You’re on the wallet confirmation page, ready to tap “Confirm,” and you notice the request includes both “Signature” and “Authorization.” Don’t treat them as the same thing. A typical message signature usually doesn’t directly initiate an on-chain transfer; an authorization, however, may let a contract act on your behalf to spend the specified token(s). What matters isn’t whether the page looks similar, but who it authorizes, which asset it involves, and how much allowance is being granted. My rule of thumb is: if you can’t understand the authorization target or the amount, refuse first and go back to verify through the official entry point of the project you’re using. Seeing only “Connect Wallet” or “Free Claim” isn’t a sufficient reason. This doesn’t apply if you’ve already confirmed on the official page the contract, asset, and amount—and the purpose of your action is precisely this authorization. Now do a quick self-check: write down word-for-word the authorization target, the asset name, and the amount shown on the confirmation page, and compare each item against the official instructions. If even one doesn’t match, stop before you confirm.