BankVault forgot to set X-Frame-Options. Overlay their transfer button and trick a victim into sending funds.