Designing Wallet-Based User Intervention for Approval Phishing Mitigation
Maggie Yongqi Guan, Yuqi Xu, Yunlong Mao, Wei Tong, Xiaobo Zhou, Kanye Ye Wang
摘要
Approval phishing is a form of Web3 phishing that exploits token approval mechanisms to trick users into granting attackers spending authority over their tokens. As attackers increasingly hijack legitimate websites, URL-based detection alone becomes insufficient, leaving crypto wallets as the last line of defense. Based on the characteristics of approval mechanisms, we propose four wallet-based interventions for mitigating approval phishing: Spending Cap Suggestion, Active Spender Warning, Passive Spender Warning, and Delayed Confirmation. We evaluate the interventions through a between-subjects experiment (n = 364) and semistructured interviews (n = 23). Compared with the control group, the Spending Cap Suggestion condition significantly increases the likelihood that users set spending caps. The Active Spender Warning, Passive Spender Warning, and Delayed Confirmation conditions all increase cancellation rates of phishing tasks, although the increases are statistically significant only for Active Spender Warning and Delayed Confirmation conditions. The effectiveness of the interventions varies across users, as users may struggle to interpret suspicious cues and focus on transaction outcomes while overlooking approval details. Our findings highlight the need to strengthen defenses against such attacks by increasing users' awareness of post-approval consequences and supporting approvalparameter verification at the moment of authorization.
1 Another delivery approach resembles traditional phishing: attackers create a spoofed DApp site that imitates a legitimate service and distribute its URL through social channels to lure users. Once users land on the spoofed site, the workflow aligns with the steps described above: they connect their wallets and sign an approval transaction that is presented as legitimate but authorizes an attacker-controlled spender.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper13
- Phishing in Organizations: Findings from a Large-Scale and Long-Term StudyDaniele Lain, Kari Kostiainen, Srdjan CapkunS&P 2022 · 被引用 92 次
- "Don't put all your eggs in one basket": How Cryptocurrency Users Choose and Secure Their WalletsYaman Yu, Tanusree Sharma, Sauvik Das, Yang WangCHI 2024 · 被引用 19 次
- Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing TrainingDaniele Lain, Tarek Jost, Sinisa Matetic, Kari Kostiainen 等CCS 2024 · 被引用 9 次
- Stealing Trust: Unraveling Blind Message Attacks in Web3 AuthenticationKailun Yan, Xiaokuan Zhang, Wenrui DiaoCCS 2024 · 被引用 5 次
- User Perceptions of Responsible Gambling Messages as Nudges for Gambling SafetyMaggie Yongqi Guan, Yaxing Yao, Sio Hong Teng, Xiaobo Zhou 等CHI 2026 · 被引用 1 次
相关 Paper
- CtPhishCapture: Uncovering Credential-Theft-Based Phishing Scams Targeting Cryptocurrency WalletsHui Jiang, Zhenrui Zhang, Xiang Li, Yan Li 等NDSS 2026 · 被引用 1 次
- Characterizing Ethereum Address Poisoning AttackShixuan Guan, Kai LiCCS 2024 · 被引用 4 次
- Restricting the Link: Effects of Focused Attention and Time Delay on Phishing Warning EffectivenessJustin Petelka, Benjamin Berens, Carlo Sugatan, Melanie Volkamer 等S&P 2025
- Beyond Phish: Toward Detecting Fraudulent e-Commerce Websites at ScaleMarzieh Bitaab, Haehyun Cho, Adam Oest, Zhuoer Lyu 等S&P 2023
- WalleTruth: Visual-Oriented Software Testing for Web3 Wallet Browser ExtensionsXiaohui Hu, Ningyu He, Haoyu WangFSE 2026
