Today I almost lost assets due to a poorly designed scam website, luckily I had the plugin
which reported it in time! 😅 This experience made me deeply realize that behind the freedom of Web3, dangers are everywhere. If you are also interacting with a wallet, this security guide is a must-read!
The scams I've encountered
At that moment, the page displayed an 'authorization request' (as shown), although the URL gake-gi.pro was obviously suspicious (I would never click when sober!), but it's easy to overlook when fatigued. Key points:
Fake signature inducement: requesting authorization for 'all assets', which is too high (normal DApps only require specific token permissions).