About 10 years ago, any public Wi-Fi in a café was considered a don't connect to it at all zone. Today the situation is different: most websites use HTTPS by default, mobile apps use certificate pinning, and banks add extra layers of protection. But safer does not mean safe.
What is actually protected in 2026
The HTTPS connection between your device and a bank/exchange website is encrypted and authenticated. Intercepting and tampering with data over Wi-Fi becomes a difficult task: an attacker would have to either break the certificate chain or exploit flaws in a specific application. This is possible, but it's no longer turn on sniffer, read other people's passwords.
What remains vulnerable
DNS-spoofing. On a compromised Wi-Fi hotspot, the operator can spoof DNS responses: instead of the real bank.com, you are redirected to a similar phishing site. If you are used to entering your login and password automatically without looking, you will fall for it.
SSL-stripping in certain cases. Less common, but possible against older apps that do not perform strict validation.
Captive portal with MitM. The log in to Wi-Fi page that requires access to your traffic for registration could theoretically tamper with traffic during authentication.
Vulnerabilities in your device. If your phone or laptop is not updated, there may be exploits in the Bluetooth stack or Wi-Fi driver. These compromise not just one site but the entire device.
What to do in real life
VPN for critical operations. A good VPN (Mullvad, ProtonVPN, NordVPN) encrypts all your traffic to its servers. An attacker on the local network can only see an encrypted stream.
Use mobile internet for sensitive operations. Cellular networks are not perfect, but the attack threshold is higher than for public Wi-Fi. If you can make a transfer over 4G/5G instead of café Wi-Fi, choose 4G/5G.
Check the URL. Before entering your password, make sure the address bar shows the real bank domain, not something similar. HTTPS with a green padlock is not a guarantee that the site is genuine: phishing sites also use HTTPS.
Do not pay on sites without HTTPS. In 2026, such sites are almost nonexistent, but if you encounter one, do not enter anything.
Interim conclusion
Payments over public Wi-Fi are not taboo, but they are not a neutral action either. Basic discipline (VPN + URL checking + not disabling screen lock) makes the risk acceptable. Paying at a café with a PIN on the terminal can be done without much concern—that is a completely different channel unrelated to the Wi-Fi network.
A virtual card in 2 minutes
Pay for subscriptions, AI tools, travel, and international stores. Top up via USDT-TRC20 with no acquiring fees.