The Ethereum Foundation on May 12, 2026 launched Clear Signing, a security standard designed to replace blind signing — the practice of approving raw hexadecimal transaction data without human-readable context. The standard, built on ERC-7730 and ERC-8176, converts opaque transaction payloads int...
"Attackers have been exploiting this relentlessly. There has not been a widely accessible security feature capable of distinguishing malicious smart contracts from legitimate transactions. Clear Signing directly addresses this by making transactions human-readable before approval." — Tomáš Sušánka, CTO, Trezor
The Ethereum Foundation on May 12, 2026 launched Clear Signing, a security standard designed to replace blind signing — the practice of approving raw hexadecimal transaction data without human-readable context. The standard, built on ERC-7730 and ERC-8176, converts opaque transaction payloads into plain-language summaries before users approve them. Twelve organizations — including Ledger, Trezor, MetaMask, WalletConnect, and Fireblocks — have committed to implementation.
The initiative follows $3.4 billion in crypto theft documented by Chainalysis in 2025, with wallet compromise and phishing accounting for approximately 86% of losses in the first half of that year, per CertiK. The February 2025 Bybit hack — $1.5 billion drained from a cold wallet after attackers manipulated a signing interface — provided the catalyst. Signers approved a transaction that looked routine on screen but executed a malicious contract redirect. They could not verify what they were signing because nothing in the approval flow required human-readable confirmation.
The Solana Foundation has begun developing a parallel standard inspired by ERC-7730, suggesting the approach may become cross-chain infrastructure rather than an Ethereum-only feature.
Blind signing occurs when a wallet presents a transaction as raw hexadecimal data — a string of characters that conveys no meaningful information to a human user — and the user approves it without understanding what it authorizes. The practice has been the default across most wallet implementations since Ethereum's launch.
The financial toll is documented across multiple tracking frameworks:
CertiK's H1 2025 data provides the clearest breakdown of how these losses distribute by attack type. Across 344 incidents totaling $2.47 billion:
| Attack Vector | Incidents | Losses | Share of Total | |---|---|---|---| | Wallet compromise | 34 | >$1.7B | ~69% | | Phishing | 132 | >$410M | ~17% | | Code vulnerability | 47 | $235.78M | ~10% | | Other on-chain | ~131 | ~$154.22M | ~6% |
Wallet compromise and phishing — both categories where blind signing is a contributing factor — accounted for approximately 86% of documented losses by dollar value. The pattern is consistent: social engineering targeting the signing layer outperforms code-level exploits by a factor of roughly 9:1 in financial impact.
Approval phishing specifically — where attackers trick users into signing token approval or permit messages — has generated at least $1 billion in cumulative losses since 2021, according to Chainalysis research.
The Clear Signing framework consists of four integrated components delivered by a working group of 12 organizations:
1. ERC-7730 (Transaction Descriptor Standard) Originally proposed by Ledger in 2024, ERC-7730 defines a JSON format for structured transaction descriptors. When an application submits a transaction, the descriptor translates the raw calldata into human-readable fields: what function is being called, what tokens are being moved, what permissions are being granted, and to which addresses.
The standard operates externally to transactions themselves — descriptors are not embedded in the transaction payload. This allows the system to support both existing deployed contracts and new applications without requiring on-chain modifications.
2. ERC-8176 (Attestation Framework) An integrity verification layer using the Ethereum Attestation Service. Independent security auditors review descriptor files and publish on-chain attestations confirming their accuracy. This creates a verifiable audit trail — wallets can check whether a descriptor has been reviewed before displaying it to users.
3. Decentralized Registry The Clear Signing registry at clearsigning.org stores descriptor files. The registry is hosted by the Ethereum Foundation but is designed to be independently mirrorable. Anyone can contribute descriptors; independent reviewers verify them through attestations; wallets select which sources they trust.
4. Developer Tooling The Ethereum Foundation funds reference implementations in Rust and TypeScript, enabling wallet developers to integrate clear signing support without building parsers from scratch.
The result: instead of seeing 0xa9059cbb000000000000000000000000..., a user sees "Transfer 150 USDC to 0x1234...5678 on Uniswap V3." The wallet displays structured, verified information. The user confirms or rejects based on understanding, not trust.
The February 21, 2025 Bybit hack provided the specific failure case that accelerated Clear Signing's development. According to NCC Group's technical analysis, the attack chain was:
The attack did not exploit a smart contract vulnerability or break cryptography. It exploited the gap between what signers saw and what they signed. As Blockaid's analysis stated: "Signers are not verifying what they are signing — they are merely verifying that they are signing."
Clear Signing addresses this specific vector. Under ERC-7730, the wallet would parse the actual transaction calldata against verified descriptors and display the real operation — a contract upgrade, not a token transfer — regardless of what a compromised UI attempted to show.
The Bybit incident was not isolated. Similar interface manipulation attacks hit Radiant Capital (compromised 3 of 11 multisig signers through interface deception) and WazirX in the same period.
Twelve organizations are listed as contributors to the Clear Signing working group:
| Organization | Role | Status | |---|---|---| | Ledger | ERC-7730 originator; already implements via Secure Element | Live | | Trezor | Firmware and companion app updates | Transaction decoding early Q2 2026; full readable signing end Q2 2026 | | MetaMask | Wallet integration | In development | | WalletConnect | Protocol-level support | In development | | Fireblocks | Institutional custody integration | In development | | Cyfrin | Security auditing of descriptors | Active | | Sourcify | Contract verification tooling | Active | | ZKnox | Contributor | Active | | Zama | Contributor | Active | | Keycard | Hardware wallet support | In development | | Argot | Contributor | Active |
Ledger is the furthest along. Its hardware wallets, enterprise multisig product, and Direct Access platform already implement Clear Signing using the company's Secure Element and Trusted Display technology. Ledger built the original specification internally in 2023, formalized it as ERC-7730 in 2024, and transferred governance to the Ethereum Foundation in May 2026 to establish credible neutrality.
Trezor CTO Tomáš Sušánka confirmed a two-phase rollout: transaction decoding by early Q2 2026, with full human-readable signing by end of Q2 2026.
Clear Signing operates under the Ethereum Foundation's Trillion Dollar Security Initiative, which serves as the credibly neutral steward of the registry infrastructure. The initiative's scope extends beyond Clear Signing:
The $1 million audit subsidy is modest relative to the $3.4 billion in 2025 theft, but it targets the descriptor verification layer specifically — the point at which human-readable translations are validated for accuracy.
Ledger CTO Charles Guillemet noted on social media that the Solana Foundation has begun developing a clear signing standard inspired by ERC-7730. A Solana Improvement Document (SIMD) discussion for "calldata and EIP-712 digest equivalent" appeared on the Solana Foundation's GitHub, indicating formal specification work is underway.
If both Ethereum and Solana adopt compatible clear signing frameworks, the standard could evolve into cross-chain infrastructure. This matters because the blind signing problem is not Ethereum-specific — any chain where users approve opaque transaction data faces the same vulnerability class.
The economic implication: wallet providers supporting multiple chains could implement a single descriptor framework rather than chain-specific solutions, reducing integration cost and accelerating adoption.
Clear Signing is not a complete solution to transaction security. Several constraints apply:
Descriptor coverage gaps. Clear Signing works only for transactions where a verified descriptor exists. New contracts, obscure protocols, and rapidly deployed DeFi strategies may lack descriptors at launch. Users interacting with undescribed contracts would still face opaque data — though wallets could flag the absence of a descriptor as a warning signal.
Attestation quality. The system's integrity depends on the competence and independence of descriptor reviewers. A poorly reviewed or maliciously submitted descriptor could provide a false sense of security. ERC-8176 attestations create accountability, but the auditor ecosystem is nascent.
Adoption friction. MetaMask, WalletConnect, and Fireblocks have committed to integration but have not published implementation timelines. Trezor's Q2 2026 target is the only firm date outside Ledger's existing deployment. The standard's value scales with adoption — partial coverage creates inconsistent user experience.
Interface-layer attacks persist. Clear Signing addresses the signing layer, but the Bybit attack also involved infrastructure compromise (AWS S3 bucket injection). A compromised wallet application could theoretically suppress or alter clear signing displays. Hardware wallets with trusted displays (Ledger, Trezor) mitigate this; software wallets do not.
Clear Signing addresses a structural deficiency that has existed since Ethereum's inception: transactions are signed by humans who cannot read them. The economic cost of this deficiency is documented at $3.4 billion in 2025 alone, with phishing and wallet compromise — both enabled by opaque signing flows — dominating loss categories.
The standard's architecture is sound in design: open descriptors, independent attestation, neutral registry hosting. Its effectiveness will be determined by adoption speed and descriptor coverage. Ledger's three-year head start gives it first-mover advantage in implementation. The rest of the ecosystem is at various stages of commitment without firm delivery dates.
The Ethereum Foundation's framing of this as infrastructure for "trillion dollar security" reflects a specific economic calculation: Ethereum cannot serve as institutional settlement infrastructure if users — including professional treasury operators at exchanges — cannot verify what they are approving. The Bybit hack demonstrated that even sophisticated multisig configurations fail when the signing layer is opaque.
Whether Clear Signing reduces aggregate losses will be measurable within 12 months. The data infrastructure exists (Chainalysis, CertiK, PeckShield all track losses by vector). The question is whether adoption reaches sufficient coverage before the next major signing-layer exploit.