Saturday, July 11, 2026 Today's news About Live prices →
£ PoundToken
Crypto, covered properly · Est. 2026
Regulation

Ethereum wallet’s $1m phishing loss revives calls for approval safeguards

A near-$1m Ethereum phishing theft adds to $723m lost to approval scams in 2025, sharpening scrutiny of wallet security standards.

By Rajesh Patel · ·3 min read
Ethereum wallet’s $1m phishing loss revives calls for approval safeguards

A crypto holder has lost nearly $1 million after signing a malicious token approval on Ethereum, in an incident that blockchain security platform Scam Sniffer says forms part of a wider pattern of approval-based phishing that cost the sector hundreds of millions of dollars last year. The theft, confirmed on Wednesday, is the latest in a string of large wallet drains that industry figures argue exposes gaps in how ordinary users are protected from smart-contract-level fraud.

According to Scam Sniffer, the victim lost 999,999 Tether (USDT) after approving what appeared to be a routine transaction. On-chain data reviewed by the firm showed the attackers initially tried to withdraw a rounded $1 million via multicall transactions, but the attempt failed because the wallet held slightly less than that figure. “The script recalculated and pulled the exact remaining balance,” Scam Sniffer said, describing how the attackers adjusted their approach within seconds to extract the entirety of what remained.

A recurring failure mode in wallet security

Approval phishing exploits a familiar weakness in how decentralised applications interact with wallets: users are asked to grant spending permissions that, once signed, can allow attackers to move funds without any further authorisation. Security researchers say victims frequently believe they are approving a harmless or routine transaction, unaware they have granted open-ended access to their holdings.

Blockchain security firm CertiK has recorded $723 million in losses across 248 phishing incidents during 2025 alone, underscoring that approval-based attacks remain one of the most persistent forms of social engineering in the sector. The scale of these losses has prompted repeated warnings from security researchers that revoking unused token approvals and verifying contract addresses should be treated as standard wallet hygiene rather than optional precautions.

The latest theft follows a separate case reported earlier this month, in which a wallet holder lost approximately $1.65 million after connecting to a fraudulent exchange interface and signing a malicious smart contract. Researcher Ryan Coleman said at the time that “the approval gave attackers unlimited access, enabling an automated sweeper to drain funds,” adding that users should “always verify contracts and revoke unused token approvals.”

Distinct risks converge on the same week

The phishing loss comes days after another high-profile on-chain incident illustrated a different structural risk facing crypto users. Earlier this week, a trader lost nearly $2 million after a decentralised exchange routed an ether swap through a low-liquidity pool, allowing a same-block arbitrage trade to extract most of the transaction’s value. Unlike the phishing case, that loss stemmed from flawed transaction routing rather than a compromised approval, but both incidents point to the same underlying problem: retail users bear the operational risk of interacting with complex on-chain infrastructure with limited safeguards.

Taken together, the incidents add fresh weight to arguments from security firms and consumer advocates that exchanges, wallet providers and decentralised application developers need clearer standards for approval disclosures and transaction-routing safety, particularly as institutional adoption of on-chain infrastructure continues to grow.

Read more: $1m Uniswap Permit2 phishing loss underscores $14bn onchain scam crisis

More Regulation

Leave a Reply

Your email address will not be published. Required fields are marked *