An Ethereum wallet holder lost nearly $1 million worth of USDT after signing a malicious token approval that allowed attackers to drain the wallet within seconds.
Blockchain security platform Scam Sniffer reported that the victim lost $999,999 in USDT after approving a phishing transaction on Ethereum. On-chain records show the attacker initially attempted to transfer an even $1 million from the wallet. That transaction failed because the account balance was $631 short.
🚨 Someone lost $999,999 in USDT after signing a phishing token approval on Ethereum. 🎣
victim: 0x8c949361b49320c48a51f4b1c6f9f83862530f89
tx: https://t.co/54YXrwiVBi— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) July 9, 2026
Just 36 seconds later, the attacker adjusted the transaction to match the wallet’s exact balance and successfully transferred the remaining $999,999.
Attack relied on token approval, not wallet access
The theft did not require the attacker to gain direct access to the victim’s wallet or private keys. Instead, the victim signed a malicious token approval that granted permission for the attacker to spend the USDT stored in the wallet.
Token approvals are commonly used when interacting with decentralized applications, allowing smart contracts to move tokens on a user’s behalf. Fraudsters frequently disguise these requests as legitimate transactions, making them difficult to recognize without carefully reviewing the details before signing.
Why do phishing approvals remain so effective?
Phishing approvals remain one of the most successful crypto scams because the transaction often appears harmless. Many wallet interfaces focus on the action being signed rather than clearly explaining the permission being granted afterwards.
Unlike a direct transfer, an approval can allow a third party to move tokens later without requiring another signature from the wallet owner. That delay makes it harder for users to connect the approval with the eventual theft.
The safest approach is to treat every signature request as carefully as a bank transfer. Users should review token approvals before signing, avoid granting unlimited spending permissions when possible, regularly revoke approvals they no longer need, and use wallet security tools or browser extensions that flag suspicious transactions. Wallet developers have also introduced clearer warnings, transaction simulations, and approval management features. Still, phishing campaigns continue to succeed because they depend on user authorization rather than weaknesses in the blockchain itself.
The rise in crypto scams has pushed exchanges to strengthen account security, improve identity verification, and issue more frequent warnings. Bitget earlier warned that fraud targeting digital asset investors is becoming more sophisticated, with criminals increasingly using artificial intelligence, social engineering, and phishing attacks to steal funds.
Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads and CoinMarketCap Community for seamless access to high-quality industry insights.
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.


























































































