
A crypto user has lost nearly $1 million after approving a malicious Ethereum transaction that allowed scammers to drain the wallet. According to blockchain security platform Scam Sniffer, the victim lost 999,999 Tether (USDT) in an Ethereum phishing token approval scam on July 9, 2026 after signing a malicious approval request. The wallet was not hacked in the conventional sense—no private key leaked—but the owner authorized the transfer themselves by approving a malicious contract. On-chain data showed the attackers first attempted to withdraw a rounded $1 million through multicall transactions, but the transfer failed because the wallet held slightly less than that amount. The theft was executed in three transactions: 639,999 USDT, 159,999 USDT, and 200,000 USDT, with the recipient address marked as phishing on Etherscan. The near-round figure suggests the wallet's full stablecoin position was taken, highlighting how phishing scams specifically target stablecoins due to their instant convertibility and value retention.
The latest incident highlights the escalating phishing crisis in the crypto industry, with $366 million in phishing losses recorded in the first half of 2025 alone. Blockchain security firm Chainalysis reported in June that onchain scams pulled in at least $14 billion in 2025, with investment scams remaining the dominant category. As per Chainalysis, approval phishing is how some of these scams play out onchain, with scammers reusing the same wallets, legitimate approval features from contracts, and cash-out routes across victims. According to Scam Sniffer, scammers trick victims into giving malicious actors access to their wallets, taking the form of innocuous-seeming transactions where users falsely believe clicking "approve" will only initiate a minor task. The attackers then use social engineering tactics to drain funds from the wallet. Scam Sniffer analysts have tied a 200 percent jump in phishing losses this year to a shift toward high-value wallets, making these attacks increasingly dangerous for larger holders.
The attackers exploited a fundamental design flaw in ERC-20 tokens that allows scammers to drain funds without accessing private keys. Every ERC-20 token, including USDT and USDC, uses an approve function that lets users grant smart contracts permission to move tokens on their behalf. The problem is that approvals can be set to unlimited amounts and stay active until revoked. Phishing sites disguise malicious approve calls as harmless activities like wallet connections, token claims, NFT mints, or "verify your assets" prompts. Victims see normal signature requests and click confirm, unknowingly handing strangers' contracts the right to drain entire token balances. In this case, the automated drainer executed the transfer seconds after the approval was granted, demonstrating how quickly these attacks can execute once permission is granted. The victim's wallet held an unlimited allowance for the token, which gave the attacker room to act without any further confirmation, making the attack particularly devastating. The latest analysis reveals that blind signing—approving transactions without understanding their true effect—is the single largest vulnerability in self-custody, as users often trust website descriptions instead of transaction content.
The latest incident follows another major wallet compromise reported on July 4, 2026, where a crypto holder lost about $1.65 million after connecting to a fake exchange and signing a malicious smart contract. According to researcher Ryan Coleman, the approval gave attackers unlimited access, enabling an automated sweeper to drain funds. Additionally, earlier this week, a trader lost nearly $2 million after a decentralized exchange routed an Ether swap through a low-liquidity pool, allowing a same-block arbitrage trade to extract most of the transaction's value. The scam drained the victim's wallet within seconds of a single click, highlighting the speed at which these attacks can execute. The incident also echoes a MetaMask phishing campaign uncovered in January, which used fake two-factor prompts to bypass user suspicion entirely, demonstrating how sophisticated these attacks have become. Wallet providers keep adding protections, but analysts note that no interface change fully replaces a careful read of what a signature actually authorizes. The latest data shows that drainer-as-a-service has industrialized wallet theft, with sophisticated developers building complete packages including malicious smart contracts, phishing templates, and sweeping automation, rented to non-technical criminals for a cut of stolen funds.
The latest phishing loss comes as researchers urge users to review execution paths carefully before confirming onchain transactions. Scam Sniffer advised users to double-check all signature requests before approving, avoid rushed transactions and use tools such as scam detection extensions. The firm recommends checking the exact contract address and permission scope that a wallet displays, and users should avoid approving requests by default. Revoking unused or unlimited approvals on a regular basis remains one of the simplest defenses against this attack type. Following the theft, Scam Sniffer analysts renewed calls for crypto users to verify every signature request before confirming it. The gap between one signature and a drained wallet keeps narrowing for Ethereum users as phishing tactics grow more automated, with token approval phishing remaining one of the most persistent threats in decentralized finance where attackers do not need victims' private keys to steal funds. With both approval phishing and address poisoning in play, the common theme is user interaction—scams manipulate what people think they're signing or sending, requiring defenses that slow down and verify exact permissions before proceeding. The industry consensus emphasizes that the most important firewall in crypto is the pause between reading a signing request and approving it, with the responsibility of self-custody requiring informed suspicion, readable transactions, minimal exposure, and regular approval revocation.