signature verifier

who signed this? personal_sign, eip-712, split and compact.

message
signature65-byte 0x… from personal_sign / signMessage
expected signer (optional)
eip-191 digest (what was actually signed)
0xb9698fa57885423120f1c6c7d0f7a355cf086ce7b57485e9a00979db2e09fbf1

about this tool

Recover the signer of a personal_sign message or EIP-712 typed data, check it against an expected address, see the digest that was signed, and split signatures into r, s, v or EIP-2098 compact form.

good to know

why does verification fail with the right key?

the signed bytes must match exactly: a trailing newline, a different chainId or verifyingContract in the eip-712 domain, or signing the hash instead of the message all change the digest.

what is high-s?

for every signature there is a second valid one with s flipped. openzeppelin’s ECDSA rejects the "high" half so signatures can’t be replayed in a mutated form.