Beyond malicious scripts, players often fall for social engineering tactics. To stay safe, always use the official trading tables in the or the Mansion (Third Sea) .
Use an Authenticator App (Google or Microsoft) rather than just email.
But change what the other player sees in their trade window unless both players are running the same exploit — which defeats the point.