Crypto Lexicon
Blind Signing
Blind signing means approving a transaction your wallet cannot decode. Why it happens, what EIP-712 and ERC-7730 change, and what your device never checks.
Why a Wallet Cannot Always Read a Transaction
A transaction sent to a smart contract carries a data field: a four byte function selector followed by arguments packed into thirty two byte words. That encoding is not self describing. Without the contract's ABI, the description of its functions and their argument types, those bytes cannot be turned back into a name or a meaning.
So a device holding only the raw bytes has nothing useful to render, and it shows you the bytes. It is being honest. It is just being honest in hexadecimal.
Typed Data Is Structure, Not Intent
EIP-712, which is final, tackled the same problem for off chain messages by defining a way to hash and sign typed structured data. Its own motivation section describes what it replaced as "an opaque hex string displayed to the user with little context". A wallet supporting it can show field names and values instead of hex.
That is structure, and structure is not intent. Knowing a field is called spender tells you nothing about whether the address inside it belongs to a marketplace or to somebody in a hurry. Ledger's documentation puts the limit neatly: an ABI "decodes the function call but cannot establish intent or trust".
What Clear Signing Adds
ERC-7730, still a draft rather than a finished standard, aims at that gap. It defines a JSON descriptor in three parts: context, binding it to specific contracts and chains, metadata, supplying names and token details, and display, mapping each function and field to a readable label. The wallet fetches the matching descriptor and renders the call as a sentence. The Ethereum Foundation hosts a registry of these as a neutral steward, and wallets choose which registries to trust.
What the Device Does Not Check
The genuinely useful thing to understand is what a hardware wallet is not doing. It does not inspect the destination contract, check it against a list of known frauds, or hold any opinion whatsoever about whether this is a good idea. It guards a key and renders what it can decode. It is a very secure pen.
The practical rule: treat a blind signing prompt as a stop sign rather than a formality. If the device cannot tell you what you are approving, the real question is not whether you trust the device, it is whether you trust the site that built the payload. And a site that has just been impersonated looks identical to one that has not.
Knowledge check
Three quick questions on this entry. Pick an answer to see whether it is right.
Question 1 of 3Which description matches Blind Signing?
Question 2 of 3What does a hardware wallet do when it cannot decode a transaction?
Question 3 of 3Which of these also belongs to Wallets & Security?
Frequently asked question
What is Blind Signing?
Blind signing means approving a transaction your wallet cannot decode. Why it happens, what EIP-712 and ERC-7730 change, and what your device never checks.