- Domain blocklist (MetaMask eth-phishing-detect, CryptoScamDB) + address reputation checks. - Inline red banners in connect/tx modals; enforce allowlist for custom RPCs.