Phishing
Tricking someone into revealing a secret or approving a transaction by impersonating a trusted person, app, or website.
The classic form asks for a recovery phrase directly, through a fake wallet website, a look-alike domain bought through search advertising, or a support account that messages first in a chat app. The more expensive modern form asks for nothing secret at all: the victim connects a wallet to a malicious site and signs a token approval or an off-chain permit message, granting an address permission to move a token from the wallet later, without any further prompt. Because approvals persist until revoked, a signature made once can be used weeks afterward. Practical defenses are bookmarking the real site rather than searching for it, reading what a signature actually authorizes rather than the site's description of it, confirming details on a hardware device screen, and periodically reviewing and revoking outstanding approvals.
En la práctica
A wallet drainer site typically requests an approval for the maximum possible amount of a token, so a single signature is enough to move the entire balance of that token whenever the attacker chooses.
El malentendido más común
That you are safe as long as you never share your recovery phrase, when one approval signature can grant an attacker standing permission to move tokens from your wallet.