How to review a transaction before signing
- Author
- CRYPTO PORT Editorial
- Published
- Updated
- Reading time
- 7 min
In short
A signature is permission to execute what is in front of you, and there is essentially no way to take it back. Approve without reading and you lose the assets. Check five things: which site, what kind of operation, which asset and how much, the destination, and the network. If you cannot read or explain the request, do not sign.
Key points
- A signature authorises moving assets, and it is practically irreversible
- Check five things: the site, the operation, the asset and amount, the destination, the network
- A transfer and an approval — granting someone the right to move your tokens — are different things
- Being rushed, seeing a warning, or not understanding the text are all reasons to stop
Definition
Reading what a wallet is asking you to sign in terms of the outcome it will produce, and confirming that this matches what you intended.
Begin by being clear about what signing is. It is not a confirm button. It is you using your private key to grant permission for this content to be written to the chain. A written transaction cannot be reversed, and once whoever you authorised has moved the assets, there is no route back. Most crypto losses happen not because keys were stolen but because the owner signed something.
There are five things to check. One: the site making the request — the wallet shows its domain, so compare it with the site you believe you opened. Two: what kind of operation it is, because a transfer, an approval and a contract call mean entirely different things. Three: which asset and how much. Four: the destination address. Five: the network. Read them in order without looking away from the screen.
The transfer-versus-approval distinction deserves particular care. A transfer hands over the stated amount right now. An approval grants a contract the right to move your tokens — nothing leaves at that moment, but whoever holds the right can draw on it whenever they choose afterwards. Requests for an unlimited allowance do occur, and people who signed without noticing have repeatedly been cleaned out weeks later. 'How to revoke a token approval' covers tidying these up.
Decide in advance what you do when the display is unreadable. Some wallets simulate the outcome and show how your balances would change, which is a strong signal: if the preview says every NFT you hold would move out, that is your answer. When all you get is a run of hexadecimal, you would be signing without knowing what happens. Do not sign what you do not understand, and do not let that line move.
Finally, the signals to stop on: pressure from countdowns or dwindling stock, a warning from the wallet itself, a request that does not match the action you were trying to take, or a signature prompt appearing when you did nothing to trigger one. Any one of them is enough to close the window. A legitimate transaction can always be repeated later.
Watch out for
- · A signed transaction cannot be undone, and anyone you approved can move those assets at any later date
- · Watch for requests for an unlimited allowance — cap it where you can, and revoke rights once they are no longer needed
- · Countdowns, urgency and limited-quantity claims exist to stop you checking; being rushed is a reason to stop
Frequently asked questions
I cannot read what the signing screen says. What should I do?
Do not sign. Approving something you cannot read is handing over blank permission. If the action is genuinely necessary, check the official documentation, understand what is supposed to happen, and come back to it.