Skip to content

Wren features and boundaries

This page explains Wren’s product boundary. It does not replace the exact protocol and qualification documents in the Wren repository.

Wren desktop receives requests from browser dapps and native applications. It reviews and handles supported requests in one desktop interface.

Wren can review:

  • account access and permissions;
  • network additions and network switches;
  • transactions, including calldata and token approvals;
  • personal messages, typed data, SIWE-shaped sign-in messages, and token permits;
  • non-atomic EIP-5792 wallet calls; and
  • selected simulation effects and call-trace evidence from the configured RPC.

Wren normalizes, checks, simulates when available, reviews, signs, and broadcasts supported transactions. It does not make an unsafe request safe by changing its meaning. Review the destination, account, network, amounts, approvals, and calldata yourself. Compare the request with the hardware-device display when the signer supports it.

Queued transactions are read-only while an earlier transaction is active. After Wren submits the current transaction, it opens the next request for review and continues confirmation and reorganization monitoring in the background.

Simulation is evidence from a configured RPC. It is not a guarantee of execution or outcome. Use another trusted review when a simulation fails, is unavailable, is truncated, or is incomplete. Wren requires explicit consent for dangerous legacy eth_sign requests.

Support depends on the request and signer. Wren rejects unsupported transaction types and fields instead of silently rewriting them. Type-3 blob transactions are unsupported. EIP-5792 calls are sequential and non-atomic. Permit and SIWE support is review and consent support; Wren does not authenticate a web session or execute a permit contract for you.

Permit reviews show the account, token, amount, network, spender, expiry, and signature type. Token approval reviews keep the requested, custom, unlimited, and revoke choices with the resulting allowance. The editor stays open while Wren refreshes the review. Approval and permit editors show Your balance. Use balance sets a custom allowance with full token precision. Wallet privacy hides the balance and disables this shortcut. Select Retry if the balance cannot be read. Transaction reviews group the decoded action, estimated asset changes, editable fees and nonces, contract data, and signer action. A failed background refresh does not replace a usable review result. Wallet Calls reviews show the starting nonce, maximum batch fee, and transaction fee controls.

See How Wren protects approvals, RPC compatibility, and supported standards for the exact method boundary.

Wren can create an encrypted local wallet with a new 12-word recovery phrase or Ethereum private key. It uses the operating system’s secure random generator, requires password and backup confirmation, and shows the new secret only during setup. Wren clears an unchanged copied secret from the clipboard after one minute, but clipboard history or another program may retain it.

The dashboard can prepare a contract deployment from complete EVM creation data and an optional native value. Wren does not compile Solidity or Vyper in this tool. It gathers gas, simulation, and nonce evidence from the configured RPC, then uses the ordinary transaction review, signer, and single-broadcast lifecycle.

Wren can also publish Solidity or Vyper source for an existing contract or a confirmed Wren deployment. It reads supported compiler, Foundry, or Hardhat build files locally and checks them against the selected chain and contract. It accepts integrity-bearing Vyper 0.4.3 solc_json artifacts and checks each source checksum. A matching saved submission opens its status. Sourcify is the primary publication service. Etherscan V2 is an optional fallback on supported networks. Published source is public, and Wren cannot withdraw it.

Wren gives each connected app a separate permission record. A permission can bind an app to selected accounts, permitted wallet methods, enabled chains, the app identity, and an expiry. Wren rechecks standing and queued requests against that record.

An app’s network route is separate from every other app’s route. An authorized app can switch its own route to an enabled network. The switch does not change another app’s route. Wren deliberately has no shared wallet-wide network selection.

Open Control center → Connected apps to review retained access and default networks. Revoke access when an app no longer needs it. A browser origin and an authenticated local client have different source identities and revocation paths.

Two apps use Wren at the same time. Each app has a separate account permission and network route. There is no shared network switch.

See Manage accounts and addresses and Manage networks and RPC endpoints for the related controls.

Wren Companion injects Wren’s EIP-1193 provider into supported browser pages and announces it through EIP-6963. It identifies the browser origin and carries the request to Wren desktop.

Companion is not a wallet, signer, or approval authority. It does not need a recovery phrase, private key, keystore password, or hardware-wallet PIN. Wren desktop keeps the account permission, review, signing, and broadcast authority.

Companion 0.1.3 uses mutually authenticated protocol 3. During setup, Pair this Companion shows a six-digit code. Compare it with the code in Wren before you select Accept. Select Decline for an unexpected request or a code mismatch. Matching codes authenticate the installations. They do not make a compromised computer or browser profile safe.

Companion shows Wren is unavailable when it cannot reach the desktop. It shows Update Wren when the versions do not match. It shows Wren identity changed when the saved desktop identity changes.

Do not bypass an update warning. Use Reset pairing only when you expect the identity change. Then compare a new code.

Companion 0.1.3 needs Wren 0.1.11 or a later compatible build. Update the extension separately. Both browser stores currently list 0.1.2, which remains compatible with Wren 0.1.11.

Chrome and Brave can install Companion from the Chrome Web Store. Firefox users can install Companion from Firefox Add-ons. Verified Chrome and Firefox archives remain available from the Companion release. The packages are not interchangeable. Companion has no telemetry or remote code. Read the Companion security policy and privacy policy for its browser boundary.

While Wren is open, it monitors direct transactions and standard token transfers for saved addresses on enabled, connected networks. Activity submitted elsewhere shows Outside Wren. Monitoring starts at the current chain position and resumes after reconnects. Earlier history and internal-call traces are not included.

Select an Activity row to see its type, result, app, network, account, and exact times. Supported transaction entries can recover methods and transfers from transaction data and confirmed receipts. Wren uses local calldata decoding when remote metadata is unavailable. It checks the retained hash, sending account, and canonical block when available, and labels incomplete evidence instead of guessing.

Wren keeps a small reference ledger for the 90-day Activity window. It stores the activity identity, account, origin, chain, submitted hashes, and an optional canonical block reference. It does not store fetched transaction bodies, calldata, opaque decoded bytes, recipients, or amounts. The ledger is not included in profile backups. See Review Activity for the user controls and clearing boundary.

Open the wallet account selector, then select Add account. Choose an account type lists these current options:

  • Hardware devices: GridPlus Lattice1, Ledger device, and Trezor device.
  • Create new: a new 12-word Recovery phrase or Ethereum Private key. Wren stores the new local signer in an encrypted signer worker after backup confirmation.
  • Import existing: Recovery phrase, Private key, and Keystore file (JSON). Wren stores imported local signer data in encrypted signer workers.
  • Watch-only: Watch account. It can monitor an address but cannot sign.

Linux x64 is the qualified release target. Windows x64 is an unsigned, unqualified preview. macOS x64 and arm64 are ad-hoc signed, unnotarized, and unqualified previews without physical qualification. Trezor Safe 7 and Model One have user-test evidence with Connect 10. Model One has documented signing limitations. Ledger and GridPlus Lattice1 have implemented paths and automated coverage, but they have not been physically requalified. Other Trezor models share implementation and automated bridge coverage but have not been physically requalified. Trezor Safe 7 Bluetooth is unsupported.

These labels describe project evidence. They are not security certification. Review Signer and platform support before you rely on a signer.

Wren has no first-party hosted backend. Its default services are explicit and replaceable.

  • Built-in networks use PublicNode for EVM RPC by default. The selected RPC receives your IP address and each request, which can include queried addresses, calldata, and submitted signed transactions. Choose Custom or Local for a network when you need another endpoint.
  • Wren requests USD prices from DefiLlama and GeckoTerminal. Price requests send your IP address, network IDs, and token IDs, but no wallet address or balance. See price coverage and refresh timing.
  • The embedded Send app loads reviewed content through IPFS.io by default. Wren verifies the pinned directory CID before it activates the content.
  • The selected Earn surface requests its fixed vault catalog from Yearn Kong. It does not send account addresses, balances, or transaction details in that catalog request.
  • Token artwork comes from a reviewed CoinGecko asset host. Wren does not load arbitrary remote artwork.

Explorers and protocol sites open only after you select them. Wren does not contact Pylon or send account addresses to an NFT indexer. The inherited NFT panel is disabled. See Network data and privacy and the threat model for more boundaries.

Wren stores contacts locally. A saved contact name can appear during request review. It does not change the address or signed payload.

The current Earn surface provides a local, allowlisted Yearn catalog on Ethereum, Base, and Katana. It can show positions and run bounded deposit, withdraw, approval, and revoke workflows. A watch-only account can inspect positions but cannot transact. Yearn vaults still have smart-contract and strategy risk. Use the exact Yearn Earn boundary for supported products and workflow evidence.

See Manage tokens and Use Earn for task instructions.

Open Settings → Security → Recovery to use Export encrypted backup or Restore encrypted backup. Wren encrypts the profile backup with a password that you choose. Wren cannot recover that password.

Inspect a backup before you replace the current profile. Test restoration with non-valuable accounts. Keep the backup separate from the computer that runs Wren.

Wren also supports a one-time Import a Frame profile flow. It copies validated configuration and encrypted signer files through private staging. It does not read or change the active Frame profile. Use the installation tutorial for the required order and checks.

The current release does not claim support for:

  • macOS, Windows, or Linux arm64 as platform-qualified desktop targets. Windows x64 and macOS x64/arm64 are available only as unqualified previews;
  • Trezor Safe 7 Bluetooth;
  • smart accounts, ERC-4337 user operations, mobile, or WalletConnect; or
  • atomic EIP-5792 execution, EIP-4844 type-3 blob transactions, or externally supplied EIP-7702 authorization input.

Read Advanced execution boundaries before you depend on an advanced transaction path. Read Signer and platform support before you depend on a device or operating system.