Generate a signing request QR — scan with the app — server verifies the signature itself
BLS_SIG_BLS12381G2_XMD:SHA-256_SSWU_RO_NUL_
and re-derives the ETH address from the group public key.
The client's verified flag is advisory only.