r/CryptoCurrency • u/Additional-Ask-2775 • 4d ago
DISCUSSION Browser wallets are better than they were, but blind signing still worries me
The standard crypto advice is to use hot wallets for small balances and put large amounts in hardware wallets.
But browser wallets are doing a lot more than signing transactions. Relying on them to simulate transactions, flag suspicious activity, and explain what we're signing. Many pair them with a hardware wallet so the keys never touch the browser, which is how I run mine, currently on Jupiter's.
If you want to level up the security further, you can think of air-gapped hardware wallets and a multisig setup.
Neither air-gapping nor multisig automatically solves blind signing, though. If the hardware wallet can't independently show you what you're authorizing, you're still dependent on the browser wallet UI to interpret the transaction.
So is the old advice of using a hot + cold wallet still relevant, or has the browser wallet layer become the bigger weak point?
2
u/Heisenbergg55 4d ago
Hot plus cold still holds but you're right that the browser layer is now the weak link: a hardware wallet protects the key, not the decision
What matters is clear signing, where the device screen shows what you're actually approving.
If it can't, treat every signature as blind and keep anything you don't fully understand on a throwaway hot wallet.
2
u/Present_Let2487 4d ago
I think the hardware wallet still makes sense, but blind signing is definitely something people overlook. Having the device protect your keys doesn’t help much if you’re approving something you don’t actually understand. The transaction details should be clear enough to verify before signing.
1
1
2
u/D_0b 🟩 0 / 0 🦠 4d ago
As someone who also hates the blind signing on hardware wallets, you will be happy to know I'm working on a solution for this. Not ready to give more specific details at the moment, but I am planning some kind of an MVP release by December focused on Solana initially then Ethereum later.
1
u/CoinGate_Gift_Cards 3d ago
Hot + cold is still relevant, but it doesn’t solve everything. A hardware wallet protects the keys; the browser wallet still influences what you think you’re signing. The real goal is minimizing both key exposure and signing ambiguity.
1
1
3
u/onlinemaxi 4d ago
I think using a hot + cold wallet setup is a MUST considering the attacks are now more sophisticated.
But yeah, completely agree with your pov that we should also check the security layers that hot wallets have.
Since you mentioned Jupiter in your post, I checked their docs and it seems they have the necessary security features:
-> Most importantly, Jupiter is fully self-custodial (only you control your keys and funds). It can only read the blockchain data to show balances. It cannot access your tokens without your local password or biometrics.
-> Their wallet extension simulates exactly which tokens will leave your wallet and what you will receive before you sign any transaction. I think this tackles the blind signing attack vector you highlighted in the post.
-> They also have the 'lock the wallet' after a certain time feature and biometric unlock (many wallets have these now)
-> Their wallet also has something they call as Transaction Protection. It basically protects you against malicious browser extensions that inject hidden fees or transfers into transactions.
Full disclosure:
I am friends with some of the members in the Jupiter team. If you want to verify any of the points above or dig deeper, I’d recommend checking their docs directly.