Hunting Wallet Drainer And Dapp Approval Abuse

Hunt for dApp flows that trick a user's wallet into signing away its assets: an unlimited or unnecessary token approval a user grants to a contract that can then move all of their tokens, a signed permit or approve-for-all that authorizes spending far beyond the intended action, a blind-signing prompt that hides what is really being authorized, a malicious or spoofed spender or contract address the user is led to approve, and a transaction whose displayed intent differs from what it actually executes. Covers dApp front ends, wallet-connection flows, and token-approval interactions where a user's signature or approval authorizes a contract to move their assets. Use when a user signs an approval or transaction and the gap between what they think they authorized and what they did is the boundary. The deceptive or overbroad approval request is the source, the drained or movable assets are the sink, and the unlimited scope or hidden intent is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-wallet-drainer-and-dapp-approval-abuse commit 83b699fff9

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-wallet-drainer-and-dapp-approval-abuse