A cryptocurrency user lost nearly US$1 million by approving malicious token rights.
According to online tracking data, a cryptocurrency user approved a malicious token rights on Ethereum, resulting in the theft of nearly US$1 million in assets. The incident highlights how \"token approval\"-type phishing attacks have evolved from one-time scams to repeatable theft processes.
Records show that the victim lost 999,999 USDT in connection with a phishing approval attack on Ethereum. The attacker first tried to transfer funds through a batch call request, but failed due to insufficient balance, and then successfully transferred all the remaining funds through subsequent transfer operations within a few seconds.
Key Points
An \"approval\" operation on the Ethereum token could give an attacker full control, allowing it to quickly sweep away assets through automated transfers. Reports describe a multi-step theft process: the initial batch call attempt may fail, but subsequent transactions can still empty the wallet. Approval phishing attacks remain a widely used method in the chain fraud ecosystem, and this method is also often used in investment fraud. Researchers warn that scammers often reuse the same wallet pattern-meaning that a revealed incident can reveal a broader network of connected activities. Address poisoning further exacerbates the risk, and users should be extremely cautious about copied addresses and pasted contract or wallet data.
Nearly one million dollar theft triggered by token approval authority
The core of this type of phishing mechanism is the seemingly routine token approval process. In fraud, victims are induced to sign a transaction, thereby granting malicious actors the right to spend tokens or transfer funds from their wallets. The approval operation may be disguised as a small step-such as opening a transfer, interaction, or \"verification\"-but actually grants extensive or long-term access that an attacker can exploit immediately.
It was disclosed that the attack script recalculated the victim\'s remaining balance after the first theft attempt and accurately extracted all remaining funds. This means that attackers don\'t have to guess the contents of the wallet-the execution process adjusts in real time to maximize theft.
On the blockchain browser, the fraud involved three transactions that ultimately transferred 999,999 USDT.
Why approved fishing continues to work
Approved fishing is not a new trick, but a recurring pattern. Data shows that the total damage caused by phishing attacks in 248 incidents in 2025 reached US$723 million. The structure of these scams is highly consistent: victims are induced to click \"approve\" through social engineering, but the approval hands over the token control to a contract controlled by the attacker. This data is particularly important because it shows that the problem is not isolated. For criminals, approval phishing is very scalable: once a victim grants token rights, an attacker can use the rights to clear the balance without the need for continued victim interaction.
From the overall perspective of the industry, the scale of fishing losses remains high. The cryptocurrency sector lost $366 million to phishing attacks in the first half of this year, further demonstrating that approval rights-based scams are part of a broader wave of on-chain fraud rather than a niche threat.
Fraud reuse wallets and rights patterns
When criminals reuse the same infrastructure and wallet targets, the overall risk is further amplified. In another incident earlier this month, a victim lost $1.65 million by connecting to a fake exchange and signing a malicious contract. The researchers pointed out that in this scenario, approval rights gave the attacker \"unlimited access\", allowing automatic sweeping tools to sweep away all funds.
Previous analysis reports showed that online fraud will cost at least US$14 billion in 2025, and investment fraud remains the main category. In the analysis of approval phishing, relevant agencies pointed out that methods based on approval authority are one of the ways in which investment fraud shifts from social engineering to theft along the automated chain. At the same time, scammers reuse the same wallet, take advantage of the legal approval function of the contract, and adopt consistent funds transfer paths between different victims. This repetitive behavior is important for investors and users-when investigators map recurring patterns of permissions and extraction behavior, it may reveal a broader network of collaborative activities rather than isolated attackers.
Investigators say each exposed incident could reveal a wider network because scammers reuse wallets and operating paths. Users should pay attention to whether similar approval signatures, contract patterns, or theft techniques appear in different incidents-these duplications are often signs of systematic activity.
Address poisoning increases additional risks
Phishing token approval is not the only mechanism for money theft. Address poisoning is also a common tactic: fraudsters create wallet addresses similar to legitimate addresses and send small amounts of \"dust\" transactions to these similar addresses. When victims copy and paste addresses, dust contaminated approximate addresses can cause users to send funds to the attacker rather than the targeted recipient.
This risk is particularly prominent in ecosystems where manual copy-and-paste operations are still prevalent. Related tools have launched real-time address poisoning detection, which compares each pasted address with addresses previously interacted with by the wallet, aiming to flag suspicious new or unexpected addresses that match known fraud patterns.
Whether it\'s approval phishing or address poisoning, they all have in common user interaction: Scams exploit people\'s perceptions of signing or sending content. Therefore, defenses require users to slow down and carefully verify specific approval rights or receiving addresses before performing operations.
Future Focus
Approval phishing incidents often spread rapidly when criminals optimize execution methods and reuse wallet models. Users should be vigilant about any signature requests related to token approval, avoid rushing operations, and consider using Detection Tools-while security teams and on-chain analysts may continue to track recurring stolen scripts and shared infrastructure to identify and block these activities before they expand further.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH