正在检查浏览器是否支持朗读……
此阅读内容目前仅有英语版。界面使用你选择的语言。
阅读英语原文 →What exactly are you signing?
Spot the difference between viewing an account and granting spending permission.
Make this a habit: read the verb. Connect, approve and send are different requests.
- Which token?
- Which spender?
- How much?
Permission has a scope
An EVM token approval lets a named spender use an allowance of a particular token. Inspect the spender and amount, especially an unlimited allowance. A trusted-looking page can still request more permission than the action needs. Reject a request you cannot explain.
An unexpected token is not an assignment
Scam airdrops can lead users into failed transfers and then display a link to a supposed fix. That link may ask for recovery material or spending approval. A token appearing in your account does not oblige you to claim, sell or repair it.
Translate a pretend prompt
Consider this fictional request: 'Allow Sample App to spend unlimited SAMPLE tokens'.
- Underline the spender and the allowance.
- Rewrite it as 'This account can let this spender move this much of this token'.
- Decide what you would need to verify before accepting. You do not need to connect a wallet.
You can describe the authority a prompt grants in plain language.
If you cannot explain the permission, pause the action.
学习进度保存在此设备上。