ADVERTISEMENT

Events

ETHWomen Toronto
21 Jul 26
Toronto
Rare Evo 2026
28 Jul 26
Las Vegas
IAMTN Annual Summit 2026
14 Oct 26
London

Ethereum User Loses Nearly $1 Million in USDT After Signing Phishing Approval

An Ethereum wallet holder lost nearly $1 million worth of USDT after signing a malicious token approval that allowed attackers to drain the wallet within seconds.

Blockchain security platform Scam Sniffer reported that the victim lost $999,999 in USDT after approving a phishing transaction on Ethereum. On-chain records show the attacker initially attempted to transfer an even $1 million from the wallet. That transaction failed because the account balance was $631 short.

Just 36 seconds later, the attacker adjusted the transaction to match the wallet’s exact balance and successfully transferred the remaining $999,999.

Attack relied on token approval, not wallet access

The theft did not require the attacker to gain direct access to the victim’s wallet or private keys. Instead, the victim signed a malicious token approval that granted permission for the attacker to spend the USDT stored in the wallet.

Token approvals are commonly used when interacting with decentralized applications, allowing smart contracts to move tokens on a user’s behalf. Fraudsters frequently disguise these requests as legitimate transactions, making them difficult to recognize without carefully reviewing the details before signing.

Why do phishing approvals remain so effective?

Phishing approvals remain one of the most successful crypto scams because the transaction often appears harmless. Many wallet interfaces focus on the action being signed rather than clearly explaining the permission being granted afterwards.

Unlike a direct transfer, an approval can allow a third party to move tokens later without requiring another signature from the wallet owner. That delay makes it harder for users to connect the approval with the eventual theft.

The safest approach is to treat every signature request as carefully as a bank transfer. Users should review token approvals before signing, avoid granting unlimited spending permissions when possible, regularly revoke approvals they no longer need, and use wallet security tools or browser extensions that flag suspicious transactions. Wallet developers have also introduced clearer warnings, transaction simulations, and approval management features. Still, phishing campaigns continue to succeed because they depend on user authorization rather than weaknesses in the blockchain itself.

The rise in crypto scams has pushed exchanges to strengthen account security, improve identity verification, and issue more frequent warnings. Bitget earlier warned that fraud targeting digital asset investors is becoming more sophisticated, with criminals increasingly using artificial intelligence, social engineering, and phishing attacks to steal funds.

 

Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads and CoinMarketCap Community for seamless access to high-quality industry insights.

Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.

ADVERTISEMENT
ADVERTISEMENT

Spotlight

-
00:00
00:00
Update Required Flash plugin
-
00:00
00:00