Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


A wallet signature request asks your wallet to use an account's private key to authorize data. Before approving, verify the site independently, classify the request as a transaction, plain message, sign-in, or typed data, and confirm the action, account, chain, counterparty, assets, limits, nonce, deadline, and verifying contract.
Key Takeaways
- A signature can authorize meaningful action even when it costs no gas at signing time.
- Read the wallet prompt, not only the website button that triggered it.
- A familiar domain does not make an unexpected request safe.
- Reject opaque, truncated, mismatched, or unlimited authority you cannot explain.
- Never sign a second “cancellation” supplied by a suspicious site.
The phrase “sign this message” is too broad to decide whether a prompt is safe. A wallet can sign several kinds of data, and each carries a different effect.
| Request type | Typical purpose | Fields to inspect | Main risk |
|---|---|---|---|
| On-chain transaction | Send assets or call a contract | chain, recipient, value, contract method, token movement, gas | Immediate execution after broadcast |
| Plain message | Prove control of an address or accept text | exact readable text, domain context, nonce, purpose | Opaque bytes or reusable authorization |
| Sign-in message | Authenticate without a password | domain, URI, account, chain, nonce, issued time, expiry | Logging into an impersonating service or replay |
| Typed structured data | Permit, order, delegation, claim, vote, or protocol action | domain separator, verifying contract, spender, asset, cap, nonce, deadline | Broad off-chain authority later submitted by another party |
EIP-712 defines a standard for hashing and signing typed structured data, including domain separation and structured fields that a wallet can display. It explicitly does not provide replay protection by itself.[1] The application still needs correct nonce, deadline, chain, contract, and verification logic.
Do not reduce the decision to “transaction equals dangerous, message equals harmless.” A transaction may be a small transfer you intended, while a gasless typed signature may grant a third party permission to spend tokens later.
Use a fixed sequence so urgency cannot skip a field.
MetaMask describes signature phishing as a path where a user is induced to sign data that an attacker can use, often while the website presents a different story.[2] Treat the wallet's rendered fields as evidence, but remember that incomplete rendering can hide meaning.
Typed data is designed to be more understandable than a raw byte string, but field names alone do not guarantee safety. Read both the domain and the message.
Verify the contract address through official protocol documentation or a trusted explorer reached independently. A recognizable token symbol or domain name in the prompt can be supplied by untrusted code and is not an identity proof.
Signing itself may happen off-chain, so the wallet does not need to broadcast a transaction or charge gas. The signature can still be valuable because another party may later submit it to a contract, use it to authenticate, fill an order, exercise a permit, or prove consent.
The Ethereum Foundation's clear-signing work focuses on making transaction and approval meaning more understandable to users rather than presenting opaque hashes.[3] Clearer display reduces ambiguity, but it cannot decide whether you trust the site, counterparty, contract, asset scope, or business purpose.
Reject language such as “no gas means no risk,” “this is only verification,” or “sign now and cancel later.” Ask what exact verifier accepts the signature and what state change it can cause.
Stop when any of these comparisons fail:
Do not approve because a transaction simulation says “no balance change.” Simulation may not cover later use of a permit, future deposits, external state changes, every internal call, or a different transaction submitted with the signature.
If the page came from an email or message, compare it with the phishing protection checklist. If software initiated the prompt unexpectedly, verify that it is not a fake application.
Reject it and use an independent channel to determine what the application should request. Check official documentation, support reached from the real site, contract records, and another reputable wallet's interpretation where appropriate. Do not paste private keys, seed phrases, or sensitive signed payloads into a public decoder.
Some advanced operations genuinely contain complex data. Complexity changes the review method, not the safety threshold. Ask the application to identify the request type, contract, method, spender, affected assets, limits, and expiry. If those facts cannot be reconciled with the prompt, do not sign.
A hardware wallet can protect the private key from the connected computer, but it cannot make an opaque authorization understandable. If the device shows only an unknown hash or blind-signing warning, you lack the information needed for an informed approval.
Close the site and wallet prompt. Remove the site's connection to reduce further requests, then verify whether any earlier transaction, approval, or signature succeeded. Disconnecting is housekeeping; it is not revocation.
Preserve the URL, prompt type, visible fields, account, chain, time, and any transaction or signature identifier without exposing recovery material. Report the domain or account through the appropriate wallet, browser, platform, and abuse channels.
If you already signed, identify what authority was granted. A token approval may need safe on-chain revocation; a permit may have a nonce or deadline; a compromised seed phrase requires a new wallet; device compromise requires isolation. The wallet drainer explainer maps these mechanisms to different response paths.
Separate long-term holdings from a wallet used with new applications. Use bounded approvals, short deadlines, and task-specific accounts where the protocol supports them. Periodically review allowances and remove permissions no longer needed.
Bookmark frequently used services, keep wallet software and extensions updated, and remove duplicate or unused wallet extensions. Practice reading prompts during low-stakes actions and cancel any request whose purpose you cannot state precisely.
For teams, document approved contracts and expected signature types rather than sharing screenshots of a “normal” prompt. Contract upgrades, chain deployments, and new permit formats can make an old screenshot misleading.
The broader crypto security incident guide helps place signing risk beside key theft, exchange compromise, protocol bugs, and social engineering.
No. Wallets can sign transactions, plain messages, sign-in statements, and typed data. Some off-chain signatures can later authorize an on-chain action.
It can when the signed message is a permit, order, delegation, or other authorization accepted by a contract or service. Read the exact type and fields rather than relying on the word “message.”
Creating an off-chain signature usually does not. A party that later submits it on-chain may pay gas, while the authority can still affect your assets.
It is the contract expected to interpret or validate typed data. Confirm its address through an independent official source and check that it matches the intended network.
No. Expiry reduces the time window but does not fix a malicious spender, excessive amount, wrong contract, or unintended action.
Only when you independently understand the exact request and trust the full workflow. A site pressuring you to bypass unreadable details is a reason to stop.
Do not trust a cancellation supplied by a suspicious site. Some protocols support nonce invalidation or revocation, but the correct method is specific to the original authorization.
The signature may be unused, off-chain, expired, or waiting for submission. Preserve its fields and seek protocol-specific guidance; no visible transaction does not prove that no authority exists.
Disclaimer: This article provides general security information, not financial, investment, trading, tax, legal, or professional incident-response advice. Signature formats, wallet displays, contract behavior, and remedies vary by protocol and jurisdiction.
Sources:
Sources checked 8 September 2026.
Related reading:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.





