{"id":72702,"date":"2026-09-18T22:55:01","date_gmt":"2026-09-18T19:55:01","guid":{"rendered":"https:\/\/lwallet.com.ua\/?p=72702"},"modified":"2026-09-18T22:55:01","modified_gmt":"2026-09-18T19:55:01","slug":"metamask-transaction-simulation","status":"publish","type":"post","link":"https:\/\/lwallet.com.ua\/en\/metamask-transaction-simulation\/","title":{"rendered":"Can you trust a transaction simulation in MetaMask?"},"content":{"rendered":"\r\n\r\n\r\n<p class=\"wp-block-paragraph\">When a dapp \u2014 a website or app connected to your wallet \u2014 sends a request to MetaMask, the wallet opens a confirmation screen. A <strong>MetaMask transaction simulation<\/strong> can show you, before you sign, how the transaction is expected to change your balance: for example, \u201c+1,240 USDC\u201d and \u201c-0.5 ETH.\u201d It is a prediction based on the current state of the network.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">That preview is useful for catching the wrong token, an unexpected amount, or a transfer you did not intend to make. But it is still only a prediction: <strong>a simulation does not prove that a contract is safe, and it does not guarantee that the onchain result will be identical<\/strong>. Network state can change, a malicious contract can deliberately behave differently during simulation, and some signatures or permissions do not move funds at the moment you approve them. That is why Estimated changes should be treated as one check, not the final verdict.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">What a MetaMask transaction simulation shows before you sign<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic2-1024x573.jpg\" alt=\"MetaMask transaction simulation \u2014 Estimated changes before confirmation\" class=\"wp-image-72678\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic2-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic2-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic2-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic2-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic2-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic2-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic2.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">MetaMask calls this feature <a href=\"https:\/\/support.metamask.io\/manage-crypto\/transactions\/simulations\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>estimated balance changes<\/strong><\/a>. In the confirmation screen, you will see it as <strong>Estimated changes<\/strong>. MetaMask simulates the transaction before it is submitted and shows the asset movements it expects.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">There are two details worth knowing before you rely on that preview:<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong>The simulation uses MetaMask infrastructure.<\/strong> MetaMask says the feature may send transaction data and\/or your IP address to a centralized MetaMask server. In Extension, privacy-related settings are under Settings \u2192 Privacy; in Mobile, they are under Settings \u2192 Security &amp; Privacy. Turning off Estimated balance changes also disables Added protection.<\/li>\r\n\r\n\r\n\r\n<li><strong>Estimated changes focuses on asset movement.<\/strong> It can show ERC-20 balance changes, ERC-721 and ERC-1155 NFT transfers, and changes involving ETH or another network\u2019s native asset. It does not explain every effect a smart contract can have.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Standard transaction simulations are enabled by default. MetaMask also makes the limitation clear: <strong>the simulated result may differ from what ultimately happens onchain<\/strong>. The blockchain can change between the moment MetaMask runs the preview and the moment your transaction is included in a block.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Why the preview can differ from the final result<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic3-1024x573.jpg\" alt=\"Why a MetaMask transaction simulation can differ from the onchain result\" class=\"wp-image-72681\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic3-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic3-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic3-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic3-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic3-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic3-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic3.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A simulation sees the network as it exists at that moment. Your transaction may not be included for another few seconds or minutes. In the meantime, someone else can trade against the same liquidity pool, an oracle can update a price, liquidity can change, or the contract itself can move into a different state.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Swaps are the easiest example. MetaMask may show one output amount in the preview, while the transaction ultimately receives a slightly different amount within your slippage limit. <strong>A simulation cannot freeze the market state until your transaction lands onchain.<\/strong><\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">There is also a more dangerous reason for a mismatch: a contract can be designed to <strong>behave safely during simulation and execute different logic once the real transaction runs onchain<\/strong>.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">When a contract deliberately fools the simulation<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic4-1024x573.jpg\" alt=\"Red pill attack \u2014 how a malicious contract can fool a MetaMask simulation\" class=\"wp-image-72684\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic4-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic4-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic4-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic4-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic4-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic4-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic4.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">MetaMask refers to this as a <strong>red pill attack<\/strong>. The malicious contract tries to detect whether it is being simulated. If it is, the contract returns a harmless result. When the same transaction executes in a real block, a different branch of the code runs.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A July 2026 paper, <a href=\"https:\/\/arxiv.org\/abs\/2607.28747\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">\u201cBlockchain Transaction Simulation Phishing\u201d<\/a>, describes six technical ways attackers can build this behavior. For a wallet user, they boil down to three broad ideas:<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong>Contract state.<\/strong> After the simulation, the attacker changes data in the malicious contract or a connected contract so the transaction follows different logic later.<\/li>\r\n\r\n\r\n\r\n<li><strong>Gas-related values.<\/strong> The contract can react to the available gas or gas price if those values differ between simulation and real execution.<\/li>\r\n\r\n\r\n\r\n<li><strong>Block data.<\/strong> Block number and timestamp keep changing, so a contract can use them as conditions for choosing a different path.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The researchers found all three of those patterns in real phishing contracts and reproduced additional variants experimentally. <strong>A green \u201cplus\u201d in Estimated changes only tells you what the simulation saw. It does not prove that the contract itself is safe.<\/strong><\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">How much users lost<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">To find these contracts onchain, the researchers built a detector called SimGuard and analyzed Ethereum, BNB Smart Chain, Avalanche, and Polygon. For the period from August 2024 through June 2025, they reported:<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong>4,224 phishing contracts:<\/strong> 3,136 on Avalanche, 480 on Ethereum, 315 on Polygon, and 293 on BNB Smart Chain;<\/li>\r\n\r\n\r\n\r\n<li><strong>5,742 victim addresses<\/strong> and 6,223 loss-making transactions;<\/li>\r\n\r\n\r\n\r\n<li><strong>about $3.48 million in estimated losses<\/strong>, including $3.19 million on Ethereum;<\/li>\r\n\r\n\r\n\r\n<li><strong>more than 143.4 ETH<\/strong> lost in the largest single transaction.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The most common contracts were those that keyed off gas-related values, but they accounted for only about 6% of the estimated losses in the sample. Most of the money came from 16 contracts whose state could be changed after simulation: roughly $2.97 million, or more than 85% of the total.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/drops.scamsniffer.io\/transaction-simulation-spoofing-a-new-threat-in-web3\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Scam Sniffer<\/a> documented one such case in January 2025. The site offered a supposed reward through a Claim function, and the simulation showed a profitable outcome. After the check, the attacker changed the contract state, so the real transaction followed different logic and drained more than 143 ETH from the address. The important part is not the exact function name: <strong>the malicious transaction looked safe at the moment the user had to decide whether to approve it<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The researchers also tested 11 popular wallets, including MetaMask, Rabby, and Phantom. Most showed a misleading or inaccurate preview in at least part of the test set. In one MetaMask test, the wallet displayed a small positive balance change even though the transaction sent 0.5 ETH to a phishing contract and returned only 1 wei \u2014 the smallest unit of ETH.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">These numbers cover one specific class of phishing attacks, not crypto phishing as a whole. The authors also note that some addresses may have been misclassified, so the $3.48 million figure is better treated as an upper-bound estimate than as an exact accounting total.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">[\/vc_message]<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">When your balance does not change, but you still grant permission<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic5-1024x573.jpg\" alt=\"Token approval in MetaMask \u2014 balance unchanged while spending permission is granted\" class=\"wp-image-72687\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic5-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic5-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic5-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic5-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic5-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic5-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic5.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Not every dangerous request moves tokens immediately. Sometimes you are granting permission that can be used later while the funds stay exactly where they are for now. In that case, the important questions are <strong>who receives the permission, how much they can spend, and how long the permission remains valid<\/strong>.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Permit and Permit2: a signature can authorize future spending<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">With EIP-2612 Permit and Permit2, you can authorize future activity by signing a message instead of first sending a separate <code>approve<\/code> transaction. No funds move when you sign. Depending on the request, that signature can later be used to create spending permission or move tokens.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">MetaMask can already decode some Permit requests and show permission details and amounts in the confirmation. That is useful, but <strong>the screen cannot tell you when someone will use a valid signature later<\/strong>. If an attacker gets the signature before it expires or is revoked, the actual token movement can happen afterward. We explain the differences between approve, Permit, Permit2, and WalletConnect in more detail in <a href=\"https:\/\/lwallet.com.ua\/en\/approve-permit-walletconnect\/\">\u201cApprove, Permit and WalletConnect: How Permissions Can Drain Your Tokens\u201d<\/a>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Permit requests are commonly represented as structured EIP-712 messages, so MetaMask can display some fields in a more readable form. MetaMask also uses <a href=\"https:\/\/support.metamask.io\/configure\/wallet\/security-alerts\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Security Alerts<\/a> to flag suspicious requests. For EVM networks, transaction and signature checks are handled through MetaMask infrastructure; for supported non-EVM networks, MetaMask uses Blockaid and other security providers. These alerts can identify known threats, but they do not guarantee that every malicious request will be caught, and the user can still choose to proceed.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Approve: permission to spend tokens later<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">An <code>approve<\/code> transaction sets or changes an <code>allowance<\/code>: the amount of tokens that a specific address or contract is allowed to spend later. In technical fields, that party is called the <code>spender<\/code>. The tokens do not move during the approval itself, so the key thing to review is who gets access and how large the limit is.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">MetaMask shows a <strong>spending cap<\/strong> for these requests. Check <strong>who you are authorizing and how much they will be allowed to spend<\/strong>. If the cap is much larger than the current transaction needs, that address or contract may be able to move far more tokens later \u2014 up to the full available balance while the permission remains active.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">How \u201cAdded protection\u201d works<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic6-1024x573.jpg\" alt=\"Added protection in MetaMask \u2014 onchain verification of a transaction simulation\" class=\"wp-image-72690\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic6-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic6-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic6-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic6-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic6-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic6-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic6.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A standard simulation only shows a preview. <strong>Added protection adds an onchain check during execution:<\/strong> if the real result does not match the protected simulation, the transaction reverts and the state changes are not applied. In other words, if a contract tries to switch to a different outcome onchain, the transaction is supposed to fail instead of silently doing something else. You still pay the network gas fee for the reverted transaction.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">There are a few limits to keep in mind:<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong>Added protection is not available for every request.<\/strong> MetaMask only shows the option where enforced simulation is supported. If there is no toggle in the confirmation screen, that protection is not available for that transaction.<\/li>\r\n\r\n\r\n\r\n<li><strong>Network support is limited.<\/strong> As of September 2026, MetaMask lists 15 networks for onchain simulations: Ethereum, Optimism, BNB, Polygon, Monad, HyperEVM, Sei, Tempo, MegaETH, Robinhood, Arc, Base, Arbitrum, Avalanche, and Linea.<\/li>\r\n\r\n\r\n\r\n<li><strong>The network fee can be higher.<\/strong> The extra onchain verification requires more gas. MetaMask does not charge a separate fee for the feature.<\/li>\r\n\r\n\r\n\r\n<li><strong>Since version <a href=\"https:\/\/github.com\/MetaMask\/metamask-extension\/releases\/tag\/v13.48.0\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">13.48.0<\/a>, the toggle is not always on by default.<\/strong> If MetaMask\u2019s internal risk checks do not detect clear warning signs, Added protection can start disabled. It remains enabled when the request is classified as warning or malicious.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">What a hardware wallet adds<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The simulation, MetaMask warnings, and dapp data are all shown on your computer. If the website or interface is compromised, the screen can show one thing while different data is sent for signing. <strong>A hardware wallet gives you a separate screen where you can verify what actually reached the device before you approve it.<\/strong><\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The <strong>Bybit hack on February 21, 2025<\/strong> is a useful example. Bybit used Safe{Wallet}, a multisig wallet in which several signers must approve an operation. According to <a href=\"https:\/\/www.sygnia.co\/blog\/sygnia-investigation-bybit-hack\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Sygnia<\/a>, the attack began with the compromise of a Safe developer\u2019s workstation. The attackers later injected malicious JavaScript into the Safe web interface, so the signers saw the expected transaction while different data was submitted for signing. One Bybit cold wallet ultimately lost about $1.46 billion in assets, including 401,347 ETH.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">That incident matters here because it shows the limit of relying on browser-based information alone. A hardware wallet adds a second display, but even there a complex smart-contract call may still be hard to understand. <strong>A contract address and a handful of technical fields are not always enough to understand what a signature will actually authorize.<\/strong> EIP-712 structures the message, but by itself it does not explain the meaning of a nested smart-contract action.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">For a normal transfer, verify the recipient address, amount, and network on the hardware wallet itself. If the browser and the device show different details, reject the request. For smart-contract interactions, check the action and its parameters as well. <strong>If the device only shows a long hexadecimal string or fields you cannot interpret, you do not have enough information to know what you are approving.<\/strong><\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/eips.ethereum.org\/EIPS\/eip-7730\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">ERC-7730<\/a> defines a JSON format that can turn technical call data \u2014 including <code>calldata<\/code> or EIP-712 messages \u2014 into a human-readable description of the action and its parameters. As of September 2026, ERC-7730 is still a Draft standard.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">On May 12, 2026, the <a href=\"https:\/\/blog.ethereum.org\/2026\/05\/12\/clear-signing-announcement\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Ethereum Foundation<\/a> announced that its Trillion Dollar Security Initiative would take an active role as a credibly neutral steward of the Clear Signing registry. ERC-7730 v2 also expanded the format to cover cross-chain use cases and software wallets.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Clear Signing helps only when a correct descriptor exists for the contract and the wallet applies it correctly. New or unknown contracts may not have one yet. A readable confirmation screen can greatly reduce the chance of approving opaque data, but <strong>you still need to verify the domain, contract, and action<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">If you are choosing a device for DeFi, we compare current models and their transaction-review features in <a href=\"https:\/\/lwallet.com.ua\/en\/best-hardware-wallets-2026\/\">\u201cBest Hardware Wallets in 2026: Which One Should You Choose?\u201d<\/a>.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">What to check before you confirm<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image wp-block-image size-large is-style-default blog-img\">\r\n<figure class=\"aligncenter\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic7-1024x573.jpg\" alt=\"What to check before confirming a transaction in MetaMask\" class=\"wp-image-72693\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic7-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic7-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic7-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic7-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic7-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic7-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/09\/blog-metamask-transaction-simulation-18-09-2026-content-pic7.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Before confirming anything, first identify what MetaMask is asking you to approve and what that request can do. A normal transfer, an <code>approve<\/code> transaction, and a Permit signature are different actions, so they need different checks.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>In MetaMask:<\/strong><\/p>\r\n\r\n\r\n\r\n<ol class=\"nm-block-list wp-block-list\">\r\n<li><strong>Understand what the dapp is asking for.<\/strong> Is this a transfer, an <code>approve<\/code>, or a message signature? For Permit and Permit2, check the token, amount, the address or contract receiving spending authority (<code>spender<\/code>), and the expiration. Field names vary, but those are the four things that matter.<\/li>\r\n\r\n\r\n\r\n<li><strong>Read Estimated changes all the way through.<\/strong> Check the asset, direction, and amount. If you see an outgoing transfer you did not expect or an unfamiliar token, do not confirm until you understand why it is there.<\/li>\r\n\r\n\r\n\r\n<li><strong>If Added protection is available, check whether it is enabled.<\/strong> MetaMask recommends extra caution for unfamiliar dapps, complex transactions, and large amounts. Since version 13.48.0, the toggle may start disabled when MetaMask\u2019s internal checks do not detect clear warning signs.<\/li>\r\n\r\n\r\n\r\n<li><strong>For approve requests, check who gets permission and review the spending cap.<\/strong> An unnecessarily large allowance can let that address or contract spend far more tokens than the current action requires.<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>On a hardware wallet:<\/strong><\/p>\r\n\r\n\r\n\r\n<ol class=\"nm-block-list wp-block-list\">\r\n<li><strong>For a transfer, verify the full address, amount, and network.<\/strong> Checking only the first and last few characters is weak protection against address poisoning, where an attacker deliberately tries to get a lookalike address into your history.<\/li>\r\n\r\n\r\n\r\n<li><strong>For a smart-contract interaction, check the action and its parameters.<\/strong> The contract address alone does not tell you what the transaction will authorize.<\/li>\r\n\r\n\r\n\r\n<li><strong>Do not approve a request you cannot understand.<\/strong> If the device shows a long hexadecimal string, a <code>data<\/code> field with no readable explanation, or unfamiliar parameters instead of the action you expected, stop and find out what you are being asked to sign.<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">If MetaMask and your hardware wallet show different information, reject the request and re-check the domain, contract, and source of the transaction. If you have already granted an overly broad or suspicious permission or signed a questionable Permit2 request, review your approvals and revoke them if necessary through <a href=\"https:\/\/revoke.cash\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">revoke.cash<\/a>. If there are signs that your private key or recovery phrase has been exposed, revoking permissions is not enough \u2014 move the remaining funds to a new wallet with a new backup.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">If your hardware wallet is new, go through our <a href=\"https:\/\/lwallet.com.ua\/en\/the-first-30-minutes-with-a-hardware-wallet-checklist\/\">first 30 minutes hardware wallet checklist<\/a> before moving a significant balance. It covers device checks, backup verification, and a test transaction.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">If a site promises a \u201creward\u201d but first asks you to send your own funds to an unfamiliar contract, stop and verify the contract independently. In some red pill schemes, the simulation showed a profit immediately before the real transaction sent the deposit to the attacker.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">[\/vc_message]<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Can you trust a MetaMask transaction simulation?<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A <strong>MetaMask transaction simulation<\/strong> is useful before you confirm. Estimated changes can show the expected movement of assets and often catches obvious mistakes before you sign. But <strong>it does not prove that a contract is safe or guarantee that the final onchain result will be identical<\/strong>. A red pill attack can make the same contract behave differently in simulation and real execution, while approve, Permit, and Permit2 can grant future spending authority without an obvious balance change at the moment you confirm.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Added protection adds an onchain verification layer for supported transactions, while a hardware wallet gives you a separate screen for reviewing what is actually being signed. Before you confirm, make sure you understand <strong>what action you are authorizing, where funds can go, who receives spending authority, and how much access you are granting<\/strong>.<\/p>\r\n\r\n","protected":false},"excerpt":{"rendered":"<p>When a dapp \u2014 a website or app connected to your wallet \u2014 sends a request to MetaMask, the wallet opens a confirmation screen. A MetaMask transaction simulation can show you, before you sign, how the transaction is expected to change your balance: for example, \u201c+1,240 USDC\u201d and \u201c-0.5 ETH.\u201d It is a prediction based &hellip;<\/p>\n","protected":false},"author":10,"featured_media":72676,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2725],"tags":[],"class_list":["post-72702","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/72702","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/comments?post=72702"}],"version-history":[{"count":2,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/72702\/revisions"}],"predecessor-version":[{"id":72704,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/72702\/revisions\/72704"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media\/72676"}],"wp:attachment":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media?parent=72702"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/categories?post=72702"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/tags?post=72702"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}