Independent platform · No upfront fees · We are not a recovery firm

Home › Knowledge Hub › Verifying what you sign

How to verify what you are actually signing

By Yair Revach · Co-founder, Chain Pursuit · 10 min · Last updated 1 October 2026

The largest cryptocurrency theft on record happened to an organisation with cold storage, multiple signatures, and several people reviewing the transaction. It succeeded because the interface showing them the transfer had been altered. Reviewing a transaction on a screen is not verification, because the screen can be wrong. Verification means checking the details somewhere the attacker does not control.

What Bybit demonstrated

On 21 February 2025, the exchange Bybit detected unauthorised activity during a routine transfer from an Ethereum multisig cold wallet to a warm wallet. More than $1.4 billion in assets, including 401,347 ETH, were taken.

The cryptography held. The keys were never stolen. The multisig arrangement, requiring several authorised people to approve, worked as designed.

Analysis by NCC Group found that attackers targeted the web interface used to manage the multisig. Forensic work reported by Sygnia found malicious JavaScript had been introduced into the Safe{Wallet} interface used in that workflow. Safe{Wallet} stated its smart contracts were unaffected.

The signers reviewed the transaction. They saw a plausible internal transfer to a familiar address. They approved it. The underlying transaction logic and destination were different from what appeared on screen.

Reporting has attributed the attack to North Korean state-linked actors, which is an attribution from investigators rather than a settled finding.

Three sets of trained eyes reviewed that transfer. The lesson is not that they were careless. It is that reviewing a display is not verification when the display is part of the attack surface.

What the signers saw, and what they signed
WHAT THE SCREEN SHOWEDWHAT WAS AUTHORISEDA routine internal transferA familiar destination addressAn amount that looked correctNothing unusual to three reviewersAltered transaction logicA destination they did not chooseMore than $1.4 billionThe largest theft on recordBybit, February 2025. The cryptography held. The interface did not.
Every control Bybit had worked. The one that failed was the ability of humans to see what they were approving.

The principle

Verify the details somewhere the attacker does not control.

For an individual, that place is your hardware wallet's own screen. The device is driven by its own firmware, not by your browser or your computer. If the address on the device differs from the address on your monitor, the monitor is lying and the device is telling the truth.

This is the entire reason hardware wallets have screens. Most people skip reading them, which reduces the device to an expensive way of holding a key.

What to check, every time

The destination address, on the device screen. Not on your computer. Compare against what you expect.

The full address, not the ends. Address poisoning attacks seed your transaction history with look-alike addresses matching the first and last few characters. In December 2025 and January 2026, Scam Sniffer reported individuals losing approximately $50 million and $12.25 million after copying the wrong address from their own history.

The amount, and the asset. Including the decimal placement. A misplaced decimal is a different transaction.

The network. The same-looking address exists across several chains. Sending on the wrong one is a separate category of loss.

What the transaction does, if it is a contract interaction rather than a simple transfer. This is where it gets harder, and it is the next section.

Blind signing

A simple transfer is easy for a device to describe: send this much of this asset to this address. A smart contract interaction may not be. The device receives data it cannot decode into readable terms, so it shows you a hash and asks you to approve.

Approving that is blind signing. You are authorising something you cannot read.

It is sometimes unavoidable. Many legitimate applications require it. But it is always a decision, and it deserves to be treated as one rather than as a formality.

When to refuse:

There is no penalty for declining. Closing a prompt costs nothing, and you can always return once you understand it.

Clear signing

Some devices and applications support clear signing, sometimes called readable or structured signing, where transaction details are rendered in human terms rather than as raw data. The EIP-712 standard exists for this: it defines how structured data should be presented so a wallet can display what is actually being authorised.

Where your device and the application both support it, use it. It is the difference between "approve this hash" and "allow this contract to move up to 500 USDC".

Support varies by device, by application and by transaction type. It is improving, and it is not universal.

The prompts that look harmless

Not every request is a transaction, and the ones that are not deserve more suspicion rather than less.

A transaction moves something now, and you can see what. It costs gas, appears in your history, and executes once.

A signature proves you control an address. Most are harmless, such as logging into a site.

An approval lets a contract move a specific token on your behalf, later, without asking again. Many default to unlimited.

A Permit signature is an approval that costs no gas and creates no on-chain transaction when you sign. Nothing appears in your history, so there is no event to alarm you, while the permission is live. Scam Sniffer found Permit and Permit2 accounted for 38% of losses above $1 million in 2025. The largest single incident, around $6.5 million in September, came from one malicious Permit signature.

Permit2 extends that across multiple tokens through a single contract.

EIP-7702 signatures, which appeared after the Pectra upgrade, allow an ordinary address to behave temporarily like a smart contract. Malicious use was recorded during 2025 and wallet warnings are still catching up.

The practical rule: a signature request on a site you reached today deserves more scrutiny than a transaction does, because a transaction shows you what it moves and a signature often does not.

Transaction simulation

Some wallets and browser extensions simulate a transaction before you sign, showing the expected outcome: what leaves your wallet, what arrives, what permissions change. Rabby does this natively, and tools such as Blockaid and Wallet Guard provide it as a layer.

Use it where available. It catches a meaningful share of drainer transactions by showing you that a prompt described as a claim would in fact empty an account.

Do not treat it as proof. Simulation predicts an outcome under current conditions. A contract can behave differently at execution, and a simulator can be wrong. It is a strong signal, not a guarantee, and a warning from one should end the conversation rather than start a debate with yourself.

Habits that remove whole categories

Type addresses, or use saved contacts. Never copy from transaction history. That is the specific behaviour address poisoning exploits.

Verify the first transaction to a new address with a small amount. Send a trivial sum, confirm it arrives, then send the rest. The delay costs minutes.

Keep a separate wallet for anything unfamiliar. A drained experimental wallet is an annoyance. Our warm wallet guide covers running two, and the cold wallet guide covers the long-term side.

Bookmark the applications you use. Search advertising for major protocols is routinely bought by phishing operations, and the fake result sits above the real one.

Read wallet warnings. They exist because the site looked fine to somebody else too.

Red flags at the moment of signing

What not to do

Checklist: before every signature

What this guide cannot do

Verification reduces risk. It does not remove it. Interfaces can be compromised, simulators can be wrong, and a determined attacker with access to the right part of the chain can defeat careful people, which is precisely what Bybit shows.

This is general information, not legal or financial advice.

If you approved something you should not have

Move remaining assets to a new wallet first, then revoke approvals. Our guide on what to do if your wallet is compromised covers the order and why it matters.

Expect an approach afterwards from someone offering to recover the funds. Read how to spot a crypto recovery scam before replying.

Use Chain Pursuit's free tools to understand your options, preserve evidence, and identify possible recovery scams. Do not share your seed phrase or private keys with anyone.

Sources

NCC Group, Bybit Hack: In-Depth Technical Analysis, March 2025. https://www.nccgroup.com/research/in-depth-technical-analysis-of-the-bybit-hack/

Sygnia, Sygnia's Investigation into the Bybit Hack, 2025. https://www.sygnia.co/blog/sygnia-investigation-bybit-hack/

Bybit, Security Incident: Timeline of Events and FAQs, February 2025. https://learn.bybit.com/en/this-week-in-bybit/bybit-security-incident-timeline

Scam Sniffer, 2025: Crypto Phishing Losses Fall 83% to $84 Million, January 2026. https://drops.scamsniffer.io/scam-sniffer-2025-crypto-phishing-losses-fall-83-to-84-million/

Loss figures for the Bybit incident vary between $1.4 billion and $1.5 billion across sources; we use "more than $1.4 billion" following NCC Group. Scam Sniffer figures reflect that firm's observed EVM wallet-drainer dataset, not a complete total.

Frequently asked questions

What is blind signing?

Approving a transaction your device cannot decode into readable terms, so it shows a hash rather than details. It is common with smart contract interactions and sometimes unavoidable. Treat it as a decision rather than a formality, and decline where you cannot establish what the transaction does.

Why check the address on the hardware wallet instead of my computer?

Because the device screen is driven by the device's own firmware, which the attacker does not control. Your computer's display can be altered by compromised software. That difference is the entire reason hardware wallets have screens.

Is checking the first and last few characters of an address enough?

No. Address poisoning attacks generate look-alike addresses matching exactly those characters, then seed them into your transaction history so a later copy-paste sends funds to the attacker. Documented losses from this run into tens of millions.

Do transaction simulators make signing safe?

They help considerably and they are not proof. A simulator predicts an outcome under current conditions; a contract can behave differently at execution. Treat a warning as decisive and a clean result as encouraging rather than conclusive.

What is the difference between signing a transaction and signing a message?

A transaction moves something now, costs gas, and appears in your history. A message signature proves you control an address and often does neither. That is why some malicious signatures, particularly Permit approvals, leave no trace at the moment you sign.

My wallet showed a warning but the site looked legitimate. Should I continue?

No. The warning exists because the site looked legitimate to someone else too. Close the prompt, leave, and verify independently by typing the address yourself. Declining costs nothing.

Does a hardware wallet protect me from approving a malicious transaction?

Only partly. It lets you verify the destination on a screen your computer does not control, which is significant. It cannot tell you whether the transaction is a good idea, and if you approve something harmful it will sign it faithfully.

How did Bybit lose funds if they used multisig and cold storage?

The attackers did not break the cryptography or steal keys. They compromised the interface the signers used, so the transaction displayed for approval was not the transaction being authorised. Every control worked except the ability of humans to see what they were signing.

If you approved something you should not have

Ten questions showing which documentation and reporting routes are available in your case.

Recovery pathway assessment

Keep reading