Skip to article
Degrees of SatoshiFollow the connections.
Degrees of Satoshi/ Encyclopedia

Encyclopedia Ethereum · Entry 118

Typed-data signatures: reading EIP-712 messages

Theme
Ethereum
Sources
2 cited records
Reading time
About 3 minutes
Automated verification
Substantive update
In this article

At a glance

Key facts

Key facts for Typed-data signatures: reading EIP-712 messages
FactDetailSource
StructureThe signed digest commits to typed message data and a domain separator.[1]
DomainDomain fields can include name, version, chainId and verifyingContract.[1]
ReplayEIP-712 explicitly leaves application replay handling to implementers.[1]
01

Read both the domain and the action

The domain identifies the signing context, while the typed message describes the requested operation. A familiar application name does not replace checking the verifying contract, chain and message fields.

Look for the recipient or spender, asset, amount, deadline and nonce where the application defines them. Not every typed message uses the same field names or permissions.

02

A signature can be submitted later by someone else

A token permit can let a relayer submit a signed allowance authorization. The user may pay no gas when signing, yet the accepted permit can create spending authority.

“No gas” describes the signing step, not the absence of financial consequences. Do not classify every off-chain signature as a harmless login.

03

Readable fields do not enforce themselves

The verifying application must check the domain and implement appropriate one-time-use, deadline or idempotency rules. Including a field in a display is insufficient if the verifier does not enforce it.

A security review therefore examines both the message a wallet signs and the contract logic that accepts it.

Direct answers

Questions people ask

Does EIP-712 automatically prevent a signature from being used twice?

No. The standard specifies typed signing and domain separation. The application must reject unwanted repeats or make repeated execution harmless.

Inspect the evidence

The answer and key facts have stable claim links. These records retain the scope and qualification when reused.

EIP-712 defines how structured typed data is hashed and signed, including a domain that separates signing contexts. It can make wallet requests more interpretable, but does not make their requested permissions safe. Applications must still implement replay controls, and a signature may authorize valuable actions without an immediate on-chain fee.

Scope: Ethereum · data through 2026-10-02. Verification: verified · 2026-10-02T18:12:41.505Z.

Link to this claim
Structure: The signed digest commits to typed message data and a domain separator.

Scope: Ethereum · data through 2026-10-02. Verification: verified · 2026-10-02T18:12:41.505Z.

Link to this claim
Domain: Domain fields can include name, version, chainId and verifyingContract.

Scope: Ethereum · data through 2026-10-02. Verification: verified · 2026-10-02T18:12:41.505Z.

Link to this claim
Replay: EIP-712 explicitly leaves application replay handling to implementers.

Scope: Ethereum · data through 2026-10-02. Verification: verified · 2026-10-02T18:12:41.505Z.

Link to this claim
Revision history
  1. — First publication after primary-source research and independent automated verification.

Source register

Sources and references

Retrieval dates and locators are recorded individually.
  1. Typed structured data hashing and signingEthereum Improvement Proposals

    Typed-data encoding and domain fields; replay protection is application-specific.

    Locator: Specification; Security Considerations · Version / scope: EIP/ERC-712; retrieved document hash recorded · Retrieved: 2026-10-02T17:03:42.239ZOpen source
  2. Permit Extension for EIP-20 Signed ApprovalsEthereum Improvement Proposals

    Signed token allowances, deadlines, nonces and domain checks.

    Locator: Specification; Security Considerations · Version / scope: EIP/ERC-2612; retrieved document hash recorded · Retrieved: 2026-10-02T17:03:42.295ZOpen source
How this article was made

Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.

Editorial method and corrections

Degrees of Satoshi editorial project. “Typed-data signatures: reading EIP-712 messages.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/eip-712-typed-data/