{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "signature-replay-attacks",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/signature-replay-attacks/",
  "collection": "ethereum",
  "title": "Signature replay: when the same authorization can be used again",
  "description": "Understand how a valid signature can be reused outside its intended scope and compare transaction nonces, chain domains and application-level replay defenses.",
  "aliases": [],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T18:12:41.505Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "A signature replay occurs when a valid signed authorization is accepted again or in an unintended context. Defenses bind the signature to the intended domain and action, then enforce appropriate nonces, deadlines or one-time-use rules. Transaction-level replay protection does not automatically protect every off-chain message.",
    "claimId": "signature-replay-attacks-quick-answer",
    "sourceIds": [
      "eip155",
      "eip712",
      "eip2612"
    ]
  },
  "keyFacts": [
    {
      "label": "Chain domain",
      "value": "EIP-155 binds its protected transaction signing format to a chain ID.",
      "sourceIds": [
        "eip155"
      ],
      "id": "chain-domain",
      "claimId": "signature-replay-attacks-fact-chain-domain"
    },
    {
      "label": "Application domain",
      "value": "EIP-712 supports separating signing contexts.",
      "sourceIds": [
        "eip712"
      ],
      "id": "application-domain",
      "claimId": "signature-replay-attacks-fact-application-domain"
    },
    {
      "label": "One-time use",
      "value": "ERC-2612 requires the expected permit nonce and increments it on acceptance.",
      "sourceIds": [
        "eip2612"
      ],
      "id": "one-time-use",
      "claimId": "signature-replay-attacks-fact-one-time-use"
    }
  ],
  "prerequisites": [
    "eip-712-typed-data"
  ],
  "sections": [
    {
      "id": "contexts",
      "heading": "Ask where and how often the signature should work",
      "sourceIds": [
        "eip712"
      ],
      "paragraphs": [
        "A signed instruction might be intended for one contract, chain, action and occurrence. If the verifier omits one of those boundaries, the same signature may authorize more than the signer expected.",
        "Domain separation and one-time-use are different protections. A signature can be restricted to the right contract yet still be reused there if the contract lacks suitable stateful checks."
      ]
    },
    {
      "id": "nonce",
      "heading": "Different nonce systems protect different actions",
      "sourceIds": [
        "eth-transactions",
        "eip2612"
      ],
      "paragraphs": [
        "An ordinary sender transaction nonce sequences top-level transactions. A token’s permit nonce tracks signed allowance authorizations under that token’s rules. They are not necessarily the same counter.",
        "Sending an unrelated transaction does not generally invalidate every outstanding application signature. Check the actual application’s cancellation or nonce-consumption mechanism."
      ]
    },
    {
      "id": "deadline",
      "heading": "A time limit narrows exposure but does not fix wrong scope",
      "sourceIds": [
        "eip2612",
        "eip712"
      ],
      "paragraphs": [
        "A deadline can limit when a signature is accepted. It cannot repair a verifier that accepts the wrong chain, contract or action while the signature is still live.",
        "Also distinguish replay from frontrunning: another party may submit a valid authorization first without changing its intended effect. Applications need correct behavior under both cases."
      ]
    }
  ],
  "faq": [
    {
      "question": "Does disconnecting a wallet invalidate signatures already given to a site?",
      "answer": "Disconnecting the interface does not alter a verifier’s on-chain nonce or authorization rules. An existing signature remains governed by its actual domain, deadline and cancellation conditions.",
      "sourceIds": [
        "eip2612",
        "eip712"
      ]
    }
  ],
  "claims": [
    {
      "id": "signature-replay-attacks-quick-answer",
      "articleSlug": "signature-replay-attacks",
      "statement": "A signature replay occurs when a valid signed authorization is accepted again or in an unintended context. Defenses bind the signature to the intended domain and action, then enforce appropriate nonces, deadlines or one-time-use rules. Transaction-level replay protection does not automatically protect every off-chain message.",
      "sourceIds": [
        "source-1975773eb9dbad9f",
        "source-c78d0f0c60a42b2d",
        "source-1f53bb744ddddb6b"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-1975773eb9dbad9f",
          "locator": "Specification"
        },
        {
          "sourceId": "source-c78d0f0c60a42b2d",
          "locator": "Specification; Security Considerations"
        },
        {
          "sourceId": "source-1f53bb744ddddb6b",
          "locator": "Specification; Security Considerations"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:12:41.505Z",
        "reviewer": "Codex independent automated reviewer /root/verify_ethereum_100",
        "notes": [
          "Compared EIP-155 chain-bound transaction signatures, EIP-712 domain/replay scope and ERC-2612 nonces/deadlines. Transaction and permit counters are distinct mechanisms.",
          "Disconnecting a UI cannot alter the cited verifier rules; deadline does not repair missing domain scope. Frontrunning is separated from repeated acceptance."
        ]
      }
    },
    {
      "id": "signature-replay-attacks-fact-chain-domain",
      "articleSlug": "signature-replay-attacks",
      "statement": "Chain domain: EIP-155 binds its protected transaction signing format to a chain ID.",
      "sourceIds": [
        "source-1975773eb9dbad9f"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-1975773eb9dbad9f",
          "locator": "Specification"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:12:41.505Z",
        "reviewer": "Codex independent automated reviewer /root/verify_ethereum_100",
        "notes": [
          "Compared EIP-155 chain-bound transaction signatures, EIP-712 domain/replay scope and ERC-2612 nonces/deadlines. Transaction and permit counters are distinct mechanisms.",
          "Disconnecting a UI cannot alter the cited verifier rules; deadline does not repair missing domain scope. Frontrunning is separated from repeated acceptance."
        ]
      }
    },
    {
      "id": "signature-replay-attacks-fact-application-domain",
      "articleSlug": "signature-replay-attacks",
      "statement": "Application domain: EIP-712 supports separating signing contexts.",
      "sourceIds": [
        "source-c78d0f0c60a42b2d"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-c78d0f0c60a42b2d",
          "locator": "Specification; Security Considerations"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:12:41.505Z",
        "reviewer": "Codex independent automated reviewer /root/verify_ethereum_100",
        "notes": [
          "Compared EIP-155 chain-bound transaction signatures, EIP-712 domain/replay scope and ERC-2612 nonces/deadlines. Transaction and permit counters are distinct mechanisms.",
          "Disconnecting a UI cannot alter the cited verifier rules; deadline does not repair missing domain scope. Frontrunning is separated from repeated acceptance."
        ]
      }
    },
    {
      "id": "signature-replay-attacks-fact-one-time-use",
      "articleSlug": "signature-replay-attacks",
      "statement": "One-time use: ERC-2612 requires the expected permit nonce and increments it on acceptance.",
      "sourceIds": [
        "source-1f53bb744ddddb6b"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-1f53bb744ddddb6b",
          "locator": "Specification; Security Considerations"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:12:41.505Z",
        "reviewer": "Codex independent automated reviewer /root/verify_ethereum_100",
        "notes": [
          "Compared EIP-155 chain-bound transaction signatures, EIP-712 domain/replay scope and ERC-2612 nonces/deadlines. Transaction and permit counters are distinct mechanisms.",
          "Disconnecting a UI cannot alter the cited verifier rules; deadline does not repair missing domain scope. Frontrunning is separated from repeated acceptance."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "eip155",
      "label": "Simple replay attack protection",
      "publisher": "Ethereum Improvement Proposals",
      "url": "https://eips.ethereum.org/EIPS/eip-155",
      "locator": "Specification",
      "note": "Transaction chain ID domain separation; not blanket protection for all signatures.",
      "version": "EIP/ERC-155; retrieved document hash recorded",
      "checkedAt": "2026-10-02T17:03:42.312Z",
      "contentSha256": "d2ee74d5b9d5230e5871645148c0978b10463b039a25d2ba753d3a8d6350c8c0",
      "recordId": "source-1975773eb9dbad9f"
    },
    {
      "id": "eip712",
      "label": "Typed structured data hashing and signing",
      "publisher": "Ethereum Improvement Proposals",
      "url": "https://eips.ethereum.org/EIPS/eip-712",
      "locator": "Specification; Security Considerations",
      "note": "Typed-data encoding and domain fields; replay protection is application-specific.",
      "version": "EIP/ERC-712; retrieved document hash recorded",
      "checkedAt": "2026-10-02T17:03:42.239Z",
      "contentSha256": "0951c36c432c48e281bd131331bdd5f4426706417e0d38fa3e667c0b7f84a530",
      "recordId": "source-c78d0f0c60a42b2d"
    },
    {
      "id": "eip2612",
      "label": "Permit Extension for EIP-20 Signed Approvals",
      "publisher": "Ethereum Improvement Proposals",
      "url": "https://eips.ethereum.org/EIPS/eip-2612",
      "locator": "Specification; Security Considerations",
      "note": "Signed token allowances, deadlines, nonces and domain checks.",
      "version": "EIP/ERC-2612; retrieved document hash recorded",
      "checkedAt": "2026-10-02T17:03:42.295Z",
      "contentSha256": "aa208d281cac5dbb182656bc7a3feab982df5c5df9e2f6dfa9b9efb5fc578ed1",
      "recordId": "source-1f53bb744ddddb6b"
    },
    {
      "id": "eth-transactions",
      "label": "Ethereum transactions",
      "publisher": "ethereum.org contributors",
      "url": "https://ethereum.org/en/developers/docs/transactions/",
      "locator": "The transaction lifecycle; Typed transaction envelope",
      "note": "Signed transaction fields, nonces, propagation, inclusion and transaction types.",
      "version": null,
      "checkedAt": "2026-10-02T17:03:41.854Z",
      "contentSha256": "2eb9d9cb65efec673d9bb3327961aa14a0e354b612e149c5a6b733032977fee7",
      "recordId": "source-c4666896686db30e"
    }
  ],
  "related": {
    "articles": [
      "permit-signatures",
      "ethereum-chain-id",
      "ethereum-wallet-requests"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and independent automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Signature replay: when the same authorization can be used again.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/signature-replay-attacks/"
}
