Ledger CTO warns crypto users about the dangers of 'blind signing'
With the recent attack on OpenSea highlighting blockchain vulnerabilities, Charles Guillemet, the chief technology officer of Ledger warns users about “blind signing,” which he defines as “consenting a transaction to be signed blindly, without understanding what it means.” In an interview with Cointelegraph, Guillemet broke down the problems and highlighted issues with blind signing. The Ledger chief technology officer notes that consenting to transactions requires signing a message to be sent to the blockchain. A user is the only one capable of signing transactions with the private key, while others can verify if its correct. “The issue is that this message is not intelligible by default. Its a digital payload,” says Guillemet. Guillemet also explained that when a coin transfer is signed, it‘s normally supported by a wallet that “properly parses the payload and displays its intent.” However, when it comes to signing complex interactions with smart contracts, Guillemet says that “parsing the display is not always properly supported and you have no choice but consenting blindly for a transaction that you don’t understand.” “It‘s risky because you can think you’re signing a transaction to move part of your funds to address A while you actually sign a transaction to move all your