The two signatures they want
An ERC-20 approval, which authorises a contract to move a specific token up to a limit. Or an off-chain permit signature, which does the same thing without an on-chain transaction and therefore without a gas prompt — making it feel even less consequential.
A permit request is especially dangerous because it looks like "sign in with your wallet". It is not a login. It is a transferable authorisation.
The pages they use
Airdrop claim pages, NFT mints with a countdown, token migration notices, "your wallet is at risk, revoke here" pages, and staking dashboards that mirror a real protocol. The last category is effective because the real protocol does need an approval.
Traffic comes from advertisements on search results, replies to popular posts, compromised Discord servers and direct messages. Rarely from somewhere you navigated to yourself.
Reading the prompt properly
Your wallet shows the token, the spender address and the amount. Three questions: does this site need this token at all, do I recognise this spender, and why is the amount unlimited? A mismatch on any of them ends the interaction.
For signature requests, read the message. If it contains a spender, a token and a deadline, it is a permit, not a login, no matter what the button says.
After a compromise
Move remaining assets to a fresh wallet with a new phrase immediately — revoking first wastes time the attacker is using. Then revoke the allowances on the old address so anything arriving there later is not swept.
Treat the old address as public. Assume any permission granted from it is still live, and do not reuse it.