# Signature replay: when the same authorization can be used again

A signature replay occurs when a valid signed authorization is accepted again or in an unintended context. Defenses bind the signature to the intended domain and action, then enforce appropriate nonces, deadlines or one-time-use rules. Transaction-level replay protection does not automatically protect every off-chain message.

Evidence: [Simple replay attack protection](https://eips.ethereum.org/EIPS/eip-155); [Typed structured data hashing and signing](https://eips.ethereum.org/EIPS/eip-712); [Permit Extension for EIP-20 Signed Approvals](https://eips.ethereum.org/EIPS/eip-2612)

Canonical: https://degreesofsatoshi.com/encyclopedia/signature-replay-attacks/
Published: 2026-10-02
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T18:12:41.505Z
Data current through: 2026-10-02

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Chain domain:** EIP-155 binds its protected transaction signing format to a chain ID. ([Simple replay attack protection](https://eips.ethereum.org/EIPS/eip-155))
- **Application domain:** EIP-712 supports separating signing contexts. ([Typed structured data hashing and signing](https://eips.ethereum.org/EIPS/eip-712))
- **One-time use:** ERC-2612 requires the expected permit nonce and increments it on acceptance. ([Permit Extension for EIP-20 Signed Approvals](https://eips.ethereum.org/EIPS/eip-2612))

## Ask where and how often the signature should work

A signed instruction might be intended for one contract, chain, action and occurrence. If the verifier omits one of those boundaries, the same signature may authorize more than the signer expected.

Domain separation and one-time-use are different protections. A signature can be restricted to the right contract yet still be reused there if the contract lacks suitable stateful checks.

Evidence: [Typed structured data hashing and signing](https://eips.ethereum.org/EIPS/eip-712)

## Different nonce systems protect different actions

An ordinary sender transaction nonce sequences top-level transactions. A token’s permit nonce tracks signed allowance authorizations under that token’s rules. They are not necessarily the same counter.

Sending an unrelated transaction does not generally invalidate every outstanding application signature. Check the actual application’s cancellation or nonce-consumption mechanism.

Evidence: [Ethereum transactions](https://ethereum.org/en/developers/docs/transactions/); [Permit Extension for EIP-20 Signed Approvals](https://eips.ethereum.org/EIPS/eip-2612)

## A time limit narrows exposure but does not fix wrong scope

A deadline can limit when a signature is accepted. It cannot repair a verifier that accepts the wrong chain, contract or action while the signature is still live.

Also distinguish replay from frontrunning: another party may submit a valid authorization first without changing its intended effect. Applications need correct behavior under both cases.

Evidence: [Permit Extension for EIP-20 Signed Approvals](https://eips.ethereum.org/EIPS/eip-2612); [Typed structured data hashing and signing](https://eips.ethereum.org/EIPS/eip-712)

## Questions

### Does disconnecting a wallet invalidate signatures already given to a site?

Disconnecting the interface does not alter a verifier’s on-chain nonce or authorization rules. An existing signature remains governed by its actual domain, deadline and cancellation conditions.

Evidence: [Permit Extension for EIP-20 Signed Approvals](https://eips.ethereum.org/EIPS/eip-2612); [Typed structured data hashing and signing](https://eips.ethereum.org/EIPS/eip-712)

## Claims and scope

### signature-replay-attacks-quick-answer

A signature replay occurs when a valid signed authorization is accepted again or in an unintended context. Defenses bind the signature to the intended domain and action, then enforce appropriate nonces, deadlines or one-time-use rules. Transaction-level replay protection does not automatically protect every off-chain message.

Scope: {"collection":"ethereum","dataAsOf":"2026-10-02","blockHeight":null}

### signature-replay-attacks-fact-chain-domain

Chain domain: EIP-155 binds its protected transaction signing format to a chain ID.

Scope: {"collection":"ethereum","dataAsOf":"2026-10-02","blockHeight":null}

### signature-replay-attacks-fact-application-domain

Application domain: EIP-712 supports separating signing contexts.

Scope: {"collection":"ethereum","dataAsOf":"2026-10-02","blockHeight":null}

### signature-replay-attacks-fact-one-time-use

One-time use: ERC-2612 requires the expected permit nonce and increments it on acceptance.

Scope: {"collection":"ethereum","dataAsOf":"2026-10-02","blockHeight":null}

## Sources

- [Simple replay attack protection](https://eips.ethereum.org/EIPS/eip-155) — Ethereum Improvement Proposals. Transaction chain ID domain separation; not blanket protection for all signatures. Locator: Specification. Retrieved: 2026-10-02T17:03:42.312Z.
- [Typed structured data hashing and signing](https://eips.ethereum.org/EIPS/eip-712) — Ethereum Improvement Proposals. Typed-data encoding and domain fields; replay protection is application-specific. Locator: Specification; Security Considerations. Retrieved: 2026-10-02T17:03:42.239Z.
- [Permit Extension for EIP-20 Signed Approvals](https://eips.ethereum.org/EIPS/eip-2612) — Ethereum Improvement Proposals. Signed token allowances, deadlines, nonces and domain checks. Locator: Specification; Security Considerations. Retrieved: 2026-10-02T17:03:42.295Z.
- [Ethereum transactions](https://ethereum.org/en/developers/docs/transactions/) — ethereum.org contributors. Signed transaction fields, nonces, propagation, inclusion and transaction types. Locator: The transaction lifecycle; Typed transaction envelope. Retrieved: 2026-10-02T17:03:41.854Z.

## Revision history

- 2026-10-02: First publication after primary-source research and independent automated verification.

## Cite this entry

Degrees of Satoshi editorial project. “Signature replay: when the same authorization can be used again.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/signature-replay-attacks/
