USENIX Security2026Top-tier venue
Designing Wallet-Based User Intervention for Approval Phishing Mitigation
Maggie Yongqi Guan, Yuqi Xu, Yunlong Mao, Wei Tong, Xiaobo Zhou, Kanye Ye Wang
Abstract
Approval phishing is a form of Web3 phishing that exploits token approval mechanisms to trick users into granting attackers spending authority over their tokens. As attackers increasingly hijack legitimate websites, URL-based detection alone becomes insufficient, leaving crypto wallets as the last line of defense. Based on the characteristics of approval mechanisms, we propose four wallet-based interventions for mitigating approval phishing: Spending Cap Suggestion, Active Spender Warning, Passive Spender Warning, and Delayed Confirmation. We evaluate the interventions through a between-subjects experiment (n = 364) and semistructured interviews (n = 23). Compared with the control group, the Spending Cap Suggestion condition significantly increases the likelihood that users set spending caps. The Active Spender Warning, Passive Spender Warning, and Delayed Confirmation conditions all increase cancellation rates of phishing tasks, although the increases are statistically significant only for Active Spender Warning and Delayed Confirmation conditions. The effectiveness of the interventions varies across users, as users may struggle to interpret suspicious cues and focus on transaction outcomes while overlooking approval details. Our findings highlight the need to strengthen defenses against such attacks by increasing users' awareness of post-approval consequences and supporting approvalparameter verification at the moment of authorization.
1 Another delivery approach resembles traditional phishing: attackers create a spoofed DApp site that imitates a legitimate service and distribute its URL through social channels to lure users. Once users land on the spoofed site, the workflow aligns with the steps described above: they connect their wallets and sign an approval transaction that is presented as legitimate but authorizes an attacker-controlled spender.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4e751fcc-70ac-41fb-a7a5-90045e6c9f32Builds on13
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 92 citations
- "Don't put all your eggs in one basket": How Cryptocurrency Users Choose and Secure Their WalletsYaman Yu, Tanusree Sharma, Sauvik Das, Yang WangCHI 2024 · 19 citations
- Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing TrainingDaniele Lain, Tarek Jost, Sinisa Matetic, Kari Kostiainen et al.CCS 2024 · 9 citations
- Stealing Trust: Unraveling Blind Message Attacks in Web3 AuthenticationKailun Yan, Xiaokuan Zhang, Wenrui DiaoCCS 2024 · 5 citations
- User Perceptions of Responsible Gambling Messages as Nudges for Gambling SafetyMaggie Yongqi Guan, Yaxing Yao, Sio Hong Teng, Xiaobo Zhou et al.CHI 2026 · 1 citation
Related papers
- CtPhishCapture: Uncovering Credential-Theft-Based Phishing Scams Targeting Cryptocurrency WalletsHui Jiang, Zhenrui Zhang, Xiang Li, Yan Li et al.NDSS 2026 · 1 citation
- Characterizing Ethereum Address Poisoning AttackShixuan Guan, Kai LiCCS 2024 · 4 citations
- Restricting the Link: Effects of Focused Attention and Time Delay on Phishing Warning EffectivenessJustin Petelka, Benjamin Berens, Carlo Sugatan, Melanie Volkamer et al.S&P 2025
- Beyond Phish: Toward Detecting Fraudulent e-Commerce Websites at ScaleMarzieh Bitaab, Haehyun Cho, Adam Oest, Zhuoer Lyu et al.S&P 2023
- WalleTruth: Visual-Oriented Software Testing for Web3 Wallet Browser ExtensionsXiaohui Hu, Ningyu He, Haoyu WangFSE 2026
