For years, signing a crypto transaction on a hardware wallet has felt a bit like signing a legal document written entirely in hieroglyphics. You trust that it says what your app told you it says, but the device screen itself? A wall of hexadecimal gibberish that could mean “swap 100 USDC for ETH” or “drain your entire wallet to a stranger in Moldova.” Trezor is now tackling that problem head-on.
On September 8, Trezor rolled out Clear Signing, a feature built on the open ERC-7730 standard that translates smart contract interactions into plain language directly on the device’s screen. Instead of a hex string, users see the actual action being performed, the token amounts involved, and the destination addresses.
How clear signing actually works
The ERC-7730 standard works through something called transaction descriptors. Each supported smart contract publishes a descriptor that acts like a Rosetta Stone, mapping raw transaction data to human-readable labels. When a user initiates a transaction through Trezor Suite, WalletConnect, or Trezor Connect, the wallet checks whether a descriptor exists for that contract.
If one does, the device displays the decoded information: what you’re doing, how much you’re spending, and where it’s going. If no descriptor exists, the wallet falls back to the traditional blind-signing flow, complete with an explicit warning that you’re approving something the device can’t fully verify.
No additional setup is required. The feature integrates automatically with existing Trezor infrastructure, which means users who update their firmware and software get the protection without toggling any settings.
The supported hardware includes the Safe 7, Safe 5, Safe 3, and Model T. The older Model One, Trezor’s original device, is not compatible with Clear Signing.
Launch partners and protocol coverage
At launch, Clear Signing supports several of the largest protocols in DeFi. The initial roster includes 1inch, Aave, Lido, Tether, LiFi, and Hyperliquid, all of which have published ERC-7730 descriptors to make their smart contracts readable on Trezor devices.
The ERC-7730 registry itself has been growing at a meaningful clip. Between its introduction in May 2026 and the end of July 2026, the number of published transaction descriptors increased by roughly 28%.
Trezor built this feature in collaboration with Ledger and the Ethereum Foundation, making Clear Signing less of a proprietary flex and more of an industry-wide infrastructure project.
Why blind signing was always the weakest link
Blind signing has been one of the most persistent attack vectors in crypto security. The premise of a hardware wallet is that it keeps your private keys offline, safe from malware and remote exploits. But that protection breaks down when users approve transactions they can’t actually read.
Phishing attacks have exploited this gap for years. A malicious dApp can present one thing on your browser screen while submitting an entirely different transaction to your hardware wallet. If the wallet only shows you hex data, you have no way to catch the discrepancy.
The cumulative damage from these attacks over the past decade runs into the billions. Token approval exploits, address poisoning, and contract manipulation all thrive in an environment where users routinely sign things they don’t understand. Clear signing doesn’t eliminate every attack vector, but it removes the information asymmetry that makes blind signing so dangerous.
What this means for Ethereum’s DeFi ecosystem
Trezor’s adoption of Clear Signing carries implications beyond just one hardware wallet brand. As both Trezor and Ledger push the ERC-7730 standard, protocol developers face increasing incentive to publish descriptors for their contracts. A protocol without a descriptor now shows up on users’ devices with a warning flag.
The 28% growth in ERC-7730 descriptors between May 2026 and the end of July 2026 points to a standard that’s gaining real traction. Hardware wallet competition has historically centered on price, form factor, and coin support. Trezor’s Clear Signing launch reframes that competition around transaction legibility, a dimension that matters most precisely when things go wrong.





