Patrick Collins
@patrickalphac
How do you know what you're signing on your hardware wallet is correct? Asking this question could have saved Radiant Captial $50M last year, and could save you even more. If you're on a security council, DAO, or you own a hardware wallet, you need to know this π
5 replies
15 recasts
55 reactions
Patrick Collins
@patrickalphac
A big thanks to @pcaversaccio for creating the original tool to do this. When you sign something with your multi-sig, you get an output like this. You MUST know what this is representing in order to sign it. Radiant didn't verify this signature, and it cost them $50M
1 reply
0 recast
6 reactions
Patrick Collins
@patrickalphac
You can use the safe_hashes tool to understand if this is indeed the correct data. After running the tool, it'll give you an output of what transaction is being called and the expected signature hash.
1 reply
0 recast
5 reactions