Approving a transaction without verifying its instructions. Exploited by drainers whose wallet popups show only that a transaction is being signed rather than what it will do. Even hardware wallets fail when blind signing is enabled.