For Approval transactions, HashPort verifies the Spender rather than the Token
Because the object actually receiving the permission is the Spender or Operator
When a user executes approve through a DApp, the wallet cannot only confirm that the Token is legitimate
It also needs to confirm who the user is actually granting permission to
This is where Approval Phishing becomes dangerous
An attacker can copy a real DApp interface, use a real Token, and make the entire page look almost identical to the official website
But once the user clicks Approve, the permission may actually be granted to the attackers Spender
That is why HashPort defines the subject for approve increaseAllowance setApprovalForAll and permit related operations as the Spender or Operator
The wallet needs to verify whether the current page is the official frontend associated with that Spender
Because for an approval transaction, the object the user actually needs to trust is not the Token
It is the address receiving the permission