ATTACKER iframe · real origin: …
No web3 request, no popup. It captures the victim's login signature cross-origin, then
replays it to the dApp from ITS OWN origin to log in AS the victim.
waiting for the victim's login signature to leak...
self-test running…