官方的 MASTR 标志 MASTR 支持这项工作
目录
← 知识库首页

Technical reference

ERC-1271: a contract decides whether a signature is valid

Smart-wallet signatures depend on validation logic and state, not only public-key recovery.

Source-based reference · Updated 12 September 2026

研究文章和参考条目以英语发布。导航提供七种语言。

本文目录
  1. The validation call
  2. Validity can depend on state
  3. An integration test worth keeping
  4. Sources

The validation call

ERC-1271 defines isValidSignature for contract accounts. A verifier supplies a message hash and signature; the contract indicates acceptance with a specified return value. The contract may apply multisig rules or another authorisation scheme. Recovering an externally owned account from the signature is not an equivalent check.

Validity can depend on state

A signature accepted before a signer rotation may not be accepted afterwards. The verifier must consider the account's current validation rules and cannot treat an earlier successful call as permanent authorisation for unrelated future actions. Contract upgrades can also change how the same account validates requests.

An integration test worth keeping

Test the same request before and after changing the authorised signer set. Also test an incorrect contract address and a contract returning an unexpected value. These tests separate a real contract-signature check from code that merely assumes every wallet is controlled by one conventional private key.

Sources

相关阅读

MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包