The Ethereum Foundation on May 12, 2026 launched Clear Signing, an open standard that replaces blind transaction approvals with human-readable summaries across wallets and hardware devices. The initiative unifies two technical standards — ERC-7730 and ERC-8176 — under a coordinated working group ...
The Ethereum Foundation on May 12, 2026 launched Clear Signing, an open standard that replaces blind transaction approvals with human-readable summaries across wallets and hardware devices. The initiative unifies two technical standards — ERC-7730 and ERC-8176 — under a coordinated working group that includes Ledger, Trezor, MetaMask, WalletConnect, Fireblocks, and Cyfrin, among others. Full ecosystem-wide implementation is targeted for end of Q2 2026.
The standard arrives after a series of high-profile exploits tied directly to blind signing, most notably the $1.4 billion Bybit hack in February 2025 — the largest single cryptocurrency theft on record. SlowMist's annual report logged approximately 200 security incidents in 2025 totaling $2.935 billion in losses, up 46% year-over-year. Signature phishing losses alone reached $494 million in 2024 before declining to $83.85 million in 2025, according to Scam Sniffer. The January 2026 figure spiked 207% over December, indicating the problem persists despite prior mitigation efforts. Clear Signing addresses the root UX failure that enables these attacks.
When an Ethereum user initiates a transaction or signs a message, most wallets display raw hexadecimal calldata — function selectors followed by encoded parameters. A Uniswap V3 swap, for example, renders as a function selector and a list of integers. The user sees no plain-language indication of what assets are moving, who receives them, or what permissions are being granted.
This is blind signing: approving machine-readable data that only highly technical users can interpret. The practical consequence is that the transaction approval step — designed as the user's last line of defense — provides no meaningful protection for the vast majority of wallet holders.
Quantified damage. The Bybit exploit on February 21, 2025 drained 401,347 ETH ($1.4 billion) from a cold wallet. According to forensic analysis by NCC Group and Halborn, attackers compromised a developer at Safe{Wallet} via social engineering, then injected malicious JavaScript into the Safe UI. When Bybit's multi-signature signers went to approve a routine transaction, the interface displayed legitimate-looking data while executing a modified payload containing hidden sweepETH and sweepERC20 functions. Multiple security firms, including Chainalysis and Mandiant, attributed the attack to the Lazarus Group.
The WazirX hack in July 2024 ($235 million) followed a similar pattern. SlowMist tracked approximately 200 security incidents in 2025 totaling $2.935 billion, a 46% increase from 2024 despite incident counts falling from 410 to roughly 200. The FBI's Internet Crime Complaint Center received 181,565 cryptocurrency fraud complaints in 2025 totaling more than $11 billion, up 22% from 2024.
Signature phishing — where users approve malicious token approvals or permit signatures — accounted for $494 million in losses in 2024, according to Scam Sniffer. That figure fell 83% to $83.85 million in 2025, with victim counts dropping 68% to 106,000. However, January 2026 saw a 207% spike over December 2025, with attackers shifting to fewer but higher-value targets.
The Clear Signing standard rests on two complementary Ethereum Improvement Proposals.
ERC-7730: Structured Data Clear Signing Format. First proposed by Ledger in February 2024, ERC-7730 defines a JSON descriptor format that enriches the type data contained in ABIs and schemas of structured messages — including EVM transaction calldata, EIP-712 messages, and EIP-4337 User Operations. Each descriptor file maps a contract's functions to human-readable field labels, formatting rules, and contextual intent descriptions.
When a wallet supports ERC-7730, it reads a contract's descriptor file alongside the raw calldata and reconstructs the transaction in plain language. A Uniswap V3 swap renders as "Send 1,000 USDC, receive minimum 0.42 WETH" rather than opaque hex. Descriptor files live in an open registry hosted on GitHub, currently managed by the Ethereum Foundation. Wallets independently decide which registry instances they trust, and any party can mirror or self-host.
The April 2026 release of ERC-7730 V2 expanded coverage to cross-chain use cases, software wallets, and confidential-token primitives developed in collaboration with Zama.
ERC-8176: Attestation Framework. ERC-8176 layers integrity verification on top of ERC-7730. After a descriptor is merged into the registry, independent auditors can publish cryptographically signed attestations confirming that the descriptor accurately represents what the underlying contract will execute. Wallets can then apply their own trust policies — for example, requiring at least two independent attestations before displaying a human-readable summary, or falling back to a warning screen for unattested contracts.
This two-layer design separates the translation problem (ERC-7730) from the trust problem (ERC-8176). A compromised or inaccurate descriptor can be flagged by auditors without requiring changes to the core format specification.
The working group coordinated by the Ethereum Foundation includes:
| Category | Organizations | |---|---| | Hardware Wallets | Ledger, Trezor | | Software Wallets | MetaMask, WalletConnect | | Institutional Infrastructure | Fireblocks | | Security Auditors | Cyfrin | | Privacy/Encryption | Zama | | Verification Tooling | Sourcify, Argot | | Smart Card Wallets | Keycard, ZKnox |
Ledger originated clear signing as an internal security project in 2021, formalized it as ERC-7730 in 2024, and transferred governance to the Ethereum Foundation in early 2026 to establish credible neutrality. The Foundation's Trillion Dollar Security Initiative now serves as the registry steward.
Tomáš Sušánka, CTO of Trezor, stated: "We welcome the Ethereum Foundation's Clear Signing standard as a critical security advancement for our entire industry."
Trezor has published the most specific timeline among participating wallet makers:
| Milestone | Target | |---|---| | Transaction decoding (hex to readable) | Beginning of Q2 2026 | | Full human-readable signing | End of Q2 2026 |
Ledger, which has supported clear signing internally since 2021, is expected to align with the unified standard on a similar timeline. MetaMask and WalletConnect have not published specific dates but are listed as active working group members with developer tooling contributions.
The Ethereum Foundation has released open SDKs and developer tooling for wallets, protocols, and auditors. Protocol developers can submit descriptor files to the ERC-7730 registry via pull request, with the Cyfrin security team and independent contributors reviewing submissions.
Clear Signing is one component of a broader Ethereum Foundation security program launched on February 9, 2026 in partnership with the Security Alliance (SEAL). The initiative introduced a live dashboard tracking Ethereum's security posture across six domains:
Separately, the Foundation launched a $1 million audit subsidy program, implemented in collaboration with Areta, Nethermind, and Chainlink Labs. The subsidy provides developers with access to over 20 audit firms at reduced cost, explicitly targeting smaller projects that cannot afford full-scope audits at market rates.
The Trillion Dollar Security gathering at Devconnect Buenos Aires in February 2026 set the agenda: evaluate the full-stack security posture, identify gaps and emerging risks, enable short-term execution by aligning ecosystem actors, and strengthen long-term security through coordination and shared standards.
Evaluating the potential economic impact of Clear Signing requires examining the loss categories it addresses.
Direct theft via blind signing exploits. The Bybit hack ($1.4 billion) and WazirX hack ($235 million) both exploited blind signing as a vector. However, neither attack would have been prevented by Clear Signing alone — the Bybit attack modified the UI itself, meaning the displayed data was already manipulated before reaching the signing step. Clear Signing with ERC-8176 attestations adds a verification layer that could make such UI manipulation detectable, but this depends on wallet-side implementation of attestation checks against an independent source of truth.
Phishing and approval scams. This is the category most directly addressed. The $83.85 million in signature phishing losses tracked by Scam Sniffer in 2025 overwhelmingly involved users approving transactions they could not read. A wallet displaying "Approve unlimited USDC spending by [unknown contract]" instead of raw hex data could materially reduce approval rates for malicious transactions.
Residual risk. Clear Signing does not address: private key theft, protocol-level exploits, social engineering that occurs before the transaction approval step, or attacks on chains that do not adopt the standard. The standard currently targets EVM-compatible chains. Non-EVM ecosystems (Solana, Cosmos, etc.) would require separate implementations.
The economic value proposition follows the framework of value distribution in blockchain ecosystems. Security infrastructure generates no direct fee revenue but operates as a public good whose absence imposes costs across all economic participants — users, protocols, and validators alike. The $2.935 billion in 2025 security losses represents value extracted from the ecosystem that did not flow to any productive participant.
Coverage gap. Clear Signing only works for contracts that have submitted descriptor files to the registry. Unregistered contracts will still display raw hex or trigger warning screens. Adoption is voluntary. There is no mechanism to compel protocol developers to submit descriptors.
Attestation bootstrapping. ERC-8176 requires a critical mass of independent auditors producing attestations. The initial pool — Cyfrin and the Foundation — is small. The subsidy program may help, but the attestation market's long-term economic model is undefined.
Cross-chain fragmentation. ERC-7730 V2 added cross-chain support, but each L2 and EVM-compatible chain requires its own descriptor submissions. With hundreds of active EVM chains, descriptor coverage will be uneven for the foreseeable future.
False sense of security. If users learn to trust human-readable summaries without verifying attestation status, a compromised or inaccurate descriptor could itself become an attack vector. The standard's security ultimately depends on the integrity of the attestation layer.
Clear Signing represents an infrastructure-level response to a UX failure that has persisted since Ethereum's earliest days. The economic case is straightforward: billions in annual losses trace back to users approving transactions they cannot read. The technical solution — JSON descriptors verified by independent attestations — is conceptually simple but operationally complex, requiring sustained coordination across wallet providers, protocol developers, auditors, and the Foundation itself.
The standard's long-term impact depends on two variables: descriptor coverage (how many contracts participate) and attestation depth (how many independent auditors verify each descriptor). Both are currently thin. The working group's composition — spanning the major hardware and software wallet providers — suggests the demand side is committed. The supply side, meaning protocol developer submissions and auditor capacity, is the binding constraint.
Whether Clear Signing materially reduces annual loss figures will not be measurable until at least Q4 2026, after full wallet rollouts are complete and sufficient descriptor coverage exists across major DeFi protocols. The $1 million audit subsidy may accelerate adoption, but at current audit market rates, that figure covers approximately 10-20 full-scope reviews.
The initiative is best understood not as a single fix but as the first standardized layer in what the Trillion Dollar Security Initiative frames as a full-stack security posture for an ecosystem managing hundreds of billions in value.