Providers each build their signing string differently — some sign only the body, others prepend a timestamp, an id, or a version marker in a fixed order — and getting that order wrong produces a mismatch that looks exactly like an attack. This checks the signature the way the named provider actually specifies, with constant-time comparison, and returns the string that was signed so a mismatch can be debugged instead of guessed at.
| Network | Scheme | Amount | Pay To |
|---|---|---|---|
| Base | exact | $0.002000 USDC | 0x2880...4E5E |