An attack that alters the website or interface a user reaches, so that a correct-looking page constructs transactions the protocol never intended.
Why it matters
The contracts can be flawless and the outcome still be theft, because the user signs whatever the page put in front of them. It is the clearest case for treating the signing device’s display as the authority rather than the browser’s.
What you can check
The contracts and the interface are separately owned and separately attackable. Where a project documents which domains are official, publishes integrity hashes for its scripts, and states who controls its DNS, those are checkable claims about the layer that actually failed here.
Where it showed up
Records in the Incident Tracker that turn on this: BadgerDAO front-end injection and Ledger Connect Kit supply chain attack.
Not advice. Definitions are for understanding, not instruction. Nothing here is financial, legal, tax or security advice.