No immediate paid transaction does not mean no risk. Inspect request type, domain, network, contract, spender, value and expiry. Reject requests whose scope your wallet cannot explain.
Read the message
Readable is not safe
Deferred permission
Login
A login message should explain service, account and session context. Do not infer its purpose from the “connect” button: inspect the actual request. A site can substitute a permission message.
Structured data
EIP-712 structures signed fields for display. It does not endorse the contract or site. Compare chain and verifying contract with independently obtained documentation; malicious requests can use a valid format.
Permit
Some tokens allow a signed message to create an allowance. Another party may submit it later under contract rules. Inspect spender, value, nonce and deadline. In ERC-2612, deadline limits permit submission, not automatically the lifetime of the resulting allowance.
NFT operators
An operator approval may cover all your NFTs in one contract, not just one item. Inspect collection, operator and actual rights. “Free” can describe immediate cost without describing authority granted.
After an error
Keep request fields without publishing secrets. Disconnecting, revoking allowance and invalidating signatures are distinct. Response depends on contract and nonce; use a verified procedure. Exposed keys require more than revocation.
A concrete verification
Check domain, network, spender, amount and deadline: a gasless signature can enable later spending.
Compare signing requests
| Mechanism | Potential authority | Inspect |
|---|---|---|
| Login | Authenticate a session under the message | Service, account, context and duration |
| approve (ERC-20) | Recorded allowance for a spender | Token, spender, amount |
| permit (ERC-2612) | Create allowance after message submission | Contract, value, nonce, deadline |
| setApprovalForAll (ERC-721) | Operator over all your NFTs in the contract | Collection, operator, enable or disable |
Frequently asked questions
Can a free signature be dangerous?
Yes. It may authorize later actions without an immediate transaction.
Does an expired permit remove an existing allowance?
Not automatically in ERC-2612: its deadline concerns submission.
Does disconnecting cancel signatures?
No. It does not automatically revoke recorded rights or signed messages.
Is a login signature equivalent to EIP-7702 delegation?
No. Login authenticates according to its message; EIP-7702 authorization can delegate account code. Delegation can persist and the original key retains control. Check request type and scope; no immediate gas payment does not imply harmlessness.
Verifiable sources
Ethereum.org — Signing safety
EIP-712 — Typed structured data signing
ERC-2612 — Signed token permits
ERC-20 — Token allowances
ERC-721 — NFT operators
EIP-7702 — Account code delegation
Independent educational content reviewed against primary documentation. No personalized recommendation or promise of returns. Updated October 6, 2026


