Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News Ethereum Exchanges Tether

    $1M Loss as Trader Approves Phishing Token After Wallet Signature

    9 July 2026
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    $1m Loss As Trader Approves Phishing Token After Wallet Signature
    $1m Loss As Trader Approves Phishing Token After Wallet Signature

    A crypto user lost nearly $1 million after approving a malicious token permission on Ethereum, according to onchain tracking shared by Scam Sniffer. The incident highlights how phishing โ€œtoken approvalsโ€ continue to evolve from one-off scams into repeatable theft workflows.

    Scam Sniffer reported that the victimโ€™s loss was 999,999 USDT (USDT) linked to an Ethereum phishing approval. The attacker first attempted to drain funds through multicall requests but failed due to insufficient balance, then immediately succeeded seconds later by executing follow-up transfers that removed the remaining funds.

    Key takeaways

    • A single โ€œapproveโ€ on an Ethereum token can grant an attacker sweeping power, allowing losses to be extracted quickly via automated transfers.
    • Scam Snifferโ€™s report describes multi-step draining: an initial multicall attempt may fail, but subsequent transactions can still empty the wallet.
    • Approval-phishing remains a widely used tactic within broader onchain scam ecosystems, including investment fraud.
    • Researchers warn that scammers often reuse the same wallet patternsโ€”meaning one uncovered incident can reveal a broader network of activity.
    • Address poisoning still compounds the risk, and users should treat copied addresses and pasted contract or wallet data with extra caution.

    A nearly $1 million theft triggered by a token approval

    The phishing mechanism centers on token approvals that appear routine. In these scams, victims are tricked into signing a transaction that grants a malicious actor permission to spend tokens or route funds from the wallet. The approval itself may be presented as a small stepโ€”such as enabling a transfer, interaction, or โ€œverificationโ€โ€”but it can instead grant broad or lasting access that the attacker immediately exploits.

    In the reported case, Scam Sniffer said the script recalculated the victimโ€™s remaining balance and then pulled the exact amount left after the first drain attempt. That meant the attacker did not need to guess the walletโ€™s contentsโ€”execution was adjusted in real time to maximize extraction.

    On Etherscan, the scamโ€™s activity is reflected across three transactions culminating in the extraction of 999,999 USDT. (See: Etherscan transaction.)

    Why approval phishing keeps working

    Approval phishing is a recurring pattern rather than a new trick. CertiK data cited in the coverage indicates that in 2025 phishing losses totaled $723 million across 248 incidents. The structure of these scams is consistent: social engineering prompts victims to click โ€œapprove,โ€ but the approval hands over spending capability to an attacker-controlled contract.

    CertiKโ€™s figures are particularly important because they suggest the problem is not isolated. Approval phishing scales well for criminals: once a victim grants token permissions, the attacker can use that permission to drain balances without requiring ongoing interaction from the victim.

    Industry-wide, the scale of phishing losses remains high. The article notes that the crypto sector recorded $366 million in phishing losses in the first half of the year, reinforcing that approval-based permission scams are part of a broader wave of onchain fraud rather than a niche threat.

    Scammers reuse wallets and permission patterns

    The broader risk is amplified when criminals reuse the same infrastructure and wallet targets. Earlier in the month, a separate incident was reported involving a victim losing $1.65 million after connecting to a fake exchange and signing a malicious contract. In that scenario, the approval gave attackers โ€œunlimited access,โ€ enabling an automated sweeper to drain funds, according to researcher Ryan Coleman.

    Chainalysis previously reported that onchain scams pulled in at least $14 billion in 2025, with investment scams remaining a dominant category. In Chainalysis materials on approval phishing, the firm explains that approval-based tactics are one way investment fraud moves from social engineering into automated onchain theft.

    Chainalysis also cautioned that criminals reuse the same wallets, leverage legitimate approval features from contracts, and employ consistent cash-out routes across victims. That reuse matters for investors and users because it changes what โ€œone reportโ€ can mean: when investigators map recurring permission and withdrawal behaviors, it can expose a wider network of coordinated activity rather than a standalone attacker.

    Chainalysis senior investigator Renato Bastos is quoted in the underlying coverage explaining that each uncovered report can reveal a broader network because scammers repeat wallet usage and operational paths. Readers should watch for whether similar approval signatures, contract patterns, or draining methods recur across incidentsโ€”those repetitions often indicate systematic campaigns.

    Address poisoning adds another layer of risk

    Phishing token approvals are not the only mechanism used to steal funds. The coverage also points to address poisoning, where scammers create wallet addresses that look similar to legitimate ones and then send small โ€œdustโ€ amounts to those near-matching addresses. When victims copy and paste the address, the dusted lookalike can cause users to send funds to the attacker rather than the intended recipient.

    The risk is especially relevant on ecosystems where manual copy/paste workflows remain common. The article notes that MetaMask launched live address poisoning detection in June. That tool compares each pasted address with addresses the wallet has previously interacted withโ€”designed to flag suspicious new or unexpected addresses that match known patterns for deception.

    With both approval phishing and address poisoning in play, the common theme is user interaction: scams manipulate what people think theyโ€™re signing or sending. Defenses therefore require slowing down and verifying the exact permission or recipient address before proceeding.

    What to watch next

    Approval phishing incidents like the reported 999,999 USDT theft tend to spread quickly when criminals refine execution and reuse wallet patterns. Users should be alert to any signature request connected to token approvals, avoid rushing through prompts, and consider detection toolsโ€”while security teams and onchain analysts will likely continue tracking recurring draining scripts and shared infrastructure to identify campaigns before they expand further.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Crypto Teams Submit Proposals For Anthropicโ€™s Ai Security Scanner

    Crypto Teams Submit Proposals for Anthropicโ€™s AI Security Scanner

    11 minutes ago
    Netflix Pulls Trailer For Series Based On Ftxโ€™s Sbf And Ellison

    Netflix Pulls Trailer for Series Based on FTXโ€™s SBF and Ellison

    1 hour ago
    Thailand Sets Effective Rules Next Week For Bitcoin & Ether Etfs

    Thailand Sets Effective Rules Next Week for Bitcoin & Ether ETFs

    2 hours ago
    Thailand Issues Final Framework For Spot Bitcoin And Ether Etfs

    Thailand Issues Final Framework for Spot Bitcoin and Ether ETFs

    3 hours ago
    Cantor Fitzgerald Under Senate Probe Over Reported Tether Links

    Cantor Fitzgerald Under Senate Probe Over Reported Tether Links

    4 hours ago
    Cantor Fitzgerald Under Senate Democrat Scrutiny Over Tether Links

    Cantor Fitzgerald Under Senate Democrat Scrutiny Over Tether Links

    5 hours ago

    Search Crypto News

    Featured Crypto News

    Latest News

    • Crypto Teams Submit Proposals for Anthropicโ€™s AI Security Scanner
    • Netflix Pulls Trailer for Series Based on FTXโ€™s SBF and Ellison
    • Thailand Sets Effective Rules Next Week for Bitcoin & Ether ETFs
    • Thailand Issues Final Framework for Spot Bitcoin and Ether ETFs
    • Cantor Fitzgerald Under Senate Probe Over Reported Tether Links
    • Cantor Fitzgerald Under Senate Democrat Scrutiny Over Tether Links
    • NFL Supports New Jersey Authorities in SCOTUS Fight Over Kalshi
    • Asia Crypto Update: China P2P Stablecoin Wallets Jump 43x
    • Securitize Shares Rise 10%+ After Tokenized US Equities Launch on Solana
    • NFL Supports New Jersey in SCOTUS Kalshi Petition

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Ledger
    Ledger

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    ๐Ÿ“ž +971 50 449 2025
    โœ‰๏ธ info@cryptobreaking.com
    ๐Ÿ“Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!