Yes. A signature can be free to produce and still authorize someone to move tokens later. The cost of signing and the power granted by the signed message are different questions.
How the authority becomes usable
ERC-2612 allows an allowance to be changed using a signed permit submitted to the token contract. Another party can pay for that submission. The user’s signature can therefore have financial consequences without an immediate gas charge in their wallet.
MetaMask documents signature phishing, where attackers obtain offchain authorizations that can later be used against the signer’s assets.
What “no transaction appeared” proves
It may mean the signature has not been exercised yet. It does not prove the signature has no effect or that it disappeared when you closed the website.
Likewise, disconnecting the application does not destroy copies of a signature it already received. Whether it can still be used depends on the signed fields, nonce, expiry, relevant allowances and protocol rules.
Review before signing, identify after a mistake
Check the message type, verifying contract, chain, spender, token amount and validity period. A plain authentication message and a token permit are not interchangeable.
If you signed an unknown request, preserve its nonsecret descriptive details privately and investigate the exact authorization. Avoid posting the full signature publicly. The appropriate response may involve revoking an allowance, invalidating a nonce or cancelling an order, depending on the scheme. A generic “disconnect and you are safe” instruction is insufficient.
Sources & verification (3)
Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.
- ERC-2612: Permit Extension for EIP-20 Signed Approvals
Signed approval fields, nonce, deadline, domain and permit submission.
https://eips.ethereum.org/EIPS/eip-2612 - Signature phishing
Offchain signatures can authorize later asset movement.
https://support.metamask.io/stay-safe/protect-yourself/wallet-and-hardware/signature-phishing/ - EIP-712: Typed structured data hashing and signing
Typed data domains, chain ID and verifying contract; the encoding standard alone does not include replay protection.
https://eips.ethereum.org/EIPS/eip-712