# malicious approval — X 热门讨论 (2026-09-14 11:40 UTC)

## @zkxwallet (ZKX Wallet | The Secure and Private Wallet 🗽) · 09-14 06:00 · ♥21 ↻4 💬0 ON-CHAIN AUTOPSY #4: THE PHISHING APPROVAL. Not every drain requires stealing your seed phrase. 🛡️

A malicious dApp or a compromised front-end can request an approval signature that looks routine —

But the underlying transaction actually grants unlimited spend permission on a token, or transfers an NFT directly, disguised behind generic-looking wallet prompts. ⚠️

The signature itself doesn't visually explain what it authorizes; you have to actually read the transaction details, not just click through the pop-up. ✅

Defense: always check what a signature request actually says it's approving, not just which app is asking. https://x.com/zkxwallet/status/2099377613693133219