Skip to content
IntermediateLearn the steps

How to sign a message

Author
CRYPTO PORT Editorial
Published
Updated
Reading time
5 min

In short

Signing a message proves you control an address and moves no funds by itself. That does not make every signature safe: a request presented in an unreadable format may in fact authorise a transfer of assets. If you cannot read what you are signing, do not sign it.

Key points

  • A signature proves control of an address and by itself costs no fee
  • Refuse any request whose contents you cannot read — harmless is not the default
  • Check the site's URL before signing anything it asks for
  • If you cannot explain why a signature is being requested, do not give it

Definition

Using your private key to attach a digital signature to a piece of text, proving to a counterparty that you control that address.

The mechanism is a digital signature in the strict sense: what you sign with a private key can be verified only against the corresponding public key, i.e. the address. A valid signature therefore proves the signer holds that address's key. That property gave rise to logging in without a password, or proving eligibility for something open only to holders. 'Digital signature' covers the background.

The common case is right after connecting to a dApp, where many sites ask you to sign a short message confirming you control the connected address. Signatures of this kind write nothing to the chain, so they carry no fee — and the absence of a fee is one clue that no transfer is involved.

But this is where the real point begins. Some signature requests are shown not as readable prose but as a wall of symbols and hexadecimal. That format is abused precisely so you approve without reading. Mechanisms do exist whereby a signature alone authorises a transfer, or grants someone else the right to move your assets. 'It is only a signature, so it is safe' is simply wrong. Do not sign what you cannot read — that is the entire rule.

Check three things first. One: is the URL you are on the right one? Coming from a search result or an advert especially, suspect near-identical domains. Two: can you explain why a signature is being asked for — is it a login, an application, something else? Three: can you read what is displayed? If not, stop and take the time to find out. The harder something pushes you to hurry, the more it is worth pausing.

Some wallets warn about signature requests that look dangerous. When a warning appears, do not push past it without understanding why. It is also effective simply never to answer signature requests from a cold-storage address: confine anything requiring a signature to a hot account holding small amounts.

Watch out for

  • · Never sign a request you cannot read — signatures alone can authorise moving assets
  • · Fake sites routinely ask for a signature under the pretext of 'wallet verification' or 'claiming an airdrop'; check the URL
  • · Do not reach a site from a DM or email link that asks for a signature — open it from a URL you saved yourself

Frequently asked questions

  • Does signing cost a fee?

    A signature that writes nothing to the chain costs nothing. If a fee is being shown, you are not signing a message — you are submitting a transaction, so read it again.

Related coins

Read next

Crypto quizzes

Answer a few questions and get your result instantly.

Start