Trader Loses $999,999 USDT After Signing Single Ethereum Phishing Request

 

By Giuseppe Ciccomascolo // July 9, 2026 @ 12:34 PM Make AlphaWire Logo preferred on Google News
Trader Loses $999,999 USDT After Signing Single Ethereum Phishing Request

Share

Point of Focus

  • An Ethereum user lost 999,999 USDT due to a phishing attack.
  • The attacker first attempted to drain 1 million USDT.
  • The hacker used Multicall functions to bundle multiple actions into a single transaction.

 

An Ethereum user lost nearly $1 million in USDT after signing a single malicious transaction, highlighting the growing sophistication of phishing attacks targeting cryptocurrency holders.

According to blockchain security firm Scam Sniffer, the victim unknowingly approved a fraudulent token authorization that allowed an attacker to drain almost the entire wallet balance.

Onchain data shows the attacker initially attempted to steal a full $1 million in USDT. When that transaction failed, an automated script recalculated the wallet’s exact balance and successfully withdrew $999,999 USDT just 36 seconds later.

The incident underscores how modern phishing campaigns increasingly exploit token approval mechanisms rather than stealing private keys, making them more difficult for users to detect before funds disappear.

 

A single signature was enough to drain the wallet

Unlike traditional wallet hacks, the attacker never gained access to the victim’s private keys.

Instead, the victim signed what appeared to be a legitimate token approval request on Ethereum. In reality, the signature granted a malicious smart contract permission to spend the wallet’s USDT holdings.

Once the approval became active, the attacker no longer needed additional confirmation from the wallet owner.

 

 

Blockchain records show the stolen funds were quickly divided into three separate transactions that settled in Ethereum blocks 25489460 and 25489463, only minutes after the signature.

Scam Sniffer noted that the attacker’s script first attempted to transfer exactly 1,000,000 USDT. When the transaction failed because the wallet balance was slightly lower, the software automatically recalculated the available amount and withdrew the remaining 999,999 USDT seconds later.

The rapid sequence left the victim with almost no opportunity to revoke the approval before the funds were transferred.

 

Unlimited token approvals remain a major security risk

The attack relied on one of decentralized finance’s most persistent security weaknesses: unlimited token approvals.

When users interact with decentralized applications, they often authorize smart contracts to spend tokens on their behalf. While these approvals make future transactions more convenient, they can also remain active indefinitely unless manually revoked.

If a malicious contract receives unlimited spending permission, attackers can transfer approved tokens at any time without requesting another signature.

In this case, the victim’s wallet had granted an unlimited USDT allowance, allowing the attacker to empty the balance immediately after obtaining the approval.

Security researchers say this technique has become increasingly common throughout 2026.

In May, a fake Uniswap website stole roughly $400,000 from multiple users after convincing them to approve a malicious contract. Earlier this month, a fraudulent HyperSwap airdrop campaign similarly drained a user’s wallet within seconds of a single approval.

 

Automated phishing attacks are becoming more sophisticated

The theft also demonstrates how attackers are automating wallet-draining operations.

The attacker used Multicall functionality to bundle multiple contract interactions into a single transaction, allowing the funds to move almost instantly after the approval was granted.

The stolen USDT was immediately split into three outputs, making recovery even more difficult.

 

 

Because the exploit depended on legitimate blockchain permissions rather than compromised credentials, traditional wallet security measures often failed to detect suspicious activity before the transfers occurred.

Scam Sniffer warned that phishing groups increasingly target high-value wallets using automated scripts capable of adapting in real time, including recalculating wallet balances if an initial transfer fails.

Share

Default avatar

Giuseppe Ciccomascolo

After graduating with a Master’s in Advanced Journalism at the London School of Journalism Giuseppe worked as an analyst and Senior Reporter. In 2017, he transitioned to covering cryptocurrency-related news, producing documentaries and articles on Bitcoin and other emerging digital currencies and played a pivotal role in establishing the academy for a cryptocurrency exchange website.

Table of content

Ad

Related Articles