On this pageBefore you beginWork through the stepsCritical checksCommon mistakesReview after completion
Before you start

Before you start, never enter a seed phrase, private key, recovery phrase or wallet verification code into a web page.

Before you begin

Signature Requests makes more sense when message signing, transaction signing, request contents, domain checks, rejecting unusual requests are considered as parts of one on-chain workflow. The same address format can appear across different network contexts, so appearance alone is not enough to confirm the correct destination.

During real use, confirm the active network and account first, then verify the object, scope and expected outcome related to message signing. Any action that changes assets, permissions or account state deserves a full review before confirmation.

Work through the steps

During real use, confirm the active network and account first, then verify the object, scope and expected outcome related to message signing. Any action that changes assets, permissions or account state deserves a full review before confirmation.

For transaction signing, prefer information that can be independently checked: the wallet transaction summary, the relevant network explorer, an explicit contract address or an official product page. A wallet interface is only the entry point; the important checks concern the network, address, contract and on-chain state.

01 · message signing
02 · transaction signing
03 · request contents
04 · domain checks
05 · rejecting unusual requests

Critical checks

For transaction signing, prefer information that can be independently checked: the wallet transaction summary, the relevant network explorer, an explicit contract address or an official product page. A wallet interface is only the entry point; the important checks concern the network, address, contract and on-chain state.

When request contents is involved, separate display data from on-chain facts. Names, icons and fiat estimates may come from external data sources, while balances, transaction state and approvals should be verified on the selected network.

Common mistakes

When request contents is involved, separate display data from on-chain facts. Names, icons and fiat estimates may come from external data sources, while balances, transaction state and approvals should be verified on the selected network.

For domain checks, retain the transaction hash or other useful reference when appropriate. On-chain transactions generally cannot be reversed unilaterally by a wallet, which makes pre-broadcast checks of the address, network, amount and permissions especially important.

Review after completion

For domain checks, retain the transaction hash or other useful reference when appropriate. On-chain transactions generally cannot be reversed unilaterally by a wallet, which makes pre-broadcast checks of the address, network, amount and permissions especially important.

Finally, consider rejecting unusual requests. Third-party DApps, smart contracts and network services can introduce technical, operational and market risk. Unclear signatures, unnecessarily broad approvals, or any page asking for a seed phrase or private key are reasons to stop and re-check the request.