EN
“TON't Connect!: NOTe on securing TON Wallets”
In this article, we are looking into the ways DApp developers are able to exploit customization features and architecture flaws of TON Connect Protocol to impersonate legitimate DApps / Wallets, or even exploit vulnerabilities present in Wallets that target TON blockchain.
- Wallet Impersonation
- DApp Impersonation
- Redirects from trusted context
- UI Redressing
- XSS: Sensitive data leak from Storages
- XSS: Sensitive data leak via API requests



