BITFINDING / CONTROLLED RESEARCH CHECKING HARDWARE ACCESS

LEDGER CLEAR SIGNING BYPASS / PROOF WIZARD

One parser.
Three attack paths.

Ask the trusted screen to review one action, capture what the device actually signs, and inspect the difference.

Flows
Safe / Aave / Morpho
Array
257 elements
Device review
1 element
Test wallet
Disposable seed only
!
Use a separate test device with a new, disposable seed phrase and no real funds.

This page produces signatures that can authorize real transactions. Treat the page and its outputs as untrusted. Never use your everyday wallet or reuse its recovery phrase. Never enter a seed phrase into this page or any website.

  1. 01SelectProtocol flow
  2. 02CaptureLedger signature
  3. 03InspectDisplayed vs signed
  4. 04ExportLocal reproduction

01 / SELECT AN ATTACK PATH

Same parser failure, different authorization

Each profile reconstructs a byte-for-byte validated payload and uses the signing method expected by that protocol.

Artifact
Target
Calldata
Parser omission

TRUSTED SCREEN

DISPLAYED

CRYPTOGRAPHIC AUTHORIZATION

SIGNED

02 / CAPTURE

Capture a signed artifact

Connect an affected test device and verify its signature against the complete payload.

HARDWARE ACCESS CHECK

Checking browser support before enabling WebHID.

CAPTURE RECORD

Verification log

Protocol selection, SDK state, hashes, and signer recovery appear here.