Smart-contract wallet signatures do not always remain valid forever.

Under ERC-1271, a wallet contract decides whether a signature is valid according to its current code, storage and policy. A signature can pass validation when it is created and fail later because a signer was removed, a multisig threshold changed, a Merkle proof became outdated, the signature expired or the wallet implementation changed.

That matters for off-chain orders, marketplace intents and other workflows where a signature may be created long before settlement. The user may be offline when the application finally attempts to use it. Treating the old bytes as permanently valid can produce failed settlement or unsafe assumptions.

ERC-5719 describes a signature-replacement interface for this problem. If the original signature fails ERC-1271 validation, a client can ask the wallet for a URI containing an alternative signature for the same digest. The replacement may update proof material or encoding while preserving the original signed intent.

The URI is not trusted proof. A client must independently validate the replacement through ERC-1271 under the wallet’s current state. If the request fails, the content is malformed, the replacement is invalid or the same bad signature is returned repeatedly, the client must reject it. A hard retry limit is necessary to prevent broken or adversarial replacement services from causing endless loops.

ERC-5719 is currently marked Stagnant, so applications should not assume universal wallet support. Its continuing value is as a security model: validate the original first, preserve the digest, distrust off-chain replacement data until the wallet verifies it, and fail closed when a valid alternative cannot be established.

Programmable accounts make authorization more flexible. They also make signature validity more state-dependent. Every relayer, exchange and intent system working with smart wallets should design for that difference.

Read the complete TokenToolHub guide: https://tokentoolhub.com/erc-5719-signature-replacement-stale-smart-wallet-signatures/

#Ethereum #SmartWallets #AccountAbstraction #CryptoSecurity #Web3