Official MASTR logo MASTR Support the work
Contents
← Wiki home

Scam patterns

OAuth-consent phishing

A hostile application asks for access through a real identity-provider screen.

Reference note · Sources below

Research articles and reference entries are published in English. Navigation is available in seven languages.

People & projects

In this article
  1. Overview
  2. Why it matters
  3. What to check
  4. Sources

Overview

A hostile application asks for access through a real identity-provider screen.

Why it matters

The password goes to the real provider, but the attacker receives mail, file or contact scopes.

What to check

Review application identity, redirect URI and permissions; preserve consent logs.

Sources

Related reading

scams

Permit phishing

An offchain signature authorises a token allowance without an immediate gas payment.

MASTR

Support independent research

The investigations, original evidence and guides here are free to read. Voluntary donations help fund the research and keep MASTR’s tools available.

Open wallet