Stop signing further requests and identify what you authorized. An unknown signature can be an ordinary message, a token permit, an order or a broader account permission. The right response depends on that distinction.
Separate four questions
- Did you enter a recovery phrase or private key anywhere?
- Did you confirm an onchain approval or transfer?
- Did you sign typed data that can authorize later movement?
- Has any unexpected transaction already confirmed?
MetaMask’s signature-phishing guidance explains why an offchain signature can matter before a transfer appears in history.
Preserve useful evidence privately
Keep the application domain, time, signing account, chain, request type and visible fields. Do not post an unused signature to a public forum. If it is still valid, the data itself may be actionable.
Check current allowances and relevant order or permit status through genuine tools. A standard allowance scanner may not show every unsubmitted signature.
Match the response to the authority
Remove an unwanted allowance through its proper revocation flow. Investigate nonce invalidation or order cancellation for a signed authorization. Treat disclosed keys as a separate compromise requiring a clean signer and careful asset protection.
Disconnecting the website is sensible session cleanup, but it does not invalidate everything already signed. Ethereum’s scam-support resources provide response and reporting starting points.
Avoid rushed rescue offers. Anyone asking you to sign an unexplained “recovery approval,” share a seed or pay a guaranteed-return fee adds another authorization decision at the moment you most need to reduce uncertainty.
Sources & verification (3)
Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.
- Signature phishing
Offchain signatures can authorize later asset movement.
https://support.metamask.io/stay-safe/protect-yourself/wallet-and-hardware/signature-phishing/ - Scam help & reporting | ethereum.org
Response to scams, approval revocation and recovery limitations.
https://ethereum.org/community/support/scams/ - How to revoke smart contract access to your crypto funds
Revocation and disconnecting are distinct actions.
https://ethereum.org/guides/how-to-revoke-token-access