Paper 2026/1310
Designing Wallet-Based User Intervention for Approval Phishing Mitigation
Abstract
Approval phishing is a form of Web3 phishing that exploits token approval mechanisms to trick users into granting attackers spending authority over their tokens. As attackers increasingly hijack legitimate websites, URL-based detection alone becomes insufficient, leaving crypto wallets as the last line of defense. Based on the characteristics of approval mechanisms, we propose four wallet-based interventions for mitigating approval phishing: Spending Cap Suggestion, Active Spender Warning, Passive Spender Warning, and Delayed Confirmation. We evaluate the interventions through a between-subjects experiment (n = 364) and semi-structured interviews (n = 23). Compared with the control group, the Spending Cap Suggestion condition significantly increases the likelihood that users set spending caps. The Active Spender Warning, Passive Spender Warning, and Delayed Confirmation conditions all increase cancellation rates of phishing tasks, although the increases are statistically significant only for Active Spender Warning and Delayed Confirmation conditions. The effectiveness of the interventions varies across users, as users may struggle to interpret suspicious cues and focus on transaction outcomes while overlooking approval details. Our findings highlight the need to strengthen defenses against such attacks by increasing users' awareness of post-approval consequences and supporting approval-parameter verification at the moment of authorization.
Metadata
- Available format(s)
-
PDF
- Publication info
- Published elsewhere. The 35th USENIX Security Symposium
- Keywords
- Approval phishingCrypto walletNudgeIntervention
- Contact author(s)
-
yc37963 @ um edu mo
dz20330035 @ smail nju edu cn
maoyl @ nju edu cn
weitong @ outlook com
waynexzhou @ um edu mo
wangye @ um edu mo - History
- 2026-06-24: approved
- 2026-06-23: received
- See all versions
- Short URL
- https://ia.cr/2026/1310
- License
-
CC BY-NC-SA
BibTeX
@misc{cryptoeprint:2026/1310,
author = {Maggie Yongqi Guan and Yuqi Xu and Yunlong Mao and Wei Tong and Xiaobo Zhou and Kanye Ye Wang},
title = {Designing Wallet-Based User Intervention for Approval Phishing Mitigation},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1310},
year = {2026},
url = {https://eprint.iacr.org/2026/1310}
}