Encyclopedia Ethereum · Entry 120
Signature replay: when the same authorization can be used again
In this article
At a glance
Key facts
| Fact | Detail | Source |
|---|---|---|
| Chain domain | EIP-155 binds its protected transaction signing format to a chain ID. | [1] |
| Application domain | EIP-712 supports separating signing contexts. | [2] |
| One-time use | ERC-2612 requires the expected permit nonce and increments it on acceptance. | [3] |
Ask where and how often the signature should work
A signed instruction might be intended for one contract, chain, action and occurrence. If the verifier omits one of those boundaries, the same signature may authorize more than the signer expected.
Domain separation and one-time-use are different protections. A signature can be restricted to the right contract yet still be reused there if the contract lacks suitable stateful checks.
Different nonce systems protect different actions
An ordinary sender transaction nonce sequences top-level transactions. A token’s permit nonce tracks signed allowance authorizations under that token’s rules. They are not necessarily the same counter.
Sending an unrelated transaction does not generally invalidate every outstanding application signature. Check the actual application’s cancellation or nonce-consumption mechanism.
A time limit narrows exposure but does not fix wrong scope
A deadline can limit when a signature is accepted. It cannot repair a verifier that accepts the wrong chain, contract or action while the signature is still live.
Also distinguish replay from frontrunning: another party may submit a valid authorization first without changing its intended effect. Applications need correct behavior under both cases.
Direct answers
Questions people ask
Does disconnecting a wallet invalidate signatures already given to a site?
Disconnecting the interface does not alter a verifier’s on-chain nonce or authorization rules. An existing signature remains governed by its actual domain, deadline and cancellation conditions.
Inspect the evidence
The answer and key facts have stable claim links. These records retain the scope and qualification when reused.
A signature replay occurs when a valid signed authorization is accepted again or in an unintended context. Defenses bind the signature to the intended domain and action, then enforce appropriate nonces, deadlines or one-time-use rules. Transaction-level replay protection does not automatically protect every off-chain message.
Scope: Ethereum · data through 2026-10-02. Verification: verified · 2026-10-02T18:12:41.505Z.
Link to this claimChain domain: EIP-155 binds its protected transaction signing format to a chain ID.
Scope: Ethereum · data through 2026-10-02. Verification: verified · 2026-10-02T18:12:41.505Z.
Link to this claimApplication domain: EIP-712 supports separating signing contexts.
Scope: Ethereum · data through 2026-10-02. Verification: verified · 2026-10-02T18:12:41.505Z.
Link to this claimOne-time use: ERC-2612 requires the expected permit nonce and increments it on acceptance.
Scope: Ethereum · data through 2026-10-02. Verification: verified · 2026-10-02T18:12:41.505Z.
Link to this claimRevision history
- — First publication after primary-source research and independent automated verification.
Source register
Sources and references
Retrieval dates and locators are recorded individually.- Simple replay attack protectionEthereum Improvement Proposals
Transaction chain ID domain separation; not blanket protection for all signatures.
Locator: Specification · Version / scope: EIP/ERC-155; retrieved document hash recorded · Retrieved: 2026-10-02T17:03:42.312ZOpen source - Typed structured data hashing and signingEthereum Improvement Proposals
Typed-data encoding and domain fields; replay protection is application-specific.
Locator: Specification; Security Considerations · Version / scope: EIP/ERC-712; retrieved document hash recorded · Retrieved: 2026-10-02T17:03:42.239ZOpen source - Permit Extension for EIP-20 Signed ApprovalsEthereum Improvement Proposals
Signed token allowances, deadlines, nonces and domain checks.
Locator: Specification; Security Considerations · Version / scope: EIP/ERC-2612; retrieved document hash recorded · Retrieved: 2026-10-02T17:03:42.295ZOpen source - Ethereum transactionsethereum.org contributors
Signed transaction fields, nonces, propagation, inclusion and transaction types.
Locator: The transaction lifecycle; Typed transaction envelope · Retrieved: 2026-10-02T17:03:41.854ZOpen source
Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.
Editorial method and correctionsDegrees of Satoshi editorial project. “Signature replay: when the same authorization can be used again.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/signature-replay-attacks/