Modal Phishing in Web3 Mobile Wallets
ID: 0ebe1aa7-26f0-53e1-9d2f-38388841bffc
STIX ID: report--0ebe1aa7-26f0-53e1-9d2f-38388841bffc
Feed Name: CertiK Blog
This report describes "Modal Phishing," a technique where attackers control modal window UI elements in crypto wallets to impersonate legitimate dApps or smart-contract method names (via WalletConnect metadata and on-chain method registries) and trick users into approving fraudulent transactions. The research demonstrates how wallets commonly trust unverified metadata and function name lookups, shows live examples including a phishing smart contract used for months, and recommends that wallet and protocol developers validate displayed metadata and limit what is presented to users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
