Skip to main content

What You See Is What You Sign: Inside Ethereum's Plan to Kill the $1.5B Blind-Signing Problem

9 min readDora NodaDora Noda
Share
On this page

In February 2025, three of Bybit's most senior, security-trained employees looked at their screens, saw what appeared to be a routine transfer between the exchange's cold and hot wallets, and approved it. What they actually authorized was a malicious contract upgrade that handed control of a wallet holding 401,347 ETH to North Korea's Lazarus Group. The price tag — roughly $1.5 billion — made it the largest theft in the history of digital assets.

No smart contract was hacked. No private key was brute-forced. The signers simply could not see what they were signing. And that single failure mode — "blind signing" — has quietly underwritten billions of dollars in losses across the ecosystem, from billion-dollar exchange heists down to the $790 drained from an anonymous trader who clicked the wrong "approve" button. On May 12, 2026, the Ethereum Foundation decided it was time to make that failure mode obsolete.

The flaw hiding in every "Confirm" button​

Every time you interact with a smart contract, your wallet sends a blob of hexadecimal calldata to the blockchain. A token swap, an NFT mint, a staking deposit, a setApprovalForAll that grants a contract permission to move your assets forever — under the hood, they all look like the same unreadable string of bytes:

text
0x095ea7b3000000000000000000000000a9059cbb...

Blind signing is the act of approving that string without being able to verify what it does. For most of Ethereum's history, this has been the default experience. Hardware wallets and browser extensions would either show you raw hex you couldn't parse, or a vaguely reassuring label like "Contract Interaction" that told you nothing about intent. You were trusting the dApp's front-end to be honest about what it was asking you to authorize.

That trust assumption is exactly what attackers exploit. The Bybit heist is the textbook case: Lazarus compromised a Safe{Wallet} developer machine and injected malicious JavaScript into the wallet's UI. The code lay dormant until it detected a transaction from Bybit's cold wallet, then rewrote that transaction to include a delegatecall performing a malicious upgrade — while showing the signers a perfectly normal-looking transfer. The signers' Ledger devices received the malicious payload; the Safe interface displayed the benign one. Moments after the signatures cleared, the malware swapped the clean JavaScript back in to cover its tracks.

The signers did everything procedurally right. They just had no independent, human-readable source of truth for what their keys were actually authorizing.

Death by a thousand approvals​

Bybit is the headline, but blind signing's real damage is structural and continuous. Wallet-drainer phishing — the malicious-approval scams that prey on retail users — has been a persistent tax on the entire ecosystem.

The encouraging news first: according to Scam Sniffer, phishing losses actually fell 83% in 2025, dropping to roughly $84 million from nearly $494 million in 2024, while the number of victims declined about 68% to around 106,000. Large scores got rarer — only 11 incidents topped $1 million, down from 30 the year before.

But the drainer ecosystem didn't disappear; it adapted. Attackers shifted from rare jackpots toward high-volume, low-value campaigns, with the average victim losing about $790. The dominant technique remained the malicious signature: the single largest theft of 2025 was a $6.5 million loss via a Permit signature, and Permit-based approvals accounted for 38% of losses among incidents over $1 million. These are attacks where the victim signs a message they can't read — Permit lets a token approval ride inside an off-chain signature, so there isn't even an on-chain transaction to inspect until the funds are gone.

Then Ethereum's May 2025 Pectra upgrade introduced EIP-7702, which lets a regular wallet temporarily behave like a smart contract. Within weeks, attackers weaponized it. A widely-copied malicious "sweeper" contract — nicknamed CrimeEnjoyor — proliferated so fast that, by some analyses, more than 97% of EIP-7702 delegations used nearly identical drainer code, and blockchain firm Wintermute found over 80% of delegations were tied to sweeper contracts. One victim lost $150,000 in a single 7702 transaction; another lost $1.54 million in a batched-transaction phishing attack. Every one of these was, at its core, a user approving an action whose true effect was hidden from them.

The pattern is unmistakable. The attack surface keeps shifting — approve, Permit, delegatecall, setCode — but the root cause never changes: humans signing things they cannot see.

"What You See Is What You Sign"​

Clear Signing is the Ethereum Foundation's answer, and its design philosophy fits on a t-shirt: What You See Is What You Sign (WYSIWYS). The goal is to make the human-readable, verifiable transaction the default — not an opt-in feature buried in advanced settings.

The standard is not a protocol change or a hard fork. It's a coordinated set of three components stewarded by the Foundation's Trillion Dollar Security Initiative:

  • ERC-7730 — the descriptor format. A JSON schema that lets a smart contract describe its own functions in plain language: which parameter is the recipient, which is the token amount, what the function actually does. Originally created by Ledger as an internal security project in 2021, formalized as ERC-7730 in 2024, and handed to the Ethereum Foundation in early 2026 to make it credibly neutral. When a wallet supports ERC-7730, it reads the relevant descriptor alongside the raw calldata and reconstructs the transaction into something a person can actually read.

  • A neutral registry. A public, mirrorable repository of these descriptors hosted at clearsigning.org. Anyone can submit a descriptor for their contract; no central gatekeeper decides whose contracts are "legitimate."

  • An attestation framework. Because anyone can submit a descriptor, you need a way to know which ones are trustworthy. The attestation layer — built on the Ethereum Attestation Service — lets independent security firms and auditors review a descriptor against the verified on-chain bytecode and cryptographically vouch for its accuracy. Wallets then decide which attesters they trust.

The runtime flow is elegant. A wallet checks whether ERC-7730 metadata with a valid attestation exists for the contract being called. If yes, it renders a clean, human-readable UI: "Approve 500 USDC spending limit for Uniswap V4 Router." If no trusted descriptor exists, it doesn't silently fall back to opaque hex — it computes and displays a cryptographic fingerprint of the exact payload, so a careful user (or a second device) can still detect tampering. The April 2026 release of ERC-7730 V2 extended coverage to cross-chain interactions, software wallets, and confidential-token primitives.

Crucially, Clear Signing launched with the industry actually behind it. First supporters include Ledger, Trezor, MetaMask, WalletConnect, Fireblocks, Keycard, Sourcify, Cyfrin, Zama, ZKnox, and Argot — hardware vendors, software wallets, custodians, and security firms in the same room. Trezor has committed to shipping support by June 30, 2026. For a standard that only works if everyone implements it, that breadth of buy-in is the whole ballgame.

What Clear Signing can't fix​

A healthy dose of realism is warranted, because Clear Signing is not a silver bullet — and three hard engineering problems determine how much of its promise survives contact with reality.

Decoding contracts that don't want to be decoded. Clear Signing shines for known, well-behaved protocols that publish descriptors. But most malicious contracts don't publish an ABI, let alone a friendly ERC-7730 descriptor — obfuscation is the point. For an unregistered drainer contract, the wallet falls back to the cryptographic fingerprint, which protects against tampering but still asks an ordinary user to make a judgment call. Clear Signing makes honest contracts legible; it doesn't automatically make dishonest ones legible.

Simulation accuracy. Showing a user the true effect of a transaction often requires simulating it against current chain state. For MEV-sensitive interactions, the state at execution time can differ from the state at preview time — meaning the "human-readable" outcome you approved isn't quite the outcome you get. Honest in spirit, but not a guarantee.

The hardware-wallet screen problem. This is the thorniest. A browser extension has an effectively unlimited viewport; a Ledger has a tiny screen. The standard's own guidance recommends a "flattened" representation, and notes that recursive constructs like nested calldata will work only "with restrictions" on hardware at first. No human can meaningfully verify 500 bytes of calldata on a postage-stamp display without missing a single altered character. The real risk is a two-tier outcome — full clarity in the browser, summary-only on the device that's supposed to be your last line of defense — which would quietly reintroduce the exact gap Bybit's attackers drove through.

Clear Signing raises the floor dramatically. It does not make "I didn't know what I was signing" impossible — it makes it inexcusable for the large and growing share of interactions that do have trusted descriptors, and it turns blind signing from the silent default into a conscious, flagged exception.

Why this is an infrastructure story, not just a wallet story​

It's tempting to file Clear Signing under "wallet UX." That undersells it. What the standard really does is move security context upstream, into the data layer that every dApp, indexer, and RPC provider already touches. A transaction descriptor is metadata about contract behavior — exactly the kind of structured, verifiable context that backend infrastructure is well-positioned to surface, attest to, and serve. The teams that treat human-readable intent as a first-class part of their data pipeline, rather than a front-end afterthought, will be the ones whose users don't end up as the next drainer statistic.

That's the larger lesson of the blind-signing era: the most expensive vulnerabilities in crypto haven't been in Solidity. They've been in the gap between what a system does and what a human can see. Closing that gap is a full-stack problem — and reliable, transparent infrastructure is where it gets solved.

bex.co provides enterprise-grade RPC and indexing infrastructure across Ethereum, Sui, Aptos, Solana, and 30+ chains — the verifiable data layer modern wallets and dApps build trustworthy, human-readable experiences on top of. Explore our API marketplace to build on foundations designed to last.

Sources​

Related articles

One API key for 30+ chains

bex router is a single multi-chain gateway — one key, one bill, metered in compute units instead of an account per network.

Explore bex router