A CSRF attacker would not know the password of the user and therefore the transaction could not be committed via a stealth CSRF attack.+Upon committing to a transaction, such as fund transfer, display an additional decision to the user, such as a requirement for one???s password to be entered and verified prior to the transaction taking place.