Share
Subscribe to the AlphaWire Newsletter
An Ethereum user lost nearly $1 million in USDT after signing a single malicious transaction, highlighting the growing sophistication of phishing attacks targeting cryptocurrency holders.
According to blockchain security firm Scam Sniffer, the victim unknowingly approved a fraudulent token authorization that allowed an attacker to drain almost the entire wallet balance.
Onchain data shows the attacker initially attempted to steal a full $1 million in USDT. When that transaction failed, an automated script recalculated the wallet’s exact balance and successfully withdrew $999,999 USDT just 36 seconds later.
The incident underscores how modern phishing campaigns increasingly exploit token approval mechanisms rather than stealing private keys, making them more difficult for users to detect before funds disappear.
Unlike traditional wallet hacks, the attacker never gained access to the victim’s private keys.
Instead, the victim signed what appeared to be a legitimate token approval request on Ethereum. In reality, the signature granted a malicious smart contract permission to spend the wallet’s USDT holdings.
Once the approval became active, the attacker no longer needed additional confirmation from the wallet owner.
⚙️ The first transaction requested a round $1,000,000 — $631 more than the wallet held — so the $800,000 pull failed.
36 seconds later the script recalculated and pulled the exact remaining balance. pic.twitter.com/sRZbZsRSIv
— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) July 9, 2026
Blockchain records show the stolen funds were quickly divided into three separate transactions that settled in Ethereum blocks 25489460 and 25489463, only minutes after the signature.
Scam Sniffer noted that the attacker’s script first attempted to transfer exactly 1,000,000 USDT. When the transaction failed because the wallet balance was slightly lower, the software automatically recalculated the available amount and withdrew the remaining 999,999 USDT seconds later.
The rapid sequence left the victim with almost no opportunity to revoke the approval before the funds were transferred.
The attack relied on one of decentralized finance’s most persistent security weaknesses: unlimited token approvals.
When users interact with decentralized applications, they often authorize smart contracts to spend tokens on their behalf. While these approvals make future transactions more convenient, they can also remain active indefinitely unless manually revoked.
If a malicious contract receives unlimited spending permission, attackers can transfer approved tokens at any time without requesting another signature.
In this case, the victim’s wallet had granted an unlimited USDT allowance, allowing the attacker to empty the balance immediately after obtaining the approval.
Security researchers say this technique has become increasingly common throughout 2026.
In May, a fake Uniswap website stole roughly $400,000 from multiple users after convincing them to approve a malicious contract. Earlier this month, a fraudulent HyperSwap airdrop campaign similarly drained a user’s wallet within seconds of a single approval.
The theft also demonstrates how attackers are automating wallet-draining operations.
The attacker used Multicall functionality to bundle multiple contract interactions into a single transaction, allowing the funds to move almost instantly after the approval was granted.
The stolen USDT was immediately split into three outputs, making recovery even more difficult.
This keeps happening because ERC-20 requires approvals before tokens can move, and those permissions stay active indefinitely
ERC-223 works without approvalshttps://t.co/rCI8zpEzjj
— DEX223 (@Dex_223) July 9, 2026
Because the exploit depended on legitimate blockchain permissions rather than compromised credentials, traditional wallet security measures often failed to detect suspicious activity before the transfers occurred.
Scam Sniffer warned that phishing groups increasingly target high-value wallets using automated scripts capable of adapting in real time, including recalculating wallet balances if an initial transfer fails.
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share