How to spot a phishing signature
When you “connect” a wallet, you often sign a message. Those signatures are free and feel harmless, which is exactly why attackers use them. Some signatures are authorisations in disguise.
Common disguises
- Permit / permit2. A signature that grants a contract the right to move tokens — no separate approval needed.
- Order signing. A signature that authorises a trade or transfer, later executed by someone else.
- “Login” requests that contain encoded data you did not expect.
How to read what you sign
Your wallet shows the raw request. If it is a message, look for a human-readable explanation; if there is none, be suspicious. If it references a contract you do not recognise, stop. No legitimate login needs permission to move your assets.
Habits that protect you
- Never sign a message you cannot explain.
- Prefer wallets that decode and warn about risky signatures.
- Keep a separate hot wallet for new or risky apps.
- Watch for the after-effects: a new approval or outflow you did not initiate.
Shingan is the watchful layer after the signature — if one slips through, it alerts you on the approval or outflow that follows.
