Skip to main content

What is a signature request?

A DApp asks you to sign when it needs your wallet's consent. Some signatures only prove that you own an address, but others let a contract take your tokens, even though nothing is sent and there's no fee. Read every request before you sign it, and sign only on sites you trust.

Kinds of requests​

  • A message, such as a sign-in message, is text you can read. It proves that you own the address and moves nothing.
  • A permit is a token approval given with a signature instead of a transaction. It costs no fee, but whoever has the signature can take that token, up to its limit, whenever they choose. Phishing sites often ask for permits.
  • A transaction, such as a transfer, an approval or a swap, changes your balances once it's sent to the network and confirmed there. It pays a network fee.
  • Raw data that can't be shown as readable text means signing blind: you can't tell what you agree to. When a DApp you connect with WalletConnect asks to do this, FxWallet shows Signing unreadable raw data in orange. Reject it unless you trust the DApp and know why it needs it.

FxWallet shows DApps' Solana transactions as raw data too, and a single Solana transaction can move several of your assets at once.

Before you sign​

danger

Don't sign anything to "claim", "verify" or "unlock" something, especially from a link in a message, an ad or an airdrop. Scammers use these to get a permit or an approval from you.

  • Who is asking: check the website's address letter by letter: the site you have open in Discover, or the one you connected with WalletConnect. For a permit, FxWallet also shows it under Request from, and a sign-in message lists it as its URI.
  • What you give away: for a permit, FxWallet shows the Spender and the Spend limit; for an approval, the Contract that gets it and the amount. Reject it if that isn't the DApp you meant to use, or if the limit is unlimited when you don't need it to be.
  • FxWallet's warnings: take them seriously, but a request with no warning isn't necessarily safe.

If you signed something suspicious​

Act at once. What you can still do depends on what you signed:

  • An approval or a permit on an EVM network: revoke approvals you don't recognise in Wallet → More → Approvals. A permit that hasn't been used yet isn't listed there, and revoking may not cancel it, so also move that token to another wallet of yours straight away. See If you approved a scam contract.
  • A transaction on an EVM network: FxWallet sends it as soon as you confirm it. While it's pending, you may be able to cancel it: see Pending or stuck transactions. Once the network confirms it, it can't be reversed: revoke any approval it gave.
  • A transaction on Solana: FxWallet gives the signature back to the site, and the site sends the transaction, usually within seconds. FxWallet can't cancel it, and Approvals covers EVM networks only, so if you're not sure what you signed, move your assets to a new wallet.
  • Your mnemonic phrase or private key: if you typed either on a site, your wallet is compromised. See What to do if your wallet is compromised.

Last reviewed on

Still need help?

Email support@fxwallet.com or use Me → Feedback in the app.

FxWallet support will never message you first or ask for your mnemonic phrase or private key.