Crypto users face a constant threat: sophisticated phishing attacks and wallet drainers that trick them into signing away their assets. The core of this problem is the cryptic nature of signing requests, which even experienced users can misinterpret. To combat this, we built Unblind: an engine that explains any signing requests in plain English. This time we are releasing our Metamask Snap that delivers this human-readable summary via a secure, out-of-band Telegram message, arming you with the knowledge to approve or reject a transaction.
We previously discussed this in our previous blog post.
You can install the Unblind Snap by visiting the official MetaMask Snaps Directory.
The typical security approach relies on blocklists, issuing generic warnings like "High-Risk Contract." While these alerts can provide a useful signal, they are a fundamentally incomplete solution that often leads to alert fatigue.
• False Positives: A brand-new, legitimate DeFi protocol might be flagged simply because it’s unknown, causing you to miss opportunities.
• False Negatives: A novel phishing scam might be marked as "safe" because it hasn't been blocklisted yet, giving you a false sense of security.
Reputation-based alerts create uncertainty. Our approach adds a foundational layer: clarity through high-fidelity translation.
Unblind runs a powerful context extraction and simulation of the transactions and messages before you sign it. We don't just show you data; we show you what that data is designed to do in a way that’s relevant to you. This simulation provides the core context that is missing from today's signing experience, and it's a layer upon which other signals, like reputation data, can be added for even greater security.
For example, when all the other alert systems failed at the time to warn about the Bybit hack, this is what our tool would have shown:
“You will update the master copy of your Safe Wallet to 0xbdd077f651ebe7f7b3ce16fe5f2b025be2969516. This is an administrative action.”
This shifts the power back to you. With a clear understanding of the transaction's consequences, your decision to approve or reject becomes confident and informed.
Our primary goal is to protect you from approving malicious requests. A key security principle of Unblind is its function as an out-of-band verification channel.
If your browser, operating system, or even your software wallet is compromised, an attacker can display a fake transaction on your screen while submitting a malicious one in the background. Unblind defeats this vector. You will either receive no notification on your secondary device (Telegram), or you will receive a notification that accurately describes the actual malicious action.
This discrepancy is your most critical alert. The absence of a matching message is an unambiguous signal to reject the signature request immediately. This protects you even when your primary device cannot be trusted.
We respect user privacy and only store the minimal information needed to deliver these alerts to your Telegram.
However, for those who wish to avoid linking a Telegram account at all, Unblind offers a fully air-gapped verification method. This flow ensures your addresses and account information remain entirely separate.
The workflow is simple:
1. When prompted to sign, select the "QR Code" option within the Unblind snap.
2. On a separate device (like a phone), open a web browser and navigate to https://unblind.app.
3. Use this second device to scan the QR code displayed on your primary machine.
4. The human-readable translation will appear directly on your second device for verification, with no account or connection to your identity required.
The Unblind Snap for Metamask is just the beginning. Our mission is to protect every single user signing a transaction on any chain. We believe that human-readable, verifiable intent should not be an optional plugin, but a native, fundamental part of the digital ownership experience. True security should be invisible and universal.
For this to become a reality, we need to work together.
For Our Users
Your feedback on the current Snap is invaluable. Every suggestion helps us refine the core engine that will power this broader mission. Please continue to share your experiences with us. Join the telegram group or go to the anonymous form
A Call to Builders: Partner with Us
We are calling on wallet developers, dApps, and exchanges who share our vision. To make human-readable security a universal standard, we need to work together.
Unblind’s translation engine is not just a standalone tool; it's a foundational security layer designed for integration. We offer a simple and powerful API that allows you to embed transaction simulations directly into your product.
By partnering with us, you can:
• Enhance User Trust: Give your users the clarity to transact confidently.
• Reduce Support Overhead: Prevent security incidents caused by user error and phishing.
• Strengthen Your Brand: Signal that you prioritize user safety above all else.
We are establishing an early partner program to make integration seamless. If you are building a product that involves signing requests, contact us.Let's make fearless signing the default experience across the web3 ecosystem.