@lightclient
So if wallets insecurely integrate 3074 *and* users do not verify the invoker they're interacting with, it is possible to delegate to a malicious invoker.
However, it is possible to undo by sending a single tx from the EOA. This revokes all "in-flight" AUTH signatures.