Home / News / Ethereum / Ethereum Phishing Scam Drains Nearly $1M From Crypto Wallet

Written By

Ethereum Phishing Scam Drains Nearly $1M From Crypto Wallet

Ethereum Phishing Scam Drains Nearly $1M From Crypto Wallet
Ethereum Phishing Scam Drains Nearly $1M From Crypto Wallet

What to Know

  • Nearly $1 million in USDT was drained from an Ethereum wallet.
  • Scam Sniffer says the attacker used a token approval scam.
  • CertiK found 2025 phishing losses hit $723 million across 248 incidents.
  • A separate trader lost nearly $2 million to a bad DEX swap route.

An Ethereum phishing scam drained nearly $1 million from a wallet. The victim lost 999,999 USDT after signing a bad approval. Blockchain security firm Scam Sniffer flagged the theft on Wednesday. The attacker’s script failed once, then adjusted and drained the rest.

What Happened in the Ethereum Phishing Scam?

A crypto user lost nearly $1 million in a single approval scam. The victim held 999,999 USDT on Ethereum. They signed a malicious transaction request. That signature handed spending rights to an attacker. Scam Sniffer tracked the theft and shared it publicly on Wednesday.

This kind of attack is called approval phishing. It tricks users into approving unlimited spending. The victim thinks they are signing something harmless. Instead, they give an attacker full wallet access. No second signature is needed after that.

Approval scams do not need fancy hacking skills. They rely on one careless click. That is what makes them so dangerous. Crypto wallets do not warn users clearly enough. Most people never check what they are approving. That single gap is the entire attack surface.

USDT, known as Tether, is a stablecoin pegged to the US dollar. That is why the loss reads as a flat dollar figure. Most phishing victims lose value that swings with the market. Here, the number stayed simple and painfully exact. Few victims expect that kind of exact, cruel precision.

How the Attacker Drained the Wallet

On-chain data shows the attack happened in two steps. First, the attacker tried to pull a rounded $1 million. They used multicall transactions to do it. But the wallet held slightly less than that amount. The first attempt failed right away.

Seconds later, the script adjusted itself. It recalculated the wallet’s real balance. Then it drained every remaining token. Scam Sniffer described the moment clearly.

This kind of speed shows automation at work. Sweeper bots watch wallets that sign bad approvals. They strike within seconds of a signature. Tools from Scam Sniffer phishing approval attack track these attacks across chains. Their data helps researchers spot patterns fast.

A multicall transaction bundles several actions into one. Attackers use it to try transfers fast and cheap. It also lets scripts adjust mid-attack without extra signatures. That flexibility is exactly what let the second attempt succeed.

Multicall scripts are not new. Attackers have refined them for years now. Each failed attempt teaches the bot to adjust faster next time. Expect these scripts to keep getting faster.

The script recalculated and pulled the exact remaining balance.

— Scam Sniffer

CertiK Data Shows Rising Phishing Losses

What Is a Token Approval Scam?

A token approval scam tricks a user into signing a permission. That permission lets a contract spend the user’s tokens. Attackers set the limit to unlimited in most cases. Once signed, they can drain funds anytime. No extra approval or warning pops up first.

This kind of scam is common across crypto. Blockchain security firm CertiK tracked losses through all of 2025. Phishing scams alone caused $723 million in damage. That total came from 248 separate incidents. The CertiK 2025 phishing losses report flagged phishing as a top threat.

Approval scams work because permissions feel routine. Users click approve dozens of times a week. Fake sites copy real wallet pop-ups closely. Most victims never read the fine print. That habit is exactly what attackers count on.

Do the math and the average incident cost about $2.9 million. That is roughly three times what this Ethereum victim lost. Some approval scams hit whales for tens of millions at once. Others drain smaller wallets down to the last cent, just like this case.

Attack scripts do not sleep or hesitate. They scan for fresh approvals every few seconds. The moment a signature lands onchain, a bot can act. That is why phishing losses stay so high year after year. Human reaction time simply cannot keep up.

USDT price and market data
Source: CoinMarketCap

Other Recent Wallet and DeFi Losses

This is not the only big loss this month. Earlier in July, another user lost about $1.65 million. That victim connected to a fake exchange site. They then signed a malicious smart contract. The approval opened the door for an automated sweeper.

Researcher Ryan Coleman shared details of that case on Friday. His warning echoed what happened with the $1 million theft. Both cases show the same pattern. A victim signs once. Then bots do the rest automatically.

A different kind of loss also hit traders this week. A trader lost nearly $2 million on a decentralized exchange swap. The exchange routed an Ether trade through a thin liquidity pool. A same-block bot extracted most of the trade’s value. GoPlus Security transaction routing analysis blamed bad routing, not phishing.

Three cases hit crypto wallets in the same stretch. The Ethereum approval theft. The $1.65 million exchange scam. The $2 million routing loss. Combined, they erased more than $4.6 million in days. That is real money leaving real wallets, not just a headline number.

Phishing and bad routing are different problems. Both drain wallets just as fast. Together, they show how many ways funds can vanish onchain. Security researchers keep repeating the same advice. Slow down before signing anything.

The approval gave attackers unlimited access, enabling an automated sweeper to drain funds.

— Ryan Coleman, Researcher

How Can Crypto Users Avoid Phishing Approval Scams?

Crypto users can avoid most approval scams with a few habits. Check every signature request before approving it. Use a wallet that shows what permissions you are granting. Revoke old approvals you no longer need. Never rush through a pop-up just because it looks official.

Scam Sniffer gave the same advice after this theft. Review every signature request carefully. Do not rush into approving anything. Use scam detection tools or browser extensions first. These small steps can stop most sweeper bots cold. That advice is not new, but it still works.

Here is the harder truth. Wallets still make approvals too easy to miss. Users get blamed for clicking too fast. But the interface rarely warns them clearly. Until that changes, these losses will keep piling up. It is a design failure, not just user error.

If you hold crypto, this is not abstract. One bad click can erase a life-changing sum in seconds. Diversifying wallets and using hardware signers helps limit exposure. But no tool replaces reading the approval screen every time.

Nearly $1 million is gone for good. No refund, no reversal, no second chance. The next target might already be signing something right now.

Frequently Asked Questions

What happened in the Ethereum phishing scam?

A crypto wallet lost nearly $1 million in USDT after its owner approved a malicious Ethereum transaction, according to Scam Sniffer. The attacker first tried to pull a rounded $1 million using multicall transactions, but the attempt failed. Seconds later, the script adjusted and drained the wallet’s exact remaining balance instead.

What is a token approval scam?

A token approval scam is when a user signs a transaction that gives a contract or attacker permission to spend their tokens. Attackers set the approval limit to unlimited in most cases, so once a victim signs, the attacker can drain the wallet without needing another signature.

How much did phishing scams cost crypto users in 2025?

Phishing scams caused $723 million in losses across 248 incidents during 2025, according to blockchain security firm CertiK. That works out to an average of roughly $2.9 million per incident, though losses ranged from small wallet drains to attacks on much larger holdings.

How can crypto users avoid approval phishing attacks?

Crypto users can avoid approval phishing by checking every signature request before approving it and never rushing a wallet pop-up. Scam Sniffer recommends revoking old approvals, using scam detection tools or browser extensions, and reviewing what permissions a transaction actually grants before signing.

This article is for informational purposes only and does not constitute investment advice. Every investment and trading decision involves risk. Readers should conduct their own research before making any financial decisions.

Share With Your Network :

Facebook
X
LinkedIn
Pinterest
Reddit
Telegram
WhatsApp
Email
Threads

James Wright

James Wright is a Crypto News Reporter at TheCryptoWorld, covering breaking developments across exchanges, regulation, and institutional adoption. With a journalism background rooted in business reporting, James transitioned to full-time crypto coverage in 2020 after covering the rise of decentralized finance for an independent fintech publication. He focuses on delivering fast, accurate reporting on the stories that move markets — from SEC enforcement actions to major exchange listings and corporate treasury moves.
0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Table of Contents

Check also

Specific Crypto details

Fear & greed index
49
▲ +4 from yesterday
Updated: April 11, 2026
▼ Fear
Recovering from extreme fear
0
Extreme fear
25
Fear
50
Neutral
75
Greed
100
Extreme greed
Yesterday
45
Fear
Last week
30
Fear
April 8
11
Extreme fear
0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Binance Lists Microsoft Meta Tokenized Stocks Amid $347B RWA Token Surge

Exchanges

4 weeks ago

Binance Lists Microsoft Meta Tokenized Stocks Amid $347B RWA Token Surge

James Wright

Bitcoin ETF Outflows Hit $4.5B as BTC Falls Below $59K

Bitcoin

4 weeks ago

Bitcoin ETF Outflows Hit $4.5B as BTC Falls Below $59K

James Wright

Citi Bitcoin Price Target Cut to $82,000 as ETF Flows Dry

Bitcoin

4 weeks ago

Citi Bitcoin Price Target Cut to $82,000 as ETF Flows Dry

James Wright

Solana RWA Network Hits $3.4 Billion All-Time High

Altcoins

4 weeks ago

Solana RWA Network Hits $3.4 Billion All-Time High

James Wright

Market Analysis

The Future of Crypto, Covered Daily

Real-time news, expert analysis, and market insights  trusted by thousands of crypto investors worldwide.

You have been successfully Subscribed! Ops! Something went wrong, please try again.
0
Would love your thoughts, please comment.x
()
x