A few days ago we launched Safe OpenSig. The thing that surprised me most was how misunderstood blind signing is. Even among people who think seriously about this.
So let me explain what it actually means, step by step.
Step 1: You open Safe. A transaction was proposed. You review it.
You see decoded details. A transfer, a contract call, an ownership change. Looks right. But three things can compromise what you see before you ever touch your hardware wallet.
The interface can be compromised through: a tampered frontend, a poisoned backend, a malicious browser extension, a hijacked DNS record, or a compromised dependency deep in the frontend's supply chain. You wouldn't know which one.
Step 2. You try to verify.
Smart move. You copy the calldata and paste it into an external tool to decode it.
But where did you get that calldata? You copied it from the same interface that may be compromised. The verification is tainted from the start.
The only review that means anything is one where you constructed the calldata yourself, offline, from scratch. Without touching the UI at all. That's not a realistic workflow for a n-m multisig signing transactions every week.
Step 3. You connect your Ledger.
This is where people assume the hardware takes over as the trusted layer. It doesn't.
For anything beyond a simple ETH transfer, your Ledger can't decode the transaction. It shows two hashes. Domain hash. Message hash.
nitter.net/heymarcopolox/status/2…
Step 4. You approve the hash. You always do.
This is the attack surface. There is no moment in this workflow where you can verify that what the interface showed you matches what the hardware is actually committing to. The security layer you thought existed doesn't.
What Safe OpenSig does
Before you touch your Ledger, Safe OpenSig simulates your Safe transaction locally on your mobile phone, away from your desktop. Two devices means two independent verification layers. It verifies state against multiple independent nodes, and shows you a pixel perfect mirror of what your Ledger screen will display.
The hash gets a face. You know what you're signing before you sign it.
candide.dev/opensig
I have no idea what I just signed