← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Ethereum Clear Signing Targets $1.4B Blind Signing Gap

Zephyra|May 16, 2026|BPF
EXECUTIVE SUMMARY

The Ethereum Foundation on May 12, 2026 launched Clear Signing, an open standard built on ERC-7730 and ERC-8176, designed to replace blind signing — the practice of approving transactions rendered as unreadable hexadecimal strings — with human-readable descriptions of contract interactions. The i...

"Trezor's roadmap targets transaction decoding support by early Q2 2026, with full readable-signing support by the end of the same quarter." — Tomáš Sušánka, CTO, Trezor

Executive Summary

The Ethereum Foundation on May 12, 2026 launched Clear Signing, an open standard built on ERC-7730 and ERC-8176, designed to replace blind signing — the practice of approving transactions rendered as unreadable hexadecimal strings — with human-readable descriptions of contract interactions. The initiative, coordinated through the Foundation's Trillion Dollar Security Initiative, transfers governance of a standard originally developed by Ledger in 2023 to a credibly neutral steward and deploys a decentralized descriptor registry, attestation framework, and developer SDKs in Rust and TypeScript.

The stakes are quantifiable. According to Chainalysis, cryptocurrency theft totaled $3.4 billion in 2025. Social engineering — primarily phishing attacks exploiting blind signing — accounted for 55.3% of losses, or $1.39 billion, per Sentora data. The $1.5 billion Bybit breach in February 2025, the largest single theft in crypto history, was executed by North Korea's Lazarus Group specifically by manipulating what signers saw on their hardware devices during a multisig approval. A Stanford Blockchain Review analysis attributed $500 million of the $2.2 billion stolen in 2024 directly to blind signing vulnerabilities.

Clear Signing does not alter transaction structure, broadcasting, or on-chain settlement. It operates at the wallet presentation layer, mapping raw calldata to plain-language descriptions via JSON descriptors stored in an off-chain registry. Whether this standard achieves sufficient adoption to materially reduce losses depends on wallet integration timelines, developer submission rates to the registry, and whether institutional custodians enforce it as a requirement.

Table of Contents

  1. The Blind Signing Problem: Quantifying the Losses
  2. Technical Architecture: How ERC-7730 and ERC-8176 Work
  3. The Bybit Precedent: $1.5 Billion Lost to an Invisible Contract Change
  4. Industry Adoption and Working Group Composition
  5. The Attestation Layer: Auditors as Cryptographic Guarantors
  6. The Economic Case: Who Pays and Who Benefits
  7. Limitations and Open Questions
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

The Blind Signing Problem: Quantifying the Losses

Blind signing refers to the approval of blockchain transactions where the signer cannot verify the actual operation being authorized. Most wallet interfaces display transaction data as raw hexadecimal strings — sequences of characters that convey no meaningful information to the user about what assets are moving, where they are going, or what permissions are being granted.

The financial damage is documented across multiple data sources:

  • 2025 total crypto theft: $3.4 billion, per Chainalysis.
  • Social engineering share: 55.3% of 2025 losses ($1.39 billion) attributed to phishing and manipulation, per Sentora.
  • 2024 blind signing losses: $500 million of $2.2 billion total theft attributed directly to blind signing, per Stanford Blockchain Review.
  • North Korean theft (2025): $2.02 billion stolen by DPRK-linked groups, a 51% year-over-year increase, accounting for 76% of all service compromises.
  • Phishing volume (Q1 2026): Binance intercepted 22.9 million phishing attempts. Scam Sniffer reported a 207% increase in signature phishing losses in January 2026 versus December 2025.

The pattern is consistent: attackers increasingly target the human approval step rather than exploiting smart contract code directly. When a user cannot distinguish a legitimate Uniswap swap approval from a malicious infinite token allowance, the security model of the underlying blockchain is irrelevant.

Technical Architecture: How ERC-7730 and ERC-8176 Work

Clear Signing consists of three components deployed as an integrated system:

1. ERC-7730: JSON Descriptor Format

ERC-7730 defines a standardized JSON schema that maps smart contract function calls and EIP-712 messages to human-readable descriptions. A descriptor file specifies, for each function selector in a given contract, what the transaction does in plain language.

For example, instead of a wallet displaying:

Contract: 0x7a250d5630B4cF539739dF2C5dAcb4c659F2488D
Data: 0x38ed173900000000000000000000000000000000...

A wallet implementing ERC-7730 would display:

Swap 500 USDC for at least 0.21 ETH on Uniswap V2 Router

Descriptors are stored off-chain in a decentralized, mirrorable registry hosted under Ethereum Foundation infrastructure. Any developer can submit descriptors for their contracts. The registry is not a gatekeeper — it is a distribution mechanism.

2. ERC-8176: Attestation Framework

ERC-8176 adds a verification layer. Independent security auditors can cryptographically attest that a given descriptor accurately reflects the behavior of the underlying smart contract code. Attestations are recorded using the Ethereum Attestation Service (EAS), creating a chain of accountability.

This addresses a second-order risk: if descriptors themselves could be malicious or inaccurate, they would simply move the attack surface from raw calldata to human-readable text. The attestation layer creates a market for descriptor verification.

3. Developer Libraries

SDKs in Rust and TypeScript were released alongside the standard, reducing integration friction for wallet developers. The libraries handle descriptor fetching, parsing, and rendering.

The Bybit Precedent: $1.5 Billion Lost to an Invisible Contract Change

The February 21, 2025 Bybit breach serves as the canonical case study for blind signing risk at institutional scale.

Lazarus Group operatives compromised a developer machine at Safe{Wallet}, the multisig provider used by Bybit for cold storage. They injected malicious JavaScript into the Safe UI that altered what Bybit's multisig signers saw on screen during a routine cold-to-warm wallet transfer. The displayed transaction appeared legitimate. The actual transaction authorized a contract upgrade that gave the attackers full control of the cold wallet.

The signers — multiple individuals using hardware wallets — blind-signed the messages, trusting the Safe web interface rather than independently verifying the raw transaction data on their hardware devices. The result: 401,347 ETH ($1.5 billion) drained in a single operation.

According to NCC Group's post-incident analysis, the attack exploited the fundamental disconnect between what a user's screen displays and what the blockchain will execute. Hardware wallets, designed as a security boundary, displayed hexadecimal data that no human could reasonably interpret. The signers had no practical means to verify the transaction's true intent.

This is the problem Clear Signing targets. Had ERC-7730 descriptors been in place and enforced, the hardware wallet screens would have displayed something resembling: "Upgrade Safe implementation contract to address 0x..." — a description that would have immediately flagged the operation as anomalous during a routine transfer.

Industry Adoption and Working Group Composition

The Clear Signing Working Group spans hardware wallet manufacturers, software wallets, institutional custodians, and security firms:

| Category | Participants | |----------|-------------| | Hardware Wallets | Ledger, Trezor, Keycard | | Software Wallets | MetaMask, WalletConnect | | Institutional Custody | Fireblocks | | Security/Audit | Cyfrin, Zama, ZKnox | | Infrastructure | Sourcify, Argot | | Governance | Ethereum Foundation (neutral steward) |

Ledger has already implemented Clear Signing across its consumer wallet, Enterprise Multisig, and Direct Access products. Trezor's CTO confirmed a target of full readable-signing support by June 30, 2026. MetaMask participation signals potential integration across its estimated 30+ million monthly active users.

Fireblocks' inclusion is significant for institutional adoption. As a custody platform handling over $6 trillion in cumulative transfers, its implementation would expose institutional treasury operations to clear signing by default.

The Ethereum Foundation simultaneously launched a $1 million audit subsidy program to help open-source projects fund professional code reviews — tying user-facing transaction security to developer-side code assurance.

The Attestation Layer: Auditors as Cryptographic Guarantors

ERC-8176 creates an economic role for security auditors that did not previously exist in a standardized form. Auditors review descriptor files against contract source code and, if satisfied, produce a cryptographic attestation recorded on-chain via EAS.

Wallets can then display trust signals to users: "This transaction description has been attested by [Auditor Name]." The system creates a competitive market for descriptor verification, where auditors stake their reputation on the accuracy of their attestations.

This is structurally analogous to certificate authorities in TLS/HTTPS — the green padlock that tells browser users a website's identity has been verified. Whether the crypto ecosystem develops comparable trust hierarchies remains to be seen. The failure modes of certificate authorities — including compromised CAs and revocation delays — offer instructive precedents.

The registry is designed to be independently mirrorable, preventing any single point of failure or censorship. Multiple parties can host registry copies, and wallets can source descriptors from any mirror.

The Economic Case: Who Pays and Who Benefits

Viewed through an economic value framework, Clear Signing redistributes costs and benefits across the ecosystem:

Cost bearers:

  • Smart contract developers must submit and maintain descriptor files for their contracts. This is an ongoing operational cost, though the ERC-7730 format is designed to minimize maintenance burden.
  • Wallet developers must integrate descriptor parsing and rendering. SDK availability in Rust and TypeScript reduces but does not eliminate integration effort.
  • Security auditors invest time reviewing descriptors and producing attestations. The economic model for compensating this work is not yet defined at protocol level.

Beneficiaries:

  • End users gain the ability to verify transaction intent before signing. The estimated $1.39 billion in annual social engineering losses represents the upper bound of economic value at stake.
  • DeFi protocols benefit from reduced phishing-driven reputation damage and user loss.
  • Institutional custodians gain an auditable layer of transaction verification that aligns with compliance requirements.
  • The broader ecosystem retains capital that would otherwise exit through theft, potentially improving net economic activity on-chain.

The standard does not capture value for itself. There are no fees for descriptor submissions, registry access, or standard usage. This is consistent with the Ethereum Foundation's public-goods approach but raises questions about long-term maintenance funding. The $1 million audit subsidy is a one-time allocation, not a sustainable revenue model.

Limitations and Open Questions

Clear Signing is not a universal solution. Several constraints are worth noting:

1. Coverage gap. The standard works only for contracts that have submitted descriptors to the registry. At launch, coverage is limited. The long tail of DeFi protocols — smaller projects, newer deployments, unverified contracts — will likely lack descriptors for months or years.

2. Descriptor accuracy. Without attestation, a descriptor is only as trustworthy as its author. A malicious project could submit descriptors that misrepresent contract behavior. The attestation layer mitigates but does not eliminate this risk, as attestor selection and accountability mechanisms are still maturing.

3. Adoption fragmentation. Clear Signing is Ethereum-specific. Solana, BNB Chain, Avalanche, and other ecosystems would require separate implementations. Cross-chain users remain exposed on non-participating networks.

4. Upgradeable contracts. Contracts that use proxy patterns can change their underlying logic without changing their address or function selectors. A descriptor accurate at time of attestation may become misleading after a contract upgrade. The standard does not yet specify how descriptors should handle upgradeable contracts.

5. Hardware wallet limitations. While Clear Signing improves screen-level readability, the fundamental trust model still depends on users actually reading and comprehending the displayed information. User behavior research suggests many signers develop "approval fatigue" and click through security prompts regardless of content.

Key Takeaways

  • The Ethereum Foundation launched Clear Signing (ERC-7730 + ERC-8176) on May 12, 2026 as an open standard to replace blind signing with human-readable transaction descriptions.
  • Blind signing contributed to an estimated $500 million in direct losses in 2024 and was the attack vector in the $1.5 billion Bybit breach in February 2025.
  • The working group includes Ledger, Trezor, MetaMask, Fireblocks, WalletConnect, Cyfrin, and others. Ledger has already implemented the standard; Trezor targets full support by June 30, 2026.
  • The attestation framework (ERC-8176) creates a new economic role for security auditors as cryptographic guarantors of descriptor accuracy.
  • Coverage is currently limited to contracts with submitted descriptors. The standard does not address cross-chain environments, upgradeable contract risks, or user approval fatigue.
  • The Ethereum Foundation allocated $1 million in audit subsidies alongside the launch.
  • Binance intercepted 22.9 million phishing attempts in Q1 2026. Signature phishing losses rose 207% in January 2026 versus December 2025, per Scam Sniffer.

Conclusion

Clear Signing represents the most coordinated attempt to date to address a vulnerability class responsible for billions in cumulative losses. Its technical architecture — off-chain descriptors, cryptographic attestations, and neutral governance — is well-designed for the specific problem of transaction readability. The participation of major hardware wallet manufacturers, MetaMask, and institutional custodian Fireblocks suggests the standard has a credible path to meaningful adoption within the Ethereum ecosystem.

The standard's impact, however, will be determined by unglamorous operational factors: how quickly developers submit descriptors, how rigorously auditors attest them, how thoroughly wallets integrate the rendering, and whether users actually read what is displayed. The $1.5 billion Bybit breach was not caused by a lack of standards — it was caused by signers who trusted their screens over their skepticism. Clear Signing changes what the screen shows. Whether it changes human behavior is a separate question that no JSON specification can answer.

For the Ethereum ecosystem, the economic logic is straightforward. If Clear Signing prevents even 10% of the estimated $1.39 billion in annual social engineering losses, it delivers $139 million in retained capital — orders of magnitude more than the cost of implementation. The standard captures none of that value for itself, positioning it as a public good in the most literal sense: a non-rival, non-excludable improvement to ecosystem security infrastructure.

Sources & References

  1. Ethereum Foundation Blog — Clear Signing Announcement — Official launch post for Clear Signing standard, May 12, 2026.
  2. Ledger — Stewardship of Clear Signing Passed to Ethereum Foundation — Details on governance transfer from Ledger, May 2026.
  3. CoinDesk — Ethereum Foundation Unveils New Clear Signing Standard — Coverage of launch and Trillion Dollar Security Initiative, May 12, 2026.
  4. Stanford Blockchain Review #72 — The Blind Signing Problem — Research attributing $500M in 2024 losses to blind signing. By Elliot Friedman (Kleidi) and Tesvara Jiang (Stanford), May 2025.
  5. Chainalysis — 2025 Crypto Theft Reaches $3.4 Billion — Annual crypto theft data and DPRK attribution.
  6. NCC Group — In-Depth Technical Analysis of the Bybit Hack — Forensic analysis of the $1.5B blind signing exploit.
  7. Scam Sniffer — 2025 Crypto Phishing Losses — Annual phishing loss data and signature type breakdown.
  8. CryptoNews — Ethereum's Clear Signing Standard Tackles Blind Transactions — Technical analysis including Binance Q1 2026 phishing data.
  9. Blockonomi — Ethereum Launches Clear Signing Standard — Working group membership and implementation details.
  10. ERC-7730 Specification — Ethereum Improvement Proposals — Technical specification of the standard.