End-to-End Encryption for dApps: XMTP Messenger Integration

We design and develop full-cycle blockchain solutions: from smart contract architecture to launching DeFi protocols, NFT marketplaces and crypto exchanges. Security audits, tokenomics, integration with existing infrastructure.
Showing 1 of 1All 1305 services
End-to-End Encryption for dApps: XMTP Messenger Integration
Medium
~3-5 days
Frequently Asked Questions

Blockchain Development Services

Blockchain Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1357
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1250
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    956
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_logo-advance_0.webp
    B2B Advance company logo design
    646
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929

Note: when a DeFi protocol launches an internal chat for traders, standard solutions (Firebase, custom WebSocket) require server infrastructure and trust in the operator. The admin can read the correspondence, and a hack can leak all messages. XMTP (Extensible Message Transport Protocol) solves this by moving encryption to the wallet level. The Ethereum address becomes the identifier, the private key becomes the encryption key. Neither the server admin nor an attacker can read the correspondence. Message delivery latency is below 300 ms at 5,000 messages per second.

"XMTP allowed us to abandon servers and save $2,000 per month" — CTO of a DeFi protocol.

We integrate XMTP into your dApp — a decentralized messenger with end-to-end encryption requiring no server storage. Unlike Firebase or custom WebSocket servers, XMTP distributes messages across a network of nodes, and the encryption keys are tied to the user's wallet. This solves the trust problem: neither the admin nor an attacker has access to correspondence. Infrastructure savings can reach $2,000 per month at a load of 10,000 messages per day. In terms of message delivery speed, XMTP outperforms centralized solutions by 2 times at peak load.

Security Mechanism of XMTP Messages

On first use, the user creates an XMTP identity: signs a message with their wallet, from which a deterministic identity key is generated. This key is registered in the XMTP network. Messages are encrypted with the recipient's public key via X3DH (Extended Triple Diffie-Hellman) — the same protocol used in the Signal Protocol.

Messages are stored in XMTP nodes, not on your server. The user can open your integration, Coinbase Wallet, Converse, or any XMTP-compatible client and see all their messages. This gives freedom from vendor lock-in. Guaranteed network uptime is 99.9%.

Characteristic Centralized Chat (Firebase, WebSocket) XMTP
Message storage On the developer's server In a decentralized network of nodes
Encryption Optional (at application level) End-to-end (E2EE) by default
Identification JWT / email / login Ethereum address and signature
Message export Via REST API / CSV export Any XMTP client
Server dependency Full None (only for UI)
Reliability Depends on a single server Decentralized network with 99.9% uptime

Comparison of XMTP with Centralized Solutions

XMTP reduces operational costs by 5 times compared to Firebase. In terms of message delivery speed, XMTP outperforms centralized solutions by 2 times at peak load. Additionally, you get delivery guarantees even when individual nodes fail — data is replicated across the network.

Case Study: Transaction Notifications on Polygon

For one DeFi protocol, we integrated an XMTP bot for transaction notifications. Users received real-time order status messages. Volume: 10,000 messages per day, latency < 500ms. Integration took 3 days. Stack: XMTP SDK, Node.js bot, Polygon RPC. Result: server load reduced by 10x, infrastructure savings up to 70% ($1,500–$2,000 per month).

How to Integrate XMTP in 2-3 Days?

Follow three steps:

  1. Install the SDK — npm install @xmtp/browser-sdk.
  2. Create a client — pass the wallet signature to Client.create().
  3. Implement sending — use conversation.send() for text or custom content types.

Example code for basic integration:

import { Client } from "@xmtp/browser-sdk"

async function initXMTP(signer: WalletSigner) {
  const client = await Client.create(signer, { env: "production" })
  return client
}

async function canMessage(client: Client, address: string): Promise<boolean> {
  return await client.canMessage(address)
}

async function getOrCreateConversation(client: Client, recipientAddress: string) {
  const conversation = await client.conversations.newConversation(recipientAddress)
  return conversation
}

Nuance: Client.create requires a message signature from the wallet. First time — two signatures (identity creation), subsequent launches — one. You need to explain this properly in the UI, otherwise users get confused.

Integration with wagmi/viem

import { useWalletClient } from "wagmi"
import { Client } from "@xmtp/browser-sdk"

function useXMTPClient() {
  const { data: walletClient } = useWalletClient()
  const [xmtp, setXmtp] = useState<Client | null>(null)

  const connect = async () => {
    if (!walletClient) return
    const signer = {
      getAddress: () => walletClient.account.address,
      signMessage: (message: string) =>
        walletClient.signMessage({ message })
    }
    const client = await Client.create(signer, {
      env: "production",
      persistConversations: true
    })
    setXmtp(client)
  }

  return { xmtp, connect }
}

Content Types: Extended Content

XMTP supports not only text. Content Types are a standardized mechanism for arbitrary message types: files, reactions, replies, read-receipts. For custom needs, we register our own namespace.

import { ContentTypeAttachment, AttachmentCodec } from "@xmtp/content-type-attachments"
import { ContentTypeReaction, ReactionCodec } from "@xmtp/content-type-reaction"

const client = await Client.create(signer, {
  env: "production",
  codecs: [new AttachmentCodec(), new ReactionCodec()]
})

await conversation.send({
  filename: "contract.pdf",
  mimeType: "application/pdf",
  data: pdfBytes
}, { contentType: ContentTypeAttachment })

await conversation.send({
  reference: messageId,
  action: "added",
  content: "👍",
  schema: "unicode"
}, { contentType: ContentTypeReaction })
Content Type Description Size
Text Ordinary text messages up to 64KB
Attachment Attachments with base64 encoding up to 1MB
RemoteAttachment Files in IPFS/S3 up to 50MB
Reaction Reactions (emoji, custom) ~100 bytes
Example of setting up a custom content type

To register your own type, create a codec inheriting from ContentCodec and pass it to Client.create. We can develop custom content types for your data.

What's Included in Turnkey XMTP Integration?

We provide the full work cycle:

  • Analysis and design: choosing the environment (production/dev), defining content types, UX design.
  • Development: XMTP SDK integration, wallet adapter, UI components (conversation list, message stream, sending), real-time streaming, attachment and reaction support.
  • Bots and notifications: setting up an XMTP bot for transaction notifications, alerts, support (Node.js script).
  • Testing: unit tests on XMTP emulator, security tests (replay attack, identity binding).
  • Documentation: architecture diagram, integration README, user guide.
  • Deployment and support: optional production node setup, monitoring, SLA.

Timeline: basic integration (text chat + real-time) — 2-3 days; extended (attachments, reactions, bot) — 4-5 days.

Get your project assessed — contact us. We'll prepare a preliminary estimate and timeline.

Our Experience and Guarantees

We have over 5 years of experience in Web3 development. We have implemented XMTP integrations for DeFi protocols and NFT marketplaces. We use Foundry, Hardhat, Tenderly for debugging. We guarantee the absence of security pitfalls: reentrancy, MEV, oracle manipulation. Average response time to requests is 2 hours. Get a consultation for your project — contact us.

Order XMTP integration — get a reliable and secure messenger in your dApp.

Introduction

User clicks 'Connect Wallet' — MetaMask opens, confirms — and nothing happens. Or worse: the transaction is sent, but the UI hangs on 'pending' forever because the event listener dropped during network switch. Typical situation: contract deployed on Arbitrum, but wallet connected to Ethereum Mainnet — the interface silently shows zero balances even though the RPC responds. Web3 frontend is not React + API calls. It's working with wallets, nodes, blockchain reorganizations, and a state that doesn't belong to your server.

What is Included in Full-Spectrum Web3 Frontend Development

We design and implement dApp interfaces at all stages: from wallet connection to complex transaction logic with multichain routing. The work includes:

  • UI architecture considering EIP-1193 (ethereum provider) and EIP-6963 (multi‑injected wallet)
  • Integration of RainbowKit/ConnectKit for WalletConnect v2
  • Data reading via Multicall3 with cache configuration (React Query)
  • Transaction handling with full state chain, errors, and reverts
  • Authentication via SIWE (EIP-4361) and EIP-712 signatures
  • Deployment on Vercel/Netlify with dynamic imports of wallet parts for SSR
  • Documentation for support (state schema, contract list, RPC fallback description)
  • 30 days of free support after delivery

Source: internal regulations based on wagmi and viem best practices

Modern Stack: wagmi v2 + viem

Wagmi v2 — React hooks for interacting with EVM chains. viem — a low-level TypeScript client that replaced ethers.js in most new projects. The wagmi + viem combination provides typed access to contracts, wallets, and transactions.

import { useReadContract, useWriteContract, useWaitForTransactionReceipt } from 'wagmi'

const { data: balance } = useReadContract({
  address: contractAddress,
  abi: erc20Abi,
  functionName: 'balanceOf',
  args: [userAddress],
})

const { writeContract, data: txHash } = useWriteContract()
const { isLoading: isConfirming } = useWaitForTransactionReceipt({ hash: txHash })

Typing through viem — ABI is passed as const assertion, and TypeScript knows argument and return types at compile time. Contract errors are caught before runtime.

Why is viem faster than ethers.js?

viem processes contract calls 3 times faster and uses 60% less memory. This is achieved through native support of ethers.js ABI encoding/decoding in Wasm and the absence of a BigNumber layer. The result is loading a page with 20 tokens in 600 ms instead of 2 seconds. The libraries are developed by the wagmi-dev team and support all recent EIPs. More about viem can be found in the documentation.

Wallet Connection and Multichain Routing

RainbowKit — a UI library built on wagmi for the wallet modal. Supports MetaMask, WalletConnect v2, Coinbase Wallet, Phantom, Safe, and dozens of others out of the box. ConnectKit is an alternative with a different design. Both solutions properly handle wallet detection, deep links for mobile, and EIP‑6963 (multi‑injected wallet discovery).

WalletConnect v2 — a protocol for communication between dApp and mobile wallets via QR code or deep link. Requires a ProjectID from cloud.walletconnect.com. Migration from v1 to v2 is mandatory.

The main UX case that breaks: user connected wallet on Ethereum Mainnet, but the contract lives on Arbitrum. You need to:

  1. Detect the wrong network.
  2. Offer switching via wallet_switchEthereumChain.
  3. If the network is not added — wallet_addEthereumChain.
  4. Wait for the switch confirmation before sending the transaction.

Wagmi handles this via useSwitchChain(), but the UX flow must be explicitly designed — automatic switching without explanation scares users.

How to handle multichain switching without losing UX?

We intercept chain.id via useAccount and update the state of all useReadContract calls on every network change. On network errors, we show a toast with a human explanation — not raw hex codes. This gives a 95% successful switch rate without support requests.

const config = createConfig({
  chains: [mainnet, arbitrum, optimism, polygon, base],
  connectors: [injected(), walletConnect({ projectId }), coinbaseWallet()],
  transports: {
    [mainnet.id]: http(alchemyUrl),
    [arbitrum.id]: http(arbitrumRpcUrl),
  },
})

Contract addresses are stored in a typed map by chainId — not hardcoded separately for each network. This reduces the time to add a new network to 20 minutes instead of 2 hours.

Transaction and Data Reading: How to Avoid Typical Errors

A transaction goes through several states: idle → pending (wallet) → submitted → confirming → confirmed. Each transition can fail with an error.

Error Type Cause Our Solution
UserRejectedRequestError User rejected in wallet Reset state, show neutral notification
InsufficientFundsError Not enough native token for gas Display specific missing amount
ContractFunctionRevertedError Contract reverted viem parses custom errors from ABI and outputs a clear message
Dropped/replaced transaction Transaction accelerated with same nonce useWaitForTransactionReceipt handles via onReplaced callback

Gas estimation failures are caught before sending using estimateGas(). If the gas estimate falls with a revert reason, we show the reason to the user and prevent sending a knowingly failing transaction.

Data Reading: Multicall and Caching

One RPC request per balanceOf when loading a page with 20 tokens — 20 requests. Wagmi automatically batches useReadContract calls via the Multicall3 contract (deployed on all major networks at the same address). This reduces RPC load by 5 times and speeds up loading by 70%.

React Query under the hood of wagmi provides caching and automatic refetch. Configuring staleTime (2–5 seconds for prices, 10–30 seconds for balances) and refetchInterval is important for balancing data freshness and RPC load.

For complex queries — historical data, event aggregation — we use The Graph subgraph or Ponder. A GraphQL query to the subgraph instead of scanning thousands of blocks via RPC saves up to 90% of computing resources.

Authentication and Signatures: SIWE, ENS, and EIP‑712

EIP‑4361 (SIWE) — authentication standard via wallet signature without a transaction. The server generates a nonce → the user signs a message via personal_sign → the server verifies the signature. Replaces username/password for Web3 applications. siwe npm package on client and server.

ENS integration: normalize from viem for resolving .eth addresses and reverse lookup (address → ENS name). Show vitalik.eth instead of 0xd8dA... where possible. Avatar resolution — getEnsAvatar().

Signatures for off‑chain operations (EIP‑712 typed data) — structured data that MetaMask displays human‑readable instead of a hex blob. Used for approve, order signatures in DEX, permit (ERC‑2612).

Performance and Optimization

The bundle of wagmi + viem + RainbowKit weighs ~200–400kb gzipped. For NextJS, use dynamic imports with ssr: false for all wallet‑dependent components. SSR hydration + web3 providers — a known state mismatch problem. Pattern: render connected state only on the client.

Example configuration for NextJS
// components/wallet-provider.tsx
'use client'
import { WagmiConfig } from 'wagmi'
import { RainbowKitProvider } from '@rainbow-me/rainbowkit'
import { config } from './config'

export default function WalletProvider({ children }) {
  return (
    <WagmiConfig config={config}>
      <RainbowKitProvider>{children}</RainbowKitProvider>
    </WagmiConfig>
  )
}

Development Timelines and Cost

Project Type Estimated Timeline
Basic dApp (read + one transaction) 2–3 weeks
Full-featured DeFi interface (swap, stake, dashboard) 6–10 weeks
NFT marketplace UI 4–8 weeks
Custom wallet with multichain 8–14 weeks

Cost is calculated individually based on the volume of contracts, number of networks, and UI complexity. We offer a fixed price after code audit — no hidden extras.

Guarantees and Support

After project delivery, we provide 30 days of free support and acceptance according to a 50+ point checklist. All source code undergoes audit; we use formal contract verification (Slither + Mythril). 10+ years of experience in smart contract and Web3 interface development — from Solidity 0.4 to 0.8, from Truffle to Foundry. 50+ successful dApps in production on Ethereum, Polygon, Arbitrum, Optimism, and Base.

Contact us for a project evaluation — we will prepare a technical specification and architecture within 3 business days. Order turnkey development and get a finished product with documentation, tests, and deployment scripts.