Blocky saysA digital signature proves a message came from a key holder and wasn’t altered.
To send a transaction, you sign it with your private key, producing a signature anyone can verify against your public key. Verification confirms two things: the signer holds the private key (authenticity) and the message is unchanged (integrity). The network checks signatures before accepting transactions — no signature, no spend. It's authorization without revealing the secret.
Power-ups you unlock
Sign with private key, verify with public
Proves authenticity + integrity
No password transmitted
Network rejects unsigned/invalid transactions
Double-Spend Dan attacks — common mistakes
Reusing nonces (can leak the private key in ECDSA)
Signing untrusted data blindly
Assuming a valid signature means a valid transaction (other rules apply)
Boss battleExplain the two facts a verified signature establishes.