Ledger CTO warns crypto users about the dangers of ‘blind signing’

Share This Post

“Don’t trust, verify,” says Charles Guillemet, the CTO of hardware wallet firm Ledger.

With the recent attack on OpenSea highlighting blockchain vulnerabilities, Charles Guillemet, the CTO of Ledger warns users about “blind signing” which he defines as “consenting a transaction to be signed blindly, without understanding what it means.” 

In an interview with Cointelegraph, Guillemet broke down the problems and highlighted issues with blind signing. The Ledger CTO notes that consenting to transactions requires signing a message to be sent to the blockchain. A user is the only one capable of signing transactions with the private key, while others can verify if it’s correct. “The issue is that this message is not intelligible by default. It’s a digital payload,” says Guillemet.

Guillemet also explained that when a coin transfer is signed, it’s normally supported by a wallet that “properly parses the payload and displays its intent.” However, when it comes to signing complex interactions with smart contracts, Guillemet says that “parsing the display is not always properly supported and you have no choice but consenting blindly for a transaction that you don’t understand.”

“It’s risky because you can think you’re signing a transaction to move part of your funds to address A while you actually sign a transaction to move all your funds to address B.”

Related: OpenSea disables features temporarily as contract migration completes

The security expert also gave examples where blind signing led to significant losses. In the most recent OpenSea exploit, users encountered a phishing attack that resulted in the loss of $1.7 million worth in nonfungible tokens (NFTs). Guillemet notes that in this incident, the attackers tricked their victims into blind-signing a message that made them consent to sell all their NFTs for 0 ETH.

“The attacker had only to sign a transaction saying ‘I’m ok to buy these NFTs for 0 ETH,’ and then presented these two messages to OpenSea to actually execute the transaction swapping 0 ETH against all the victims’ NFTs.”

When asked what he thinks is the solution to the issue of blind signing, Guillemet turned to an old crypto adage, “don’t trust, verify.” He tells crypto users to “always verify the transaction you consent to sign.” One suggestion that the security expert brought up is signing transactions using trusted displays that can be found on hardware wallets.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Top Crypto Analyst Unveils Strategy To ‘Make Millions’ By March 2025

Crypto analyst Miles Deutscher, boasting 550,000 followers on X, has released a new video titled “My Plan To Make Millions In Crypto By March 2025! [Fool Proof Strategy]” In this analysis,

Bitcoin Losing the Momentum as the Traders Turn Bearish on BTC Price—What’s Next?

The post Bitcoin Losing the Momentum as the Traders Turn Bearish on BTC Price—What’s Next appeared first on Coinpedia Fintech News In the times when the Bitcoin price was expected to rise above

Sky considers reverting to MakerDAO after community pushback

DeFi project Sky (formerly known as MakerDAO) is evaluating the possibility of additional brand adjustments following community feedback on its recent rebrand On Oct 21, Sky’s co-founder Rune

A Hero Falls: Bitcoin Community Blasts Michael Saylor’s ‘Paranoid Crypto-Anarchists’ and Self-Custody Remarks

Microstrategy co-founder Michael Saylor blasted the original bitcoin community stating that crypto-anarchists were paranoid about possible bitcoin seizure events involving the large companies that

BRICS Summit 2024: Is a Crypto Revolution Coming to Shake the Financial World?

The post BRICS Summit 2024: Is a Crypto Revolution Coming to Shake the Financial World appeared first on Coinpedia Fintech News The 16th Annual BRICS Summit, 2024, has kicked off in Kazan, Russia,

Messari Reports TRON’s Protocol Revenue Reached an All-Time High in Q3 2024

PRESS RELEASE Geneva, Switzerland, October 22, 2024 – Messari, a leading provider of digital asset market intelligence products, released a research report highlighting TRON’s Q3