In the world of Web3, even cautious users like Mr. Li may fall into carefully designed traps. He has always been careful, never clicking on suspicious links, refusing unknown Airdrops, and not easily connecting to unfamiliar DApps. However, when a fren recommended a seemingly legitimate new type of DEX aggregator, Mr. Li decided to give it a try.



This platform looks impeccable: the interface is professional, it supports multiple wallets, the fees are transparent, and it even offers rebates. Mr. Li connected his wallet but did not conduct any transactions or signing operations. Shockingly, the next day, his USDT was quietly transferred away.

This is not a traditional hacking attack, but a new type of 'authorization fraud'. The core of this scam lies in inducing users to unknowingly grant a smart contract unrestricted permission to transfer a certain cryptocurrency. Attackers use carefully designed phishing DApps to guide users to sign an apparently harmless Approve authorization at the moment they connect their wallets.

The danger of this type of scam lies in its concealment. Victims often discover asset losses days or even weeks later. During the wallet connection process, users find it difficult to notice the authorization operations happening in the background, which is the key to the success of such scams.

To address this threat, WalletConnect has launched multiple security measures:
1. Improved connection interface that clearly displays the authorization information involved in each connection.
2. Enhanced Session connection layer that can intercept automatic authorization processes without user confirmation.
3. DApp credibility identification system, clearly marking the credibility status of the protocol.
4. Permission tracking feature after disconnection.

These measures aim to enhance users' awareness and control over the wallet connection process, effectively preventing authorization scams. In the blockchain world, security awareness and vigilance are crucial. Users should remain alert at all times, carefully reviewing each wallet connection and authorization operation to ensure asset safety.
DAPP0.66%
WCT2.43%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 6
  • Share
Comment
0/400
NFTHoardervip
· 08-03 02:49
Who doesn't check the permissions before using a Dapp?
View OriginalReply0
GateUser-afe07a92vip
· 08-03 02:40
Connect to a new DEX? Or is it more reliable to add old projects?
View OriginalReply0
MEVEyevip
· 08-03 02:38
Tears in my eyes, another sucker has been taken.
View OriginalReply0
0xInsomniavip
· 08-03 02:36
Even friends' recommendations are unreliable, it's really terrifying.
View OriginalReply0
TooScaredToSellvip
· 08-03 02:33
Bear Market Coin Hoarding is just playing.
View OriginalReply0
gaslight_gasfeezvip
· 08-03 02:28
Haha, old trick, can't fool me.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)