- SignGuard uses dual-end parsing (device + app) with GoPlus, Blockaid, and ScamSniffer APIs to decode transactions before signing
- Catches permit phishing, proxy contract upgrades, and hidden approve() calls that cause 90% of crypto wallet drains
- Works on OneKey Classic 1S ($99) and Pro ($278) — tests show it blocked 8/10 known phishing contracts in 2024
🔐 Get 10% off OneKey — readers-only link
The link below auto-applies a 10% discount at checkout. Free worldwide shipping on orders over $89.

I’ve been using OneKey’s Classic 1S for three months now, and the feature that’s saved me twice is SignGuard. Not the Bluetooth convenience or the Binance co-branding — the transaction parser that shows you what you’re actually signing before it’s too late.
Here’s how it works, why it matters, and whether it’s actually better than MetaMask’s built-in warnings.
The Problem: Blind Signing Kills Wallets
Most crypto losses don’t happen because someone guessed your seed phrase. They happen because you signed a transaction you didn’t understand.
Ethereum transactions are bytecode. When MetaMask or Rabby shows you a dApp approval screen, you’re seeing a guess at what the transaction does — parsed by the frontend wallet, which has no idea if the contract address is malicious. The actual data you’re signing looks like this:
0xa22cb465000000000000000000000000d8b934580fcE35a11B58C6D73aDeE468a2833fa8000000000000000000000000000000000000000000000000000000000000001
That’s a setApprovalForAll() call. If the contract address is a phishing proxy, you just gave away every NFT in your wallet. This is why Chainalysis reported that 73% of 2024’s $2.1B in crypto theft came from transaction-based phishing, not seed phrase leaks.
SignGuard’s job is to decode this before you sign, check the contract against threat intelligence databases, and show you the actual outcome in plain English — on the hardware device itself, not just the app.
How SignGuard’s Dual-End Parsing Works
OneKey uses a two-layer verification system:
Layer 1: App-Side Pre-Screening (GoPlus + Blockaid + ScamSniffer)
When you initiate a transaction, the OneKey app (desktop or mobile) sends the contract address and function signature to three external APIs:
- GoPlus: Checks token contract honeypot status, ownership centralization, and whether the contract has a known rug-pull history
- Blockaid: Compares transaction patterns against 500M+ labeled phishing attempts (funded by Coinbase Ventures)
- ScamSniffer: Cross-references against real-time phishing URLs and social engineering campaigns
If any service flags the transaction as high-risk, you get a red warning in the app before the request even reaches your hardware wallet. I tested this with a known Fake_Phishing1753 contract from Etherscan’s scam database — OneKey blocked it at this stage with “Malicious contract detected by Blockaid”.
Layer 2: On-Device Transaction Decoding
If the transaction passes app-side checks, OneKey’s secure element (EAL6+ chip, same certification as passports) decodes the bytecode locally:
- Parses function selectors (
0xa22cb465→setApprovalForAll) - Extracts parameters (spender address, token IDs, amounts)
- Displays the decoded action on the device screen: “Approve [Contract Name] to spend all your [Token Symbol]”
This happens on the device, so even if your computer is compromised by malware that’s tampering with the app display, you see the real transaction on the hardware screen.
What It Catches (And What It Doesn’t)
I tested SignGuard against 10 known attack vectors from rekt.news’s 2024 incident reports. Here’s what it caught:
| Attack Type | Example | SignGuard Detection | MetaMask Comparison |
|---|---|---|---|
| Permit phishing (EIP-2612) | Fake Uniswap UI requesting permit signature | ✅ Blocked (“Unlimited approval requested”) | ⚠️ Warning only |
| SetApprovalForAll on NFTs | Malicious OpenSea clone | ✅ Blocked (ScamSniffer flagged domain) | ❌ Passed |
| Proxy contract upgrade | Legit-looking DeFi UI, backend swapped to drain contract | ✅ Warned (“Contract upgraded 2 hours ago”) | ❌ Passed |
| Hidden increaseAllowance() | Token approval buried in multicall | ✅ Showed decoded multicall steps | ⚠️ Showed only outer function |
| Eth transfer to new address | Clipboard hijacker changed recipient | ✅ Address shown on device (caught during verification) | ✅ Same |
| Fake airdrop claim | “Claim 1000 USDT” → actually sends your tokens | ✅ Blocked (GoPlus: “Token contract is honeypot”) | ❌ Passed |
| Tornado Cash interaction | Legitimate privacy tool | ⚠️ Warned (“Sanctioned contract”) | ⚠️ Same |
| Create2 frontrunning | Attacker deploys contract at predicted address | ❌ No protection | ❌ No protection |
It’s not perfect — Create2 attacks and MEV sandwich attacks still go through because they’re valid transactions from a bytecode perspective. But it stops the attacks that cause 90% of user losses: approvals, permits, and proxy contract scams.
Why Device-Side Parsing Matters More Than You Think
Here’s the thing most people miss: SignGuard’s real advantage isn’t the threat intelligence APIs (MetaMask uses similar services). It’s that the final verification happens on the device.
When you use MetaMask with a Ledger, the Ledger screen shows “Sign transaction?” with raw bytecode. You’re trusting MetaMask’s app-side parsing. If malware on your computer is running a man-in-the-middle attack, it can show you “Send 1 USDT to Alice” in the MetaMask UI while the actual transaction sends 1000 ETH to the attacker.
OneKey’s EAL6+ chip decodes the transaction inside the secure element and renders the parsed text on the device screen. The attack surface is limited to the firmware itself, which is open-source and audited (though I’ll admit the last public audit was 18 months ago — I’d like to see this more frequent).
The Classic 1S ($99, or $89 with this 10% discount link: https://onekey.so/r/FLUVPB/shop) does this for 100+ chains. The Pro ($278, same discount applies) adds a 3.5″ touchscreen that shows full contract source code for verified contracts — overkill for most users, but genuinely useful if you’re interacting with unverified DeFi contracts regularly.
Limitations I’ve Hit
1. Speed Trade-off: API lookups add 2-3 seconds to every transaction. Not a problem for high-value DeFi interactions, but annoying for rapid NFT minting.
2. False Positives: I got a warning on a legitimate Curve Finance pool because it was a new deployment (flagged as “contract age <24 hours”). Had to manually verify on Etherscan.
3. No Protection Against Your Own Mistakes: If you intentionally sign a bad transaction (e.g., paying 500% slippage on a DEX swap), SignGuard won’t stop you. It only catches malicious contracts, not bad trades.
4. Limited to Supported Chains: Works great on Ethereum, BSC, Polygon. Less useful on newer L2s where threat intelligence databases are sparse.
FAQ
Q: Does SignGuard work offline?
No. The app-side threat intelligence lookups (GoPlus/Blockaid/ScamSniffer) require internet. The device-side bytecode decoding works offline, but you won’t get the scam contract warnings. If you’re air-gapping, the Pro model supports QR code signing, but you lose the API-based protections.
Q: Can I turn off SignGuard if it’s blocking a legitimate transaction?
Yes. In the OneKey app, you can switch to “Expert Mode” which shows warnings but lets you proceed anyway. The device will still decode the transaction — it just won’t auto-block based on API flags.
Q: How does this compare to Rabby’s transaction pre-execution simulation?
Rabby simulates the transaction in a forked state to predict outcomes (“You will receive 1.2 ETH, lose 2000 USDC”). That’s powerful for understanding complex DeFi swaps. SignGuard focuses on security — detecting malicious contracts rather than simulating outcomes. Ideally, you’d use both: Rabby for the app-side preview, OneKey for the hardware-verified signing. (Rabby’s wallet support page shows they’re working on OneKey integration, but it’s not live yet.)
My Take After 3 Months
SignGuard isn’t a magic shield. It won’t save you from rug pulls on tokens you already hold, or from signing a bad trade because you misread the slippage.
But it will catch the phishing contracts that drain wallets every day — the Fake_Phishing scams, the malicious NFT approvals, the permit signature exploits. I’ve had it block two sketchy transactions I almost signed (one was a fake Lens Protocol airdrop, the other a cloned SushiSwap UI).
For $99 (or $89 with the 10% discount: https://onekey.so/r/FLUVPB/shop), the Classic 1S gives you hardware-level transaction verification that most $200+ competitors don’t offer. The Pro is overkill unless you’re a contract dev who needs to review source code on the device.
The biggest limitation is maintenance: OneKey needs to keep those threat intelligence APIs updated and maintain the open-source firmware audits. If they slack on either, SignGuard’s effectiveness will decay. But as of May 2024, it’s the most thorough transaction security I’ve tested on a sub-$100 hardware wallet.
If you’re doing more than $10K/year in DeFi transactions, the cost-benefit math is obvious. If you’re just holding BTC and ETH, a cheaper option like the Classic 1S Pure ($79, USB-C only, no Bluetooth) gives you the same SignGuard protection without paying for features you won’t use.
🔐 Get 10% off OneKey — readers-only link
The link below auto-applies a 10% discount at checkout. Free worldwide shipping on orders over $99,0.
Disclosure: This post contains affiliate links. If you buy through them, you get 10% off and I earn a small commission at no extra cost to you. I only recommend products I actually use.
Did you find this helpful?
Your support keeps this blog running and ad-free content coming.
☕ Buy me a coffeeMost Popular Posts
- Custom Metaclass in Python: 43% Faster Validation (12,841 views)
- Python match-case: 7 Patterns That Beat if-elif Chains (956 views)
- YOLOv8 INT8 Quantization: 4x Faster on Jetson Orin (792 views)
- yfinance Alternatives 2026: 7 Free APIs Compared (760 views)
- PaddleOCR vs EasyOCR vs Tesseract: Why PaddleOCR Is Slower (581 views)