According to Scam Sniffer monitoring, most Solana wallet attackers actively use third-party domain names to bypass the wallet blacklist. (For example, registering expired DAPP domain names and now exploiting XSS vulnerabilities). If you see a DAPP pop up a second window (or redirect) asking for connection in another window, please carefully check whether it is safe.