# What is a signature request?

> A signature request can be harmless, or let a site take your tokens without a fee or a transfer. Learn what to check, and what to do if you signed.

URL: https://docs.fxwallet.com/security-and-scams/signature-requests
Last reviewed: 28 September 2026

A DApp asks you to sign when it needs your wallet's consent. Some signatures only prove that you own an address, but others let a contract take your tokens, even though nothing is sent and there's no fee. Read every request before you sign it, and sign only on sites you trust.

## Kinds of requests

- **A message**, such as a sign-in message, is text you can read. It proves that you own the address and moves nothing.
- **A permit** is a [token approval](https://docs.fxwallet.com/wallet/token-approvals) given with a signature instead of a transaction. It costs no fee, but whoever has the signature can take that token, up to its limit, whenever they choose. Phishing sites often ask for permits.
- **A transaction**, such as a transfer, an approval or a swap, changes your balances once it's sent to the network and confirmed there. It pays a network fee.
- **Raw data** that can't be shown as readable text means signing blind: you can't tell what you agree to. When a DApp you connect with WalletConnect asks to do this, FxWallet shows **Signing unreadable raw data** in orange. Reject it unless you trust the DApp and know why it needs it.

FxWallet shows DApps' Solana transactions as raw data too, and a single Solana transaction can move several of your assets at once.

## Before you sign

> **Danger**
>
> Don't sign anything to "claim", "verify" or "unlock" something, especially from a link in a message, an ad or an airdrop. Scammers use these to get a permit or an approval from you.

- **Who is asking:** check the website's address letter by letter: the site you have open in **Discover**, or the one you connected with WalletConnect. For a permit, FxWallet also shows it under **Request from**, and a sign-in message lists it as its URI.
- **What you give away:** for a permit, FxWallet shows the **Spender** and the **Spend limit**; for an approval, the **Contract** that gets it and the amount. Reject it if that isn't the DApp you meant to use, or if the limit is unlimited when you don't need it to be.
- **FxWallet's warnings:** take them seriously, but a request with no warning isn't necessarily safe.

## If you signed something suspicious

Act at once. What you can still do depends on what you signed:

- **An approval or a permit on an EVM network:** revoke approvals you don't recognise in **Wallet** → **More** → **Approvals**. A permit that hasn't been used yet isn't listed there, and revoking may not cancel it, so also move that token to another wallet of yours straight away. See [If you approved a scam contract](https://docs.fxwallet.com/security-and-scams/if-your-wallet-is-compromised#if-you-approved-a-scam-contract).
- **A transaction on an EVM network:** FxWallet sends it as soon as you confirm it. While it's pending, you may be able to cancel it: see [Pending or stuck transactions](https://docs.fxwallet.com/wallet/pending-transactions). Once the network confirms it, it can't be reversed: revoke any approval it gave.
- **A transaction on Solana:** FxWallet gives the signature back to the site, and the site sends the transaction, usually within seconds. FxWallet can't cancel it, and **Approvals** covers EVM networks only, so if you're not sure what you signed, move your assets to a new wallet.
- **Your mnemonic phrase or private key:** if you typed either on a site, your wallet is compromised. See [What to do if your wallet is compromised](https://docs.fxwallet.com/security-and-scams/if-your-wallet-is-compromised).
