Hey guys, I need some advice. I'm asked to prove I have coins for a deal but want to keep my wallet safe. They’re asking me to sign a message like "hi, 3/17/2024". Is that risky with a Trezor?
Is it Safe to Sign Messages?
19 replies 437 views
chr1swhal3Full Member
Posts: 60 · Reputation: 254
#2Aug 3, 2018, 03:13 PM
Not really a danger here. Signing proves you own the keys but they can't steal your coins just from that. Just be careful who you give info to.
Right, but remember, signing messages is different from signing transactions. If you stick to message signing and not transaction IDs, you should be good.
Exactly. Just be cautious. Signing a transaction ID with the message signing method won't work anyway. Wouldn't hurt to specify what the message is for.
Yeah, it shows ownership of the public key, but also be careful. I’m iffy about signing messages after reading some horror stories. Ethereum’s signing might be more risky.
Privacy matters too. Consider transferring what you want to prove to a new wallet first. You don’t wanna signal how much you hold.
AtomicLordMember
Posts: 34 · Reputation: 184
#7Aug 5, 2018, 01:15 AM
Good point. Scammers might just wanna see how much you have to target you. Better safe than sorry.
For sure, imagine this: I get you to sign a message, then pose as you to someone else. That’s a scam waiting to happen.
I thought about that too. I think this person is legit, I know them IRL and they’ve got people who can vouch for them.
chrisomegaFull Member
Posts: 158 · Reputation: 631
#10Aug 8, 2018, 02:58 AM
True, but trust can be tricky. If you’re signing, make sure it’s in your own wallet, not using their software. That's where risks creep in.
Signing in an online wallet has worked fine for me before, but staying cautious is key. Just don’t expose your keys.
Signing doesn’t involve nodes anyway. It’s just a digital signature creation. You don’t need any internet connection for that.
chrisomegaFull Member
Posts: 158 · Reputation: 631
#13Aug 8, 2018, 09:09 AM
Yeah, I meant using a Bitcoin Core wallet. Easy to sign in a few steps there, just a matter of using the right tool.
Bitcoin signing function is pretty straightforward. Just don’t confuse it with transaction signing or you could mess up.
For peace of mind, consider doing it on an air-gapped device. That ensures your private key stays safe.
AtomicLordMember
Posts: 34 · Reputation: 184
#16Aug 8, 2018, 05:42 PM
Exactly! Signing on your own device keeps your keys protected, just make sure to use good software.
If you’ve got solid software, your signature won’t leak anything. Just don’t sign with a random nonce, that could cause issues.
gwei_blockNewbie
Posts: 185 · Reputation: 37
#18Aug 9, 2018, 03:34 AM
Right! Signed messages shouldn’t reveal your private key unless there’s a serious flaw in your software.
ben.matrixNewbie
Posts: 3523 · Reputation: 35
#19Aug 9, 2018, 08:21 AM
Let’s not forget: signing should always come with caution. Know who you’re dealing with and how the signing process works.
ben.matrixNewbie
Posts: 3523 · Reputation: 35
#20Aug 9, 2018, 10:35 AM
Agreed. That’s the bottom line. Better to double-check everything than regret it later.
Related topics
- Issues with ripemd160 on Ubuntu 22 9
- New Bitcoin Improvement Proposal with $100 Reward 9
- Clipboard Vulnerabilities in Cryptocurrency Transactions 8
- Understanding the Differences Between Traditional and Simplified Chinese Mnemonics 6
- Running Bitcoin Core on a Laptop with Limited Storage 20
- Exploring Blockstream's Satellite Tech and Its Potential 22