This can be completed by injecting an "ethereum" object on the browser window. You will need to now watch for the ethereum.enable() purpose to return legitimate right after prompting the consumer. A lot more information listed here: What would seem way more probable is that there's some sort of XSS-like https://georgesg454dwn5.wikitidings.com/user