BTC…ETH…ETH gas…Fear & Greed…Live data · not advice

Crypto Lexicon

Blind Signing

Blind signing means approving a transaction your wallet cannot decode. Why it happens, what EIP-712 and ERC-7730 change, and what your device never checks.

Why a Wallet Cannot Always Read a Transaction

A transaction sent to a smart contract carries a data field: a four byte function selector followed by arguments packed into thirty two byte words. That encoding is not self describing. Without the contract's ABI, the description of its functions and their argument types, those bytes cannot be turned back into a name or a meaning.

So a device holding only the raw bytes has nothing useful to render, and it shows you the bytes. It is being honest. It is just being honest in hexadecimal.

Typed Data Is Structure, Not Intent

EIP-712, which is final, tackled the same problem for off chain messages by defining a way to hash and sign typed structured data. Its own motivation section describes what it replaced as "an opaque hex string displayed to the user with little context". A wallet supporting it can show field names and values instead of hex.

That is structure, and structure is not intent. Knowing a field is called spender tells you nothing about whether the address inside it belongs to a marketplace or to somebody in a hurry. Ledger's documentation puts the limit neatly: an ABI "decodes the function call but cannot establish intent or trust".

What Clear Signing Adds

ERC-7730, still a draft rather than a finished standard, aims at that gap. It defines a JSON descriptor in three parts: context, binding it to specific contracts and chains, metadata, supplying names and token details, and display, mapping each function and field to a readable label. The wallet fetches the matching descriptor and renders the call as a sentence. The Ethereum Foundation hosts a registry of these as a neutral steward, and wallets choose which registries to trust.

What the Device Does Not Check

The genuinely useful thing to understand is what a hardware wallet is not doing. It does not inspect the destination contract, check it against a list of known frauds, or hold any opinion whatsoever about whether this is a good idea. It guards a key and renders what it can decode. It is a very secure pen.

The practical rule: treat a blind signing prompt as a stop sign rather than a formality. If the device cannot tell you what you are approving, the real question is not whether you trust the device, it is whether you trust the site that built the payload. And a site that has just been impersonated looks identical to one that has not.

Knowledge check

Three quick questions on this entry. Pick an answer to see whether it is right.

Question 1 of 3Which description matches Blind Signing?

Question 2 of 3What does a hardware wallet do when it cannot decode a transaction?

Question 3 of 3Which of these also belongs to Wallets & Security?

Frequently asked question

What is Blind Signing?

Blind signing means approving a transaction your wallet cannot decode. Why it happens, what EIP-712 and ERC-7730 change, and what your device never checks.

The Letter

One clear letter, every week.

Plain analysis of crypto infrastructure, markets and security. No price calls, no referral links, no hype.

Unsubscribe at any time. Read the privacy notice.

Reader reviews

Did you like what you just read?

Tell other readers what worked, what did not, and who you would recommend it to. Every review is read by a human before it is published, and critical reviews get the same treatment as glowing ones.

Leave a review →