Phishing approval lets attackers sweep almost entire wallet
A crypto user lost nearly $1 million after accepting a malicious Ethereum token approval that enabled attackers to drain the wallet. Blockchain security monitors report the victim signed an approval request that granted permission to spend the wallet’s USDT balance, allowing an automated script to extract nearly the full amount.
How the theft unfolded
On-chain analysis shows attackers initially attempted to pull a rounded $1,000,000 using multicall transactions, but the withdrawal failed because the wallet held slightly less than that figure. Seconds later, the malicious script recalculated and removed the exact remaining balance, successfully transferring 999,999 Tether (USDT) out of the wallet.
Security platform Scam Sniffer noted the scripted adjustment that captured the wallet’s final balance, illustrating how small timing and calculation tweaks can make approval-based phishing highly effective. The event adds to growing losses from token approval scams that continue to target Ethereum and other EVM-compatible chains.

Approval phishing remains a top threat in crypto
Researchers and security firms warn approval phishing is one of the most common social engineering tactics in decentralized finance (DeFi). Victims are usually tricked into signing what appears to be a routine transaction, unknowingly granting unlimited spending rights to malicious contracts or addresses. Once approved, attackers can move funds without an additional signature from the wallet owner.
According to blockchain security firm CertiK, phishing attacks in 2025 caused roughly $723 million in losses across 248 documented incidents. Many of those breaches involved malicious token approvals that allowed automated sweepers to empty wallets or siphon stablecoins like USDT.
Recent related incidents highlight varied on-chain risks
This theft follows other significant on-chain compromises reported in recent weeks. Earlier this month, a user lost around $1.65 million after connecting to a counterfeit exchange and signing a harmful smart contract. In that case, the malicious approval granted attackers unfettered access, enabling automated tools to drain funds.
Separately, a trader lost nearly $2 million when a decentralized exchange routed an Ether swap through a low-liquidity pool. Security firm GoPlus Security attributed that loss to adverse transaction routing and same-block arbitrage, not phishing — underscoring that execution paths and DeFi liquidity considerations also pose major risks.
Practical steps to reduce approval phishing and routing losses
Experts recommend several defenses for users conducting on-chain transactions and DeFi activity:
- Carefully review every signature and approval request; avoid blindly accepting unlimited allowances.
- Use wallet features that set token spend limits instead of granting infinite approvals.
- Inspect transaction execution paths and slippage settings before confirming swaps to reduce routing exploits.
- Install reputable scam detection browser extensions and use blockchain security services to screen suspicious contracts.
- Pause and verify any unexpected prompts from dApps or exchanges, especially when connecting wallets.
Scam Sniffer and other security researchers emphasize slowing down and validating each interaction. For crypto users, heightened vigilance around token approvals, wallet connections, and transaction routing remains essential to protect assets and minimize exposure to phishing and on-chain exploits.




Discussion
Leave a Comment
Comments (2)
Is this even true? if the script recalculated in seconds that's terrifying — who audits these approvals, or am I missing something here...
wow didn't expect that... one careless click and almost a mil gone. UI needs a hard stop, an extra confirm, ppl sleep on prompts