New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

DeFi Can’t Move Forward Without Clear Signing: Let Me Change Your Mind | Devcon SEA

DevconTue, Oct 7, 2025, 12:00 AM

Blind signing has been the default way of signing transactions in DeFi, but let’s be honest: as an industry we are shooting ourselves and our users in the foot by continuing to throw caution to the wind. We want to make it easy to implement clear signing for every dAapp, minimizing the work required for developers to make the ecosystem more approachable and secure. Blind signing is an existential threat to what we do, it’s time to change it, and we need your help. Speaker(s): Charles Guillemet Skill level: Intermediate Track: Security Keywords: Open Source Software, Security, UI/UX Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] GM everyone uh I'm Charles G I'm CTO at Ledger um and today I'm going to talk about clear signing and why it's it's important if you care about security uh you must have a ledger device uh raise your hand if you own a ledger device okay most most of the people in the room uh own a ler device but would you sign the transaction raise your hand you wouldn't but most of you have already signed the transaction and it's a big problem because signing a hash is uh completely insecure because you can't distinguish a legitimate transaction from a malicious payload and um you might sign away your asset so this is something we need to fight against this is what we called uh blind signing and blind signing is simply equivalent to signing a blank check so maybe you are signing the transaction you wanted to sign but maybe you are s signing away your assets and unfortunately um get scam isn't Fun and this is very real a couple of months ago W Rex was hacked 230 millions and they simply blind signed transaction uh giving away their assets only two weeks ago rant Capital got hacked same story they got a malware on their computer they thought they were signing a transaction on safe while the malware was replacing the transaction by a malicious transaction they blind signed the transaction and they got hacked so the attack these attacks are aren't theoretical at all they are they are very real they are part of our reality and we really need to fight against this attack and the idea for us is to provide the user with all the information to take a decision to sign a transaction or not so the idea is to have something very transparent completely human friendly and to empower user again Ledger won't decide for you we just give you the information and then you decide if you want to sign the transaction or not and in this case you will swap your uh your Matic to usdt everything is uh is clear and you don't have to uh to guess if the ash is dangerous or not the key component for the clear signing initiative is are quite simple we have created a standard that is based on a Json file so we are asking DBS to create a very simple Json file that explain how to interact with their ABI and to give like the uh human friendly name for the different method and uh parameters we also provide an editing tool to uh to make this as easy as possible then the this metadata file will be stored uh on some public register registry and for wallets then it's a matter of trusting this metad data file or not Ledger is one of the trusting Authority for Des metadata file we sign this metadata file and as soon as you uh will sign a transaction the whole transaction payload will come along with this uh gon metadata file that allows the hardware wallet to understand how to pass the transaction this is how it works and from if you are a wallet from an integration standpoint it's pretty easy uh you just have to integrate our last version of the device SDK so to summarize from from a DB standpoint you just have to fill this metadata file with uh the tools that we are providing and for wallets you simply have to integrate the large lastar version of the uh device management kit and then the clear signing comes for free um the device management kit is pretty uh pretty easy to use uh it allows to discover devices to connect to the device to exchange data to the device uh there is also some State Management that allows the wallet to know where the hardware wallet is and and several OS command the visualization tool is also pretty convenient for dab developer if you are a dab developer and you have written your uh smart contract you will you won't need more than 10 minutes to um to fill the metadata file and with this tool you can see what will be displayed on Ledger devices you should care um we this is not like a ledger problem it's an industrywide problem that needs to be solved we need to fight against the those attacks we need to rebuild uh trust in the ecosystem uh we see more and more sophisticated attacks and that won't stop here with more Stakes attackers got get more sophisticated and we will see more and more um people who are who are drained and so on so we we really need uh to solve this problem and we won't be able to solve this problem alone so we need your help as developer dab developer or wallet developer to make uh this reality uh here a couple of useful links so you have the developer portal you have the clear signing on page uh you have the GitHub repository and a blog post explaining how to uh interact with the clear signing initiative thank you for your attention and happy to answer to your question thank you question okay I have a small question it's a little bit of topic can I ask you about after the section sorry uh can I ask one question when you will leave it's a little bit interesting for me but a little bit off topic for now okay okay thanks okay we have a question behind um has like open Zepplin implemented that for like all the regular stuff like for vaults for example so we don't have to do it yeah very good question uh not yet to to my knowledge we have created the open standard recently we asked for we implemented some RFC in order to get feedback from the community and so on and now we are in the phase where we are asking different D to fill the Json file and the generic parcer at the device level will be available in like a couple of weeks like in one month something like this so it will come but to my knowledge they didn't do that already so for now it's on each dap to yeah each dap needs to fill this uh this gon file again it's it it takes 10 minutes but it needs to be done by tabs because they know how to interact with their smart contract yeah thanks thank you yeah here um I wanted to ask if this is if the here okay yeah if this is for any kind of signature not only so signatures or transactions and if you do some validation on the shason that the developer propos or is a totally like decentralized or something like that okay very good question so for now we focused on evm mostly uh so all of this is valid for evm we will continue the the work on other chain next year but for now it's only on evm we are supporting already uh like uh the approvals permit permit to EIP 712 and for the metadata file that needs to be done by DBS like we have created a a public repository so anyone can contribute but when it comes to uh trusting the metadata file each wallet is responsible to signing or not there metadata file and and Ledger is a trust like um a certification Authority for this metadata file the the the the transaction that you will sign on your device if they are clear sign that means that we have reviewed uh the uh the metadata file and then we think it's legitimate thank you any other question if we have still time for one question I think there's one there how how do you sorry how do you ensure the uh Integrity of those uh Json data files so they they they are simply signed uh by by so they they can't be modified I think you have a question there yeah hello um I'm probably missing something but what's the difference between this and Nat spec because I thought Nat spec was supposed to solve this problem which spec Nat spec npec to be honest I I'm not aware of npec we have created the specification of the beginning of the year and we have discussed with the different people in the ecosystem ask for for feedback and so on and U and I to be honest I I don't know this this specific spec so Nat spec is where you embed the intent within the source code using special like comment format and uh then that stuff can get tracked in a decentralized manner is it does it uh does it enable to explain how the transaction is actually implemented yeah in order to pass it yeah it's about three or four years old I think okay but what we have created is a standard that U that also gives like some formal formalism on how the dent file must be done so that the device understands it so maybe the the the difference between what we did and npec is one this specification of the jent file thanks thank you thank you very much let's give it up to Gim CTO fedro

Automatic transcript — names and jargon may be misspelled.