident is "likely related" to Sha1-Hulud, an industry-wide npm supply-chain attack from November — while stressing that "the investigation into the exact attack vector and sequence of events remains ongoing."

One number here needs care, because it is being widely misreported. Trust Wallet identified "2,520 wallet addresses that were affected by this incident and drained by the attackers, with approximately $8.5 million in assets impacted that can be associated with 17 wallet addresses controlled by the attacker." The blog then adds: "these attacker addresses also drained wallet addresses NOT associated with Trust Wallet and this incident." So $8.5M is the flow through the attacker's addresses, not this incident's losses. The incident figure is 2,520 addresses. Trust Wallet has "decided to voluntarily reimburse the affected users" — and notes it received over 5,000 claims for those 2,520 addresses, "indicating a significant number of duplicate or false submissions." Credit where due: that is a more candid postmortem than most. It still describes a second compromise of the same product.

Coinbase Wallet was excluded on different grounds. It became the Base App in July 2025. Ranking a product mid-rename produces a page that is wrong within a year.

Exodus and BlueWallet we looked at and set aside. BlueWallet is MIT-licensed and legitimate; Sparrow simply covers the Bitcoin slot with stronger privacy tooling. Exodus we could not score honestly — we found no primary source documenting its exchange spread, and we are not going to publish a fee range we cannot link.

What the popularity numbers say, and don't

One last data point, because it cuts against the ranking in a useful way. Chrome Web Store install counts on 16 July 2026: MetaMask 12,000,000 users, Phantom 4,000,000, Rabby 800,000, Zerion 100,000. Our top two picks are the smallest and the not-even-an-extension.

Those counts are rounded to a magnitude and cover the Chrome extension only — not Firefox, not mobile, not desktop. Sparrow has no comparable figure because it is not an extension. And they measure distribution, not safety: MetaMask is the wallet every dapp supports, which is a real reason to use it and no evidence at all about its licence, its default telemetry or its 0.875% swap fee. Popularity is the input every other list scores highest. It is the one thing on this page that tells you nothing.

ChainCensus builds live crypto datasets — fees, dead coins, government holdings — free to cite, with public methodology.

Our data
01
RabbyBest for EVM users who want to audit the claims themselves
8.4/ 10

The only wallet here with both a real open-source licence and a dated, in-repo audit trail you can read yourself.

+MIT licence body — the only candidate with a genuinely permissive code licence
+Audit reports committed to the repo in year folders, 2021 through 2025
+Hardware support provable from package.json: Ledger, Trezor, GridPlus, Keystone, OneKey, imKey
Its Swap router contract was exploited in October 2022 (~$200k) after a PeckShield audit missed the bug
Depends on Rabby's own servers to read balances even when you set a custom RPC
Privacy policy contradicts itself: says it collects your IP, then marks 'Identifiers' as not collected
No documented swap fee anywhere on rabby.io
02
SparrowBest for Bitcoin holders who run a node and care about privacy
8.2/ 10

Apache 2.0, no swap to exploit, and the only wallet here that never asks a server what you own.

+Connect your own Bitcoin node or Electrum server; Tor is built in
+Computes your balance locally — it is never shared externally
+No built-in swap means no swap fee and no router contract to attack
Bitcoin only, desktop only
No published audit report found — an absence, not a clean bill of health
Assumes you know what a PSBT and a UTXO are
03
ZerionBest for Multi-chain DeFi users who want copyleft and fee transparency
7.3/ 10

GPL-3.0 and unusually candid about fees — but it names audit firms without publishing a single report.

+GPL-3.0: the strictest copyleft licence in this set
+Publishes its fee treasury addresses on-chain — almost nobody does this
+Immunefi bug bounty up to $25,000
Two official Zerion pages name different audit firms, and neither links a report
0.67% swap and bridge fee unless you hold Gold DNA or pay for Premium
Hardware wallet support not documented anywhere we could verify
04
MetaMaskBest for People who need the wallet every dapp supports
6.6/ 10

The longest audit history in the category, attached to a wallet that is source-available, not open source.

+15 published audits going back to 2017 — nobody else comes close
+Ledger, Trezor, GridPlus and Keystone all supported
+Custom RPCs and arbitrary EVM networks; 19 networks on Swaps
Proprietary ConsenSys licence caps free use at 10,000 monthly active users
0.875% swap fee — the most expensive here
Default settings send your wallet address to Consensys APIs; opt-out exists but is not the default
05
PhantomBest for Solana-first users who accept a closed-source wallet
6.1/ 10

The best-documented Solana wallet: clear fees, real bounty, closed source, and two audits in five years.

+Publishes exactly which chains it does and does not support
+$50,000 bug bounty, the largest published here
+Swap fee stated plainly at 0.85%
Source code is not public — you cannot check any of it
Two audit reports ever; the most recent is from June 2024
Ledger is the only hardware wallet supported — Trezor and Tangem are explicitly not
All, compared
 01Rabby02Sparrow03Zerion04MetaMask05Phantom
LicenceMIT (+ trademark clause)Apache 2.0GPL-3.0Proprietary (non-commercial)Proprietary
Source code publicYesYesYesYes (not open source)No
Most recent published auditSept 2025None foundUndatedOct 2025June 2024
Audit reports actually linkedYes, in-repoNoYesYes (2 total)
ChainsEVM onlyBitcoin only50+ (vendor claim)19 on Swaps + custom RPC8, named
Hardware walletsLedger, Trezor, GridPlus, Keystone, OneKey, imKeyColdcard, Passport, Ledger, Trezor, Jade, BitBox02Not verifiedLedger, Trezor, GridPlus, KeystoneLedger only
In-app swap feeNot documentedNo swap0.67%0.875%0.85%
Run your own node / RPCCustom RPC, still calls own APIYes — Core or Electrum, Tor built inCustom RPCCustom RPC (calls default first)No
Documented incidentSwap contract, Oct 2022 (~$200k)None foundNone foundCVE-2022-32969CVE-2022-32969
How we rank

Scoring is documentation-based, not hands-on. We have not installed, funded or tested these wallets, and we won't pretend otherwise — every claim here traces to a licence file, an audit report, an official help page, a package manifest, a store listing or a public incident record, each linked inline so you can check it yourself. Weights: source-code licence and audit trail (35%), custody and key handling (25%), privacy behaviour and node independence (20%), hardware-wallet support and chain coverage (10%), swap cost and fee disclosure (10%). Incident history is scored on how the vendor responded and what was structurally at fault, not on whether an incident exists — every long-lived wallet has one. Prices, fees, versions and support pages checked 16 July 2026; wallet feature sets change constantly, so treat every figure as of that date. No vendor saw a draft, and no placement is paid.

Common questions
Is MetaMask open source?+

No. Its licence is a proprietary ConsenSys licence that permits free use only for non-commercial purposes, defined partly as staying under 10,000 monthly active users. The source is public to read, which is not the same thing.

Which software wallet is actually open source?+

Sparrow (Apache 2.0), Zerion (GPL-3.0) and Rabby (MIT, with a clause reserving the brand name and logo). Phantom's source is not published at all.

Do software wallets charge fees?+

Not for holding or sending — you only pay network gas. The charge is on in-app swaps: MetaMask takes 0.875%, Phantom 0.85%, Zerion 0.67%. Sparrow has no swap feature, so it takes nothing.

Can I use a hardware wallet with a software wallet?+

Yes, and that combination is the point: the software wallet becomes the interface while your keys stay on the device. Rabby and MetaMask both support Ledger, Trezor, GridPlus and Keystone. Phantom supports Ledger only.

Has any of these wallets been hacked?+

Rabby's swap router contract was exploited in October 2022 for around $200,000. MetaMask and Phantom were both affected by CVE-2022-32969, a browser flaw that could write a seed phrase to disk in plaintext. Neither case involved the wallet's key storage being broken directly.

Does my wallet know which addresses I look at?+

Usually yes. MetaMask's default settings send your wallet address to Consensys APIs, and Rabby depends on its own servers to read balances even with a custom RPC. Sparrow is the exception here — it computes your balance locally from your own node.