A portfolio manager tracking assets across multiple client wallets, a family member managing an elder’s digital estate, or an auditor verifying holdings for compliance all face the same constraint: they need visibility into balances and transactions without control over the funds themselves. Holding private keys for accounts you do not directly manage introduces operational risk, audit complications, and potential liability. The alternative—relying on public blockchain explorers or requesting screenshots—is cumbersome and error-prone.
Rabby Wallet addresses this use case through watch-only wallet functionality, allowing users to add and monitor Ethereum and EVM-compatible addresses without importing or storing the associated private keys. Because the wallet is self-custodial and open-source, the monitoring happens client-side without submitting address data to external tracking services. This approach lets advisors, trustees, and stakeholders maintain real-time portfolio visibility while the actual signing authority remains with the account owner, creating a cleaner separation between viewing and control.
Why watch-only wallets separate viewing from control
A traditional wallet stores private keys, which give complete authority to approve transactions. Every wallet interface—whether browser-based, mobile, or hardware—ultimately depends on these keys to sign and broadcast transactions to the blockchain. For many use cases, that all-or-nothing model is appropriate: you control a personal account, so you hold the keys and make decisions.
Watch-only mode inverts the privilege model. The wallet displays balances, transaction history, token holdings, and network activity for addresses you specify, but it stores no private keys and cannot initiate transactions. This is particularly useful when multiple people need different levels of access. A financial advisor needs to see a client’s portfolio to make recommendations but should not be able to execute trades. A parent managing their child’s educational fund needs transparency about growth but should not accidentally withdraw the assets. An auditor verifying an organization’s treasury holdings should be able to generate reports without touching the accounts.
The Rabby wallet extension supports this pattern by letting users add addresses via public key only—either by pasting the address directly or scanning a QR code. Because Rabby is self-custodial and operates as a browser extension, the wallet does not store your address list on external servers. Your watch-only accounts remain client-side, visible only in your browser unless you export or share them explicitly. This avoids the surveillance model where a wallet provider builds a list of addresses you monitor, creating a privacy gap between viewing and control.
Public blockchain networks make this possible. Unlike a private bank account where the institution controls all visibility, Ethereum and EVM-compatible chains publish all balances and transaction histories publicly. A watch-only address is simply a consumer of data that is already available on the chain. The security benefit comes from the clear separation: no key material flows through the monitoring interface, so a compromised extension or device cannot authorize transactions it has no cryptographic authority over.
Setting up watch-only wallets in Rabby
Creating a watch-only wallet in Rabby begins with accessing the wallet switcher—the interface that lets you manage multiple accounts. In the Rabby wallet extension, you will see an option to add a new wallet or account without importing a seed phrase or private key. Instead, you select the watch-only or address-only option and provide the public address of the account you wish to monitor.
The address can come from several sources. If the account owner is using a hardware wallet or another self-custodial wallet, they can simply share their address. If you are monitoring a multisig contract or DAO treasury, you use the contract address. If the account is already in use elsewhere, you do not need to do anything special—just copy the address and paste it into Rabby. The wallet will immediately begin displaying balances across supported EVM networks, including Ethereum mainnet, Arbitrum, Optimism, Polygon, and others that are configured in your Rabby wallet extension.
Because Rabby automatically selects networks based on where an address has activity, you may not need to manually configure anything. When you add a watch-only address, Rabby queries the public blockchain to detect which networks contain assets or transaction history associated with that address. This automatic detection reduces configuration friction and helps prevent mistakes where you forget to check a particular network.
For advanced use cases, you can also add custom RPC endpoints if you prefer to query a private or local node rather than relying on public infrastructure. This is relevant for organizations running their own Ethereum infrastructure or users with strong privacy preferences about which nodes see their monitoring requests. The distinction between public RPC endpoints and private ones is important: every address you query reveals information about your interest in that account, so using a private endpoint or your own infrastructure can reduce that metadata leakage.
What watch-only wallets can and cannot do
Can do: Watch-only wallets display real-time balances for tokens and NFTs, show transaction history and pending transactions, alert you to network changes, provide token prices and portfolio valuations, and allow you to simulate and analyze transactions before someone else signs them. If you paste in a transaction that was broadcast by the account owner, Rabby’s transaction interpretation and risk-checking features will parse it, warn about suspicious patterns, and show you exactly what will happen when the transaction is approved. This pre-sign security checking is valuable for auditors or advisors who need to verify that a proposed action matches its stated intent.
Cannot do: Watch-only wallets cannot sign transactions, cannot approve token spending, cannot execute swaps, cannot interact with smart contracts, and cannot export or reveal any private keys (because they do not have any). If someone tries to use a watch-only address to approve a transaction, the wallet will refuse and explain that signing is not available for this account. You cannot transfer funds, stake assets, or make any change to the blockchain that requires authorization.
This asymmetry is the point. A watch-only wallet is read-only by design, not by accident or permission. It is not a restricted view of a full account; it is a fundamentally different kind of account that has no signing capability. This means you can distribute watch-only access broadly without worrying that an assistant, intern, or contractor will accidentally or maliciously move funds. The technology enforces the boundary rather than relying on policies or training.
For compliance and governance contexts, this enforcement is valuable. A board member monitoring treasury accounts, an auditor verifying holdings, or a compliance officer tracking exposures can each have Rabby wallet extension configured with all the relevant addresses without any possibility of unauthorized transaction approval. If governance rules require multiple signatures or specific approval workflows, watch-only monitoring feeds information into those decision processes without bypassing them.
Portfolio tracking workflows with multiple watch-only accounts
Many advisors and portfolio managers work with dozens or hundreds of addresses. Some belong to clients, some to multisig wallets, some to liquidity pools or yield strategies. Rabby allows you to add multiple watch-only accounts and label them, making it possible to organize a complex portfolio view. You can group accounts by client, by strategy, by risk category, or by any other taxonomy that makes sense for your workflow.
Token management becomes more powerful when you are monitoring related accounts together. If a client has assets on Ethereum mainnet, Arbitrum, and Polygon, you can see the total balance across all three networks. Rabby’s balance change preview feature shows you what will happen if a pending transaction confirms, letting you verify that a swap or transfer produces the expected outcome without executing anything yourself. This is especially valuable when monitoring smart contract interactions where the actual outcome may differ from the user’s expectation due to slippage, price movement, or contract behavior.
For organizations with treasury accounts or investment funds, watch-only monitoring creates an audit trail within your own interface. You can export transaction history, take screenshots for compliance reports, and maintain a record of portfolio composition over time. Because Rabby operates as a self-custodial wallet with no central server, you are not creating a dependency on a provider that might change terms, get acquired, or go offline. The data is on the public blockchain; Rabby is simply a client that lets you view it securely.
If you are managing accounts for multiple clients or on behalf of an organization, watch-only wallets also simplify the security model. You do not need to handle private keys, seed phrases, or hardware wallet backups for each account. You only manage your own local wallet security. The account owners maintain full control and custody. This separation is cleaner for liability and governance: you are a viewer and analyst, not a custodian.
Security considerations for watch-only monitoring
Watch-only wallets eliminate private key risk but do not eliminate all risks. First, the addresses you monitor are linked in your client-side database. If someone compromises your device, they can see the complete list of accounts you are tracking, the balances, and the transaction history. This metadata—knowing that you monitor these specific addresses—may be sensitive in some contexts. If you are managing accounts for clients, a breach could expose the portfolio composition of multiple clients at once.
Second, when you query blockchain data—balances, transaction history, token prices—your queries go to an RPC endpoint, which can log the addresses you ask about. If you use Rabby’s default public RPC endpoints, those requests are associated with your IP address and may be aggregated by analytics services. This is less sensitive than revealing private keys, but it is still metadata that identifies your interest in particular accounts. For high-value portfolios or sensitive scenarios, using a private RPC or your own infrastructure is worth the additional setup cost.
Third, watch-only monitoring assumes that the addresses themselves are authentic. If you copy a wrong address or scan a compromised QR code, you will begin monitoring the wrong account. There is no cryptographic proof that the address belongs to who you think it does. In practice, this is mitigated by getting addresses directly from the account owner through a trusted channel, but it is worth remembering that the address is the only identifier.
Fourth, the Rabby wallet extension itself must be genuine. A counterfeit version could present false balances, hide transactions, or collect the addresses you add. Always download Rabby from the official rabby.io domain and verify that you are installing the legitimate extension, not a phishing or impersonation version. Check the extension ID and publisher name in your browser’s extension manager. This verification step is non-negotiable when managing client assets or sensitive portfolios.
Using watch-only wallets for auditing and compliance
Auditors and compliance officers use watch-only wallets to verify that an organization or individual holds assets as claimed. Rather than requesting bank statements or taking third-party attestations at face value, an auditor can add the organization’s blockchain addresses directly to Rabby and see the balances independently. This is especially powerful for DAOs, treasuries managed by smart contracts, multisig wallets, and organizations holding substantial crypto assets.
The public nature of blockchain data means that balances are verifiable without trusting the organization to provide accurate information. You can cross-check the addresses with public documentation—a website, governance proposal, or official announcement—and then monitor them directly. If an organization claims to hold a certain amount of ETH or stablecoins, you can verify this in real time without intermediaries.
For compliance reporting, Rabby’s transaction history export feature and balance snapshots provide documentation that holdings were verified at specific points in time. Many compliance frameworks require periodic attestations that funds are in custody. A watch-only wallet lets you generate those attestations independently rather than relying on potentially biased internal reporting. You can also set up alerts for large transfers or unusual activity, monitoring the account continuously rather than through periodic audits.
The open-source nature of Rabby also supports compliance workflows. Your IT security team can audit the code, verify that no private keys are being transmitted, and confirm that the extension operates as claimed. This transparency is valuable when you are evaluating tools for sensitive financial or audit roles. You are not relying on a vendor’s promises; you can inspect the implementation directly.
Integrating watch-only wallets with other tools and workflows
Watch-only monitoring in Rabby is often part of a larger portfolio management stack. You might use watch-only accounts in Rabby for real-time checking and alerts, while also using specialized tools for accounting, tax reporting, or performance analysis. The advantage of Rabby is that it provides transparent, on-chain data without proprietary databases or subscription services. If you need to export holdings for a tax accountant or performance report, you can use Rabby’s data as the ground truth.
For teams managing cryptocurrency on behalf of organizations, watch-only wallets can be combined with approval workflows. One person monitors the account and prepares proposed transactions; another person with signing authority reviews and approves them. Rabby’s transaction interpretation features make the review process clearer by showing exactly what a transaction will do before it is signed. This separation of duties—one person proposing, another approving—can be enforced through a watch-only monitoring interface.
You can also use watch-only wallets to track liquidity positions, yield strategies, and collateral in DeFi protocols. If a client or organization is providing liquidity to a decentralized exchange or staking assets in a yield protocol, you can monitor the smart contract interactions and see how the position changes over time. Rabby’s transaction interpretation helps you understand what is happening inside complex smart contract calls, making it easier to track strategies that are not simply buy-and-hold.
When watch-only is not enough: escalating to full wallet access
Some situations require more than monitoring. If you need to make transactions on behalf of an account owner, watch-only monitoring is not sufficient. In those cases, you have several options. The safest is to use a multisig wallet, where multiple parties (perhaps you and the account owner, or you and another authorized person) must approve transactions together. This gives you signing authority only as part of a group, not unilaterally.
Another option is for the account owner to set up a hardware wallet and then import it into your Rabby wallet extension for signing, but keep the seed phrase secure with the owner. This way, you can see the account and prepare transactions in Rabby, but the actual signature happens on a separate hardware device. The owner remains in control of the cryptographic material; you manage the interface and workflow.
If you do need to hold private keys for an account you manage on behalf of someone else, the watch-only wallet approach becomes a useful complement. You can import the full private key into a separate account within Rabby for signing, while also maintaining watch-only copies for quick reference or to monitor related accounts. This gives you two views of the same data—one with full control and one without—which can reduce the likelihood of accidentally using the wrong account for a sensitive operation.
Frequently asked questions
How do I add a watch-only wallet to Rabby Wallet Extension?
Open your Rabby wallet extension, go to the wallet switcher or account menu, and select the option to add a new account. Choose “watch-only” or “address-only,” then paste the public address or scan its QR code. Rabby will immediately begin displaying balances and transaction history for that address across all networks where it has activity. No private key or seed phrase is required.
Can I sign transactions using a watch-only wallet in Rabby?
No. Watch-only wallets are read-only by design. You can view balances, transaction history, and simulate transactions, but Rabby will not allow you to approve or sign any transaction from a watch-only address. This is a security feature: if you need to authorize transactions, you must use a full wallet with private key access, ideally with multisig or hardware wallet oversight.
Is my list of watch-only addresses private when I use Rabby wallet extension?
Your address list is stored client-side and not sent to Rabby’s servers, so the wallet provider does not see it. However, when you query blockchain data for those addresses, your RPC endpoint may log the addresses you are asking about and associate them with your IP address. For maximum privacy, consider using a private RPC endpoint or your own node. Always download Rabby from the official rabby.io domain to ensure the extension is genuine.