When a site says “sign”, it is asking your keys to produce a proof that they saw a particular blob of data and agreed. The blob might be a bitcoin send. It might be an Ethereum transaction that moves ETH. It might be a permission for a contract to pull tokens later. It might be a login that never touches the chain. It might be an off-chain order that a marketplace will settle later. The button is often the same. The blob is not. Treating every prompt as a handshake is how people get drained without “losing the seed”.
How crypto wallets actually work is the keys. DeFi is software with rules you cannot call support about is the approval as a front door. Hardware wallets are a practice is why the small screen exists. The security checklist is the rushed-click version. This page is the prompt, so a pretty “Sign in with Ethereum” cannot do the explaining for you.
Proof of a message, not proof of a website
A valid signature means the key that controls an address produced this exact message. It does not mean the website is honest, the contract is audited, or the destination is the one you had in your head. Malware can swap an address. A lookalike domain can ask for the same-looking click. A wallet that only shows “I agree” is asking you to trust the laptop. A device that shows the destination, the asset, and the amount is asking you to use your eyes.
Bitcoin signing is usually a transaction: these coins, this destination, this fee. If you sign it and it broadcasts, the coins can move. There is no separate “login signature” in the Ethereum sense. Ethereum (and chains that copied its account model) mixed several jobs into one key: pay gas, send ETH, call contracts, and sign messages that never become a transaction. That mix is convenience. It is also why the warning text matters more than the brand on the tab.
Four prompts that are not one prompt
Connect is often just the site reading your address. Sometimes it already wants a signature. “Sign in” / “Sign-In with Ethereum” is usually a message that proves you control the address right now, so the site can give you a session. A session is a website login. It should not move coins. It can still be used to list an NFT or to post in your name if the site is the marketplace. Read whether you are authenticating to a shop or authorising a spend.
A send is a transaction: value leaves, or a contract runs, and you pay gas. On-chain fees are an auction; a revert can still cost. An approval is a transaction that says a named contract may pull a token later, sometimes with no cap. Permit-style signatures can grant a similar pull without a separate approval transaction — still a permission, still a blob you should read. NFT listings can be signatures that stay valid until you cancel. The NFT guide is the shopping version of that sentence.
“Sign to continue” is not a description of the blob.
Unlimited is convenient for the app and convenient for whoever holds the app tomorrow.
Blind signing — confirming without readable details — is the laptop remaining in charge.
A surprise token in the wallet is often bait for a new prompt. Ignore the token. Do not chase it to a site.
What the wallet is trying to tell you
Good wallet software now tries to decode the blob: transfer, approve, set-all-tokens, permit, typed data. Those labels are a best effort. They can be wrong, incomplete, or spoofed by a contract that does something else after the first call. If the warning is vague and the amount would annoy you to lose, you are not ready. Simulate if the wallet offers it. A signature that “fails” on-chain still happened as a request; the meter may have run.
Pectra, in May 2025, made it easier for ordinary accounts to opt into contract-like behaviour. That is a wallet-and-UX story, not a reason to “upgrade your ETH”. New flows will ask you to sign things that look like setup. Phishing will copy those flows. The Pectra news piece is the dated fork. This paragraph is why a new prompt after a fork is not automatically the official one.
Who is asking, and from where
A hardware device signs without giving the laptop the key. It does not save you if you confirm a destination you did not check. A browser extension is hot: it can see the internet, and some of them have been the hole. An exchange login is not this page — that is a password plus two-factor, and an IOU. Do not paste a recovery phrase into a prompt that claims it is a signature. Phrases are backups. Signatures are proofs. Mixing them is the original support-scam.
Revoking an approval you no longer use is hygiene. It is a transaction, so it costs. It is not a ritual you owe a stranger in DMs. If you already signed a bad permission, the checklist’s “when something already feels wrong” is the next paragraph: known-good machine, revoke, move what is left to a phrase that never touched the bad device. Then stop. Tired people sign the second trap.
What this guide will not do
It will not walk through exploit steps or paste example payloads. It will not rank wallets. It will not tell you never to sign. Using Ethereum applications requires signatures. Using them carefully requires reading. If the blob is a send you intended, on the network you meant, to an address you checked, the proof is doing its job. If you cannot say which of the four prompts it is, wait. The chain will still be there. The fake “verify wallet” will not.
Nothing here is an instruction to connect, approve, mint, buy, or sell. A signature is a proof about a message. Make the message the one you meant.






