Off-Chain Signature Risk Explainer
Free to download on every platform. Comes pre-installed on BotFone, BotPad and BotFlip — with extra free apps included.
About this app
WHAT IT DOES
Off-Chain Signature Risk Explainer analyzes off-chain signature requests and explains the risks before you sign. The tool takes the signature type (authentication, session token, permit, order, claim, vote, or other), contract address, message content, and request source, then identifies dangerous patterns like signatures for unknown purposes, requests that could authorize transactions, signatures with unclear permissions, and suspicious source domains. It then uses AI to generate a plain-language explanation of what the signature is for, what permissions it grants, how it could be used by the requesting party, and whether the request appears legitimate or suspicious. Results include a risk level, safety score (0-100), signature type, purpose description, contract address, request source, message preview, permissions granted, flags, and a comprehensive AI-generated explanation. The tool operates entirely read-only — no transactions are sent, no signatures are required. The AI assessment is designed to help you understand what you are signing before you approve it.
HOW TO USE
Connect your EVM wallet using the "Connect" button in the header. Select the network where the contract is deployed from the dropdown menu. Optionally select the signature type if you know it — otherwise the tool will auto-detect. Enter the contract address (if relevant), the message or data being signed, and the request source (DApp name or URL). Click "Analyze signature risk" to begin the analysis. The tool analyzes the signature type, message content, and source, identifies risk patterns, and sends the data to the AI for a plain-English risk explanation. Results appear within seconds, showing the signature type, chain, risk level, safety score, purpose description, contract address, request source, message preview, permissions granted, flags, and a comprehensive AI-generated explanation written in clear, conversational language.
OFF-CHAIN SIGNATURE PATTERN DETECTION AND RISK SCORING
The tool uses a pattern-based approach to detect off-chain signature risks. It checks the signature type against known patterns — authentication (proves wallet ownership, Low risk), session token (creates temporary session, Low risk), permit/approval (authorizes token spending, Medium risk), order/trading (authorizes trade execution, Medium risk), claim/withdraw (authorizes claiming funds, Medium risk), vote/governance (casts a vote, Low risk), and other (unknown purpose, Medium risk). The tool also analyzes the message content for keywords like "approve," "transfer," "withdraw," "trade," "vote," and "proposal" to identify the signature's purpose, and checks for hex data that could indicate a transaction. The request source is evaluated for suspicious keywords like "airdrop," "claim," "reward," "giveaway," and compared against known DApp domains. The risk level is determined by the signature type and detected patterns: permit/order/claim are Medium risk, auth/session/vote are Low risk, and other with suspicious flags is High risk. The safety score (0-100) is adjusted based on the risk level (80 for Low, 55 for Medium, 30 for High, 10 for Critical). The AI receives all this data and is prompted to explain the off-chain signature risks in plain language — stating what the signature is for, what permissions it grants, how it could be used, and whether the request appears legitimate or suspicious. The AI is also instructed to state plainly what it cannot verify — that it reads the signature data and context, not the requester's intent, off-chain consequences of signing, or the legitimacy of the underlying application.
WHAT IT CANNOT SEE
This tool cannot definitively determine if an off-chain signature is safe — only reads the signature data and context. It cannot detect off-chain coordination or malicious intent not reflected in the signature data — a legitimate-looking request could be part of a coordinated attack. The tool cannot predict the outcome of signing — it can only explain the signature type and context. Legitimate off-chain signatures may be used for valid reasons (e.g., authentication, session management) — a signature request is not automatically malicious. The tool cannot verify the identity or trustworthiness of the requesting entity — it only reads the provided data. The tool cannot detect if the message has been manipulated. The tool cannot detect if the source domain is spoofed. The tool cannot predict the future use of the signature. The tool cannot verify that the contract address is legitimate.
PLEASE NOTE
Off-Chain Signature Risk Explainer supports EVM-compatible chains only (Ethereum, BSC, Polygon, Arbitrum, Optimism, Avalanche, and others). The tool is read-only and never requests wallet signatures or transaction approvals. Risk assessments are AI-generated from the signature data and context — always review what you are actually signing in your wallet before approving it. The AI explanation is for informational purposes only and does not constitute financial or legal advice. Never sign an off-chain request you do not fully understand. Be especially cautious with permit/approval signatures and requests from unknown or suspicious sources.