Library · Crypto, word by word · Cryptography

What is a digital signature?

A digital signature is a piece of data, made with a private key, that proves the holder of that key approved a specific message, such as a transaction. Anyone can check it with the matching public key, and changing even one character of the message makes the check fail.

What it means for you

A blockchain treats a valid signature as your approval, whether or not you understood what you signed. Some signatures authorise other addresses to move your tokens later even though nothing leaves your wallet at the time, so check what a wallet or site is asking you to sign.

A common mistake: “Signing a message in my wallet is harmless because it is not a transaction.”

In fact: Some signed messages are authorisations in their own right. A token permit signature, for example, can let another address move your tokens later without any further approval from you.

How it works

FIPS 186-5 approves three signature algorithms: RSA, ECDSA and EdDSA; the older DSA may now only be used to verify existing signatures. The signer applies the private key to the message, usually to its hash; the verifier takes the public key, the message and the signature and gets a yes or no. The algorithms are designed so that nobody without the private key can produce a valid signature on a different message. NIST notes that signatures give integrity, authenticity and non-repudiation support, but not confidentiality: a signed transaction is readable by anyone.

Sources: NIST FIPS 186-5: Digital Signature Standard, NIST CSRC glossary: digital signature · checked 4 October 2026

On Cryptominium

The five ways people actually lose crypto

Related words

Private keyPublic keyECDSAPermit signatureBlind signing

Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.