{"id":411690,"date":"2022-03-03T14:33:37","date_gmt":"2022-03-03T11:33:37","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/ledger-cto-warns-crypto-users-about-the-dangers-of-blind-signing\/"},"modified":"2022-03-03T14:33:37","modified_gmt":"2022-03-03T11:33:37","slug":"ledger-cto-warns-crypto-users-about-the-dangers-of-blind-signing","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/ledger-cto-warns-crypto-users-about-the-dangers-of-blind-signing\/","title":{"rendered":"# Ledger CTO warns crypto users about the dangers of &#8216;blind signing&#8217;"},"content":{"rendered":"<p>&#8220;<strong># Ledger CTO warns crypto users about the dangers of &#8216;blind signing&#8217; <\/strong>&#8221;<br \/>\n<img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjItMDMvODI1YjJkMzEtNjM3ZS00YTE4LWI4ODAtOGQwYjEzM2FmMjk4LmpwZw==.jpg\" \/><\/p>\n<div class=\"post-content\" data-v-128018ef>With the recent attack on OpenSea highlighting blockchain vulnerabilities, Charles Guillemet, the CTO of Ledger warns users about \u201cblind signing\u201d which he defines as \u201cconsenting a transaction to be signed blindly, without understanding what it means.\u201d\u00a0<\/p>\n<p>In an interview with Cointelegraph, Guillemet broke down the problems and highlighted issues with blind signing. The Ledger CTO notes that consenting to transactions requires signing a message to be sent to the blockchain. A user is the only one capable of signing transactions with the private key, while others can verify if it&#8217;s correct. &#8220;The issue is that this message is not intelligible by default. It\u2019s a digital payload,&#8221; says Guillemet.<\/p>\n<p>Guillemet also explained that when a coin transfer is signed, it\u2019s normally supported by a wallet that \u201cproperly parses the payload and displays its intent.\u201d However, when it comes to signing complex interactions with smart contracts, Guillemet says that \u201cparsing the display is not always properly supported and you have no choice but consenting blindly for a transaction that you don\u2019t understand.\u201d<\/p>\n<blockquote><p>\u201cIt\u2019s risky because you can think you\u2019re signing a transaction to move part of your funds to address A while you actually sign a transaction to move all your funds to address B.\u201d<\/p><\/blockquote>\n<p><strong><em>Related: <\/em><\/strong><strong><em>OpenSea disables features temporarily as contract migration completes<\/em><\/strong><\/p>\n<p>The security expert also gave examples where blind signing led to significant losses. In the most recent OpenSea exploit, users encountered a phishing attack that resulted in the loss of $1.7 million worth in nonfungible tokens (NFTs). Guillemet notes that in this incident, the attackers tricked their victims into blind-signing a message that made them consent to sell all their NFTs for 0 ETH.<\/p>\n<blockquote><p>\u201cThe attacker had only to sign a transaction saying \u2018I\u2019m ok to buy these NFTs for 0 ETH,\u2019 and then presented these two messages to OpenSea to actually execute the transaction sw<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>ing 0 ETH against all the victims\u2019 NFTs.\u201d<\/p><\/blockquote>\n<p>When asked what he thinks is the solution to the issue of blind signing, Guillemet turned to an old crypto adage, \u201cdon\u2019t trust, verify.\u201d He tells crypto users to \u201calways verify the transaction you consent to sign.\u201d One suggestion that the security expert brought up is signing transactions using trusted displays that can be found on hardware wallets.<\/p>\n<p><template data-name=\"subscription_form\" data-type=\"nifty_newsletter\"><\/template><\/div>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/general\/\" target=\"_blank\" rel=\"noopener\">General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/ledger-cto-warns-crypto-users-about-the-dangers-of-blind-signing\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;# Ledger CTO warns crypto users about the dangers of &#8216;blind signing&#8217; &#8221; With the recent attack on OpenSea highlighting blockchain vulnerabilities, Charles Guillemet, the CTO of Ledger warns users about \u201cblind signing\u201d which he defines as \u201cconsenting a transaction to be signed blindly, without understanding what it means.\u201d\u00a0 In an interview with Cointelegraph, Guillemet&#8230;<\/p>\n","protected":false},"author":1,"featured_media":411691,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.cointelegraph.com\/images\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjItMDMvODI1YjJkMzEtNjM3ZS00YTE4LWI4ODAtOGQwYjEzM2FmMjk4LmpwZw==.jpg","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[74894,75189,95118,74880,23147,72287],"class_list":["post-411690","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-blockchain","tag-ledger","tag-nft","tag-transactions","tag-interview","tag-security"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/411690","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=411690"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/411690\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/411691"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=411690"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=411690"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=411690"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}