Paper 2026/1310

Designing Wallet-Based User Intervention for Approval Phishing Mitigation

Maggie Yongqi Guan, University of Macau
Yuqi Xu, Nanjing University
Yunlong Mao, Nanjing University
Wei Tong, Nanjing University
Xiaobo Zhou, University of Macau
Kanye Ye Wang, University of Macau
Abstract

Approval phishing is a form of Web3 phishing that exploits token approval mechanisms to trick users into granting attackers spending authority over their tokens. As attackers increasingly hijack legitimate websites, URL-based detection alone becomes insufficient, leaving crypto wallets as the last line of defense. Based on the characteristics of approval mechanisms, we propose four wallet-based interventions for mitigating approval phishing: Spending Cap Suggestion, Active Spender Warning, Passive Spender Warning, and Delayed Confirmation. We evaluate the interventions through a between-subjects experiment (n = 364) and semi-structured interviews (n = 23). Compared with the control group, the Spending Cap Suggestion condition significantly increases the likelihood that users set spending caps. The Active Spender Warning, Passive Spender Warning, and Delayed Confirmation conditions all increase cancellation rates of phishing tasks, although the increases are statistically significant only for Active Spender Warning and Delayed Confirmation conditions. The effectiveness of the interventions varies across users, as users may struggle to interpret suspicious cues and focus on transaction outcomes while overlooking approval details. Our findings highlight the need to strengthen defenses against such attacks by increasing users' awareness of post-approval consequences and supporting approval-parameter verification at the moment of authorization.

Metadata
Available format(s)
PDF
Publication info
Published elsewhere. The 35th USENIX Security Symposium
Keywords
Approval phishingCrypto walletNudgeIntervention
Contact author(s)
yc37963 @ um edu mo
dz20330035 @ smail nju edu cn
maoyl @ nju edu cn
weitong @ outlook com
waynexzhou @ um edu mo
wangye @ um edu mo
History
2026-06-24: approved
2026-06-23: received
See all versions
Short URL
https://ia.cr/2026/1310
License
Creative Commons Attribution-NonCommercial-ShareAlike
CC BY-NC-SA

BibTeX

@misc{cryptoeprint:2026/1310,
      author = {Maggie Yongqi Guan and Yuqi Xu and Yunlong Mao and Wei Tong and Xiaobo Zhou and Kanye Ye Wang},
      title = {Designing Wallet-Based User Intervention for Approval Phishing Mitigation},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1310},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1310}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.