Read before you sign: blind signing vs transaction previews
Last updated: November 6, 2026
Every crypto loss that starts with a click has the same shape: a wallet popup, a Confirm button, and a signature. Sometimes the wallet shows you what that signature does in plain language. Sometimes it shows a wall of hexadecimal. The difference between those two screens is where most wallet-drainer losses live.
- A signature is consent. Once a transaction is signed and confirmed, no wallet, company, or support desk can reverse it.
- Blind signing means approving unreadable hex. If the wallet can't render what a signature does, you can't verify it — you're trusting the website completely.
- Transaction previews simulate the outcome first. Modern wallets dry-run your transaction and show balance changes and permission grants before you commit.
- Check three things: domain, action, spender. Thirty seconds of reading beats any post-hack regret — and urgency is the loudest red flag there is.
- Hardware wallets protect keys, not message content. A secure key can still sign a malicious transaction.
Every action is a signature
Blockchains don't have take-backs. Every meaningful action — a transfer, a swap, an NFT mint, a token approval — is authorized by a cryptographic signature from your private key. There are two kinds worth knowing about: transaction signatures, which the network executes directly, and message signatures, off-chain consents (like permit or eth_sign) that a smart contract can replay later.
The stakes are not theoretical. Scam Sniffer's 2024 report counted $494 million lost to wallet drainers across roughly 332,000 victims — up 67% year over year. Most of those losses weren't key thefts or brute-force attacks. They were signatures: people approved transactions they couldn't read, on sites built to look legitimate. Drainer kits like Inferno, Angel, and Pink are sold as ready-made services, so the same attack template shows up on thousands of phishing sites.
What blind signing actually approves
Blind signing is what happens when the wallet can't decode the payload into something human-readable — or doesn't bother to. You get a hash, a string of hex, a destination contract. The popup technically tells you everything and practically tells you nothing.
That hex can hide calls like approve() or setApprovalForAll(), which hand a contract the right to move your tokens — sometimes your entire balance of a token or collection. Because approvals persist until you revoke them, one bad signature isn't one bad transaction; it's a standing permission an attacker can exercise weeks later. Off-chain variants are worse still: a permit or Permit2 signature costs no gas and creates no transaction until the attacker replays it, so nothing looks wrong at the moment you sign.
Transaction previews: simulate before you commit
A transaction preview does what your brain can't do with hex: it runs the transaction against the current state of the chain — a simulation — and renders the outcome before you sign. A good preview answers three questions in plain language: what leaves your wallet, what comes back, and which permissions you're granting.
This is now table stakes for serious wallets. Rabby built its reputation on pre-sign balance previews; Phantom ships exploit warnings powered by Blowfish, the security engine it acquired after it had already blocked millions of scam transactions; Trust Wallet screens approvals the same way. If your wallet shows only raw calldata for a contract interaction, that's a bug-level gap — treat it as one.
The 30-second pre-sign checklist
You don't need to read bytecode to stay safe. You need a habit. Before every signature, check:
- Domain. Is the URL exactly right — not a lookalike with swapped letters, hyphens, or a different TLD? Phishing sites clone pixel-perfect frontends; the domain is usually the only thing they can't clone.
- Action. Does the previewed action match what you clicked? You pressed "Mint" — the wallet should not say "setApprovalForAll" or "Transfer".
- Spender. Who gets the permission? An approval to a random fresh contract is not the same as an approval to the protocol you intended.
- Amount and deadline. Unlimited approvals are convenient and dangerous; a long or infinite expiry means the permission outlives your session.
- Urgency. Countdown timers, "last spot", "claim expires in 5:00". Manufactured panic exists to skip your checklist.
- DM'd or ads-driven links. Real airdrops don't arrive via DM. Sponsored search results for wallet names are a classic phishing channel.
- "Verify" or "sync" your wallet. No legitimate dapp needs your seed phrase — ever — and most don't need a signature just to let you read a page.
- Approvals on a mint page. A mint needs a mint transaction, not blanket approval over your tokens.
What previews can't catch
Honesty matters here: simulation is a snapshot, not a prophecy. It shows what the transaction would do right now — but state can change between simulation and execution, and attackers deliberately design transactions that behave differently once they're inside the mempool. New drainer patterns also lag detectors by definition; yesterday's signatures get screened better than tomorrow's.
Two more gaps to know about. First, a compromised frontend: if a legitimate protocol's website itself is hijacked to serve a malicious contract, the preview will dutifully show the bad outcome — but framed inside a page you trusted. The preview only helps if you actually read it. Second, hardware wallets: they keep your keys isolated from a compromised computer, and that matters enormously — but the key isn't what's being attacked. A small screen can't decode complex contract calls, and a perfectly protected key will still faithfully sign a drainer transaction. Keys safe ≠ message safe.
Finally: no screening engine, Nova's included, catches everything. Screening is a second opinion, not a guarantee. The checklist above is the part that's fully yours.
How Nova screens signatures
Nova Shield runs pre-sign screening on your device: before you confirm, the transaction is simulated and checked against eight classes of known exploits — malicious approvals and permit traps, drainer contract patterns, address poisoning, replayable message signatures, and more. The result is rendered as a plain-language preview: balances in and out, permissions granted, and a clear warning when something doesn't add up.
Two design choices matter. Everything happens locally — Nova has zero telemetry, so your unsigned transactions are never sent to a server for judgment. And there is no remote kill switch: Shield informs, it doesn't decide. You always retain the final word on what your key signs — which is the whole point of self-custody.
Nova Shield screens every transaction on-device before you sign — balances, permissions, and eight exploit classes, in plain language. Your keys never leave this window.
Educational content, not financial or security advice. Figures cited (Scam Sniffer 2024) describe a historical reporting period; attack volumes change. Always verify signatures independently.