On this pagePrepare before you beginFollow the action in orderWhat to verify at each stepCommon mistakes and recovery thinkingA practical security checklistReview after completion

Prepare before you begin

Before starting Signature Requests, gather the information related to message signing, transaction signing, and structured data. Signing is not one uniform action. Message signatures, transaction signatures and structured-data signatures can carry very different meanings. Do not search for recovery material on an unfamiliar site or skip a network, address or permission check simply because the workflow looks familiar. Good preparation makes later anomalies easier to notice.

Key point: domain origin

During the action, treat domain origin and request contents as separate checkpoints rather than one combined confirmation. When a state related to rejecting unknown requests appears, make sure it belongs to the intended network and object. If the request differs from what you expected, stop and re-check instead of submitting the same request several times.

After completion, keep enough public information to review the result. Revisit message signing, confirm that transaction signing and structured data match the intended outcome, and make sure domain origin has not left an unnecessary permission behind. On-chain transactions generally cannot be reversed by a wallet alone, so post-action review is part of the workflow, not an optional extra.

Follow the action in order

Before starting Signature Requests, gather the information related to transaction signing, structured data, and domain origin. Signing is not one uniform action. Message signatures, transaction signatures and structured-data signatures can carry very different meanings. Do not search for recovery material on an unfamiliar site or skip a network, address or permission check simply because the workflow looks familiar. Good preparation makes later anomalies easier to notice.

Key point: request contents

During the action, treat request contents and rejecting unknown requests as separate checkpoints rather than one combined confirmation. When a state related to message signing appears, make sure it belongs to the intended network and object. If the request differs from what you expected, stop and re-check instead of submitting the same request several times.

After completion, keep enough public information to review the result. Revisit transaction signing, confirm that structured data and domain origin match the intended outcome, and make sure request contents has not left an unnecessary permission behind. On-chain transactions generally cannot be reversed by a wallet alone, so post-action review is part of the workflow, not an optional extra.

What to verify at each step

Before starting Signature Requests, gather the information related to structured data, domain origin, and request contents. Signing is not one uniform action. Message signatures, transaction signatures and structured-data signatures can carry very different meanings. Do not search for recovery material on an unfamiliar site or skip a network, address or permission check simply because the workflow looks familiar. Good preparation makes later anomalies easier to notice.

Key point: rejecting unknown requests

During the action, treat rejecting unknown requests and message signing as separate checkpoints rather than one combined confirmation. When a state related to transaction signing appears, make sure it belongs to the intended network and object. If the request differs from what you expected, stop and re-check instead of submitting the same request several times.

After completion, keep enough public information to review the result. Revisit structured data, confirm that domain origin and request contents match the intended outcome, and make sure rejecting unknown requests has not left an unnecessary permission behind. On-chain transactions generally cannot be reversed by a wallet alone, so post-action review is part of the workflow, not an optional extra.

01 Review structured data before moving to domain origin; if the two do not describe the same intended action, stop and investigate.
02 Review domain origin before moving to request contents; if the two do not describe the same intended action, stop and investigate.
03 Review request contents before moving to rejecting unknown requests; if the two do not describe the same intended action, stop and investigate.

Common mistakes and recovery thinking

Before starting Signature Requests, gather the information related to domain origin, request contents, and rejecting unknown requests. Signing is not one uniform action. Message signatures, transaction signatures and structured-data signatures can carry very different meanings. Do not search for recovery material on an unfamiliar site or skip a network, address or permission check simply because the workflow looks familiar. Good preparation makes later anomalies easier to notice.

Key point: message signing

During the action, treat message signing and transaction signing as separate checkpoints rather than one combined confirmation. When a state related to structured data appears, make sure it belongs to the intended network and object. If the request differs from what you expected, stop and re-check instead of submitting the same request several times.

After completion, keep enough public information to review the result. Revisit domain origin, confirm that request contents and rejecting unknown requests match the intended outcome, and make sure message signing has not left an unnecessary permission behind. On-chain transactions generally cannot be reversed by a wallet alone, so post-action review is part of the workflow, not an optional extra.

A practical security checklist

Before starting Signature Requests, gather the information related to request contents, rejecting unknown requests, and message signing. Signing is not one uniform action. Message signatures, transaction signatures and structured-data signatures can carry very different meanings. Do not search for recovery material on an unfamiliar site or skip a network, address or permission check simply because the workflow looks familiar. Good preparation makes later anomalies easier to notice.

Key point: transaction signing

During the action, treat transaction signing and structured data as separate checkpoints rather than one combined confirmation. When a state related to domain origin appears, make sure it belongs to the intended network and object. If the request differs from what you expected, stop and re-check instead of submitting the same request several times.

After completion, keep enough public information to review the result. Revisit request contents, confirm that rejecting unknown requests and message signing match the intended outcome, and make sure transaction signing has not left an unnecessary permission behind. On-chain transactions generally cannot be reversed by a wallet alone, so post-action review is part of the workflow, not an optional extra.

  • Check message signing in the correct network and request context before confirming.
  • Check transaction signing in the correct network and request context before confirming.
  • Check structured data in the correct network and request context before confirming.
  • Check domain origin in the correct network and request context before confirming.
  • Check request contents in the correct network and request context before confirming.

Review after completion

Before starting Signature Requests, gather the information related to rejecting unknown requests, message signing, and transaction signing. Signing is not one uniform action. Message signatures, transaction signatures and structured-data signatures can carry very different meanings. Do not search for recovery material on an unfamiliar site or skip a network, address or permission check simply because the workflow looks familiar. Good preparation makes later anomalies easier to notice.

Key point: structured data

During the action, treat structured data and domain origin as separate checkpoints rather than one combined confirmation. When a state related to request contents appears, make sure it belongs to the intended network and object. If the request differs from what you expected, stop and re-check instead of submitting the same request several times.

After completion, keep enough public information to review the result. Revisit rejecting unknown requests, confirm that message signing and transaction signing match the intended outcome, and make sure structured data has not left an unnecessary permission behind. On-chain transactions generally cannot be reversed by a wallet alone, so post-action review is part of the workflow, not an optional extra.

Notice: Important: on-chain transactions generally cannot be reversed by a wallet alone. Third-party DApps, smart contracts and staking services can introduce risk. Never send a seed phrase, private key or verification code to anyone.