ATTACKER iframe · real origin:
No web3 request, no popup. It captures the victim's login signature cross-origin, then replays it to the dApp from ITS OWN origin to log in AS the victim.
waiting for the victim's login signature to leak...