Skip to content

SIWE Doesn't properly handle Multisig Wallet Signatures #216

Description

@DobromirKirovLime

Description

When using SIWE with multisig wallets (like Gnosis Safe), the signature verification fails with an invalid raw signature length error. This occurs because multisig signatures are longer than standard EOA signatures (65 bytes)

Current Behavior

  1. When a user signs in with a multisig wallet, the signature length is >132 characters (including '0x' prefix)
  2. The SIWE library attempts to verify
  3. This fails with: TypeError: invalid raw signature length (argument="signature", value="0x...", code=INVALID_ARGUMENT)
  4. However, the verification still succeeds

Expected Behavior

The SIWE library should:

  1. Detect multisig signatures (length > 132 characters)
  2. Handle them appropriately without throwing signature length errors

Steps to Reproduce

  1. Set up a SIWE implementation
  2. Use a multisig wallet (e.g., Gnosis Safe) to sign in
  3. The signature will be longer than a standard EOA signature
  4. Attempt to verify the signature using SIWE's verify() method

Code Example

const siweMessage = new SiweMessage(message);
const fields = await siweMessage.verify(
  { signature }, // multisig signature (>132 chars)
  { provider }
);
// Throws: TypeError: invalid raw signature length

Environment

  • SIWE version: 3.0.0
  • Node.js version: 20.18.2

PS

  • The current behavior is confusing because the verification "succeeds" despite the error

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions