Wallet apps will upload your IP information—really? + Risks, explained one by one.
Is it real? Half true, half false. You need to tell the difference by “which scenario.”
Scenario Will they know your IP?
You open the TP Wallet app to send/receive coins or check balances ⚠️ Yes. The app is centralized. The moment you log in, the server knows who you are—your IP, your phone number.
You click a DApp link inside TP Wallet (e.g., Uniswap / some DeFi) ⚠️ Yes. The DApp’s RPC node will record your IP.
You directly send on-chain transfers in TP Wallet, without using a DApp ❌ Not directly. But if you use TP’s default RPC node, the node operator can still see it.
Key point: It’s not that TP “intentionally uploads your IP”—any wallet must go through RPC nodes and centralized servers, and the architecture means your IP will be recorded. This is the same for MetaMask, Trust Wallet, TokenPocket, and imToken. Saying “TP uploads your IP” is true—but saying “only TP does” is wrong. All wallets work this way.
The real risks
1. IP + on-chain address = real identity exposure
If police/regulators want to find you, they first check withdrawal records from exchanges → lock your实名 identity → then trace your IP/device in one go.
On-chain addresses are anonymous by themselves, but at the moment of deposits/withdrawals, the real name + device IP are already bound.
2. RPC nodes know all calls
Every transaction you sign, every DApp you connect to, and every address you check goes through the node.
The node operator (the wallet company/Infura/Alchemy) can theoretically analyze all of your behavior.
3. Phone permissions
TP Wallet requests access to your contacts/camera/location permissions (depending on the version).
Once you grant permission, data at the phone level is also exposed (which trading apps you installed, which IP ranges you used).
4. Being required to hand over data
Under compliance requirements in Hong Kong, the United States, and the EU, wallet companies have an obligation to cooperate with law enforcement.
All traces in your TP Wallet could theoretically be requested and accessed:
#tp