EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Phishing authorization stole 999,000 USDT from Ethereum wallet

2026-07-09 18:25:12
Bookmark

On July 9, 2026, an Ethereum user lost nearly US$1 million in USDT after signing a malicious token authorization transaction. The incident occurred quickly, and the attacker used phishing induced authorization to steal funds from the victim\'s wallet. This case reveals a common but efficient attack method in the Ethereum ecosystem: users unintentionally grant excessive privileges to malicious contracts.

According to GoPlus Security, funds were stolen from victim addresses 0x8C949361... 62530F89 due to authorizations granted to multiple phishing addresses. Phishing activities targeting token authorizations have become a common method for attackers to pursue high-value and low-resistance to steal funds. Victims are often lured to deceptive websites that mimic legitimate DeFi platforms, airdrop requests or emergency wallet operations. Once authorized, a malicious contract can transfer tokens at any time without additional user confirmation, allowing attackers to strike when the balance is sufficient.

GoPlus Security alert: A user lost US$1 million USDT by signing a malicious #Approve transaction. Victim\'s address: 0x8C949361 B49320 C48a51 F4B1 C6f9 f83862530F89 Fishing address: 0x6D8c 070338 eC3d 297f1D0ECEEA 296bd 7E13a32b9... - GoPlus Security(@GoPlusSecurity) July 9, 2026

This incident is also the same as a previous Ethereum phishing case-when a user lost approximately US$1.76 million in USDC after signing a malicious Permit authorization. In that attack, the attacker used approved signatures to transfer funds without having to be confirmed by the wallet again, indicating that authorization and Permission-based fraud continues to threaten stablecoin holders.


Attack mechanism and execution

attacks rely on a phishing token authorization, allowing malicious contracts to use the victim\'s USDT without further confirmation. The attacker first tried to transfer the entire $1 million, but almost failed due to insufficient balance. 36 seconds later, the script adjusted the policy and successfully transferred the remaining approximately 999,999 USDT.

Victim address: 0x8C949361…62530F89

Key attacker address: 0x6D8c 0703…13a32b9, 0xf84c6257…3E68d93, 0xc508a8…70Da1

Main theft transaction: 0x6e882 fd8…f2e6ffb9

Broader context of phishing authorizations

Token authorization vulnerabilities remain the number one cause of personal loss in the Ethereum ecosystem. Such attacks take advantage of the ERC-20 standard authorization mechanism, which allows users to delegate spending rights to contracts. Scammers create seemingly normal interfaces but set unlimited authorization limits so that funds can still be stolen even after months. Since 2026, similar incidents have emerged one after another, constantly targeting users through false airdrops, NFT casting or impersonating agreements.

A similar phishing pattern also appeared in a Google advertising campaign that pretended to be Uniswap-users were redirected to fake websites and lost more than $400,000 after connecting to their wallets and approving malicious transactions. This case shows that attackers continue to combine trusted brand impersonation, paid advertising, and wallet theft of contracts, using regular DeFi interactions to carry out attacks.

Security monitoring services have recorded a large number of parallel attack activities, and attackers use scripted tools to monitor victim wallets and quickly perform transfers once conditions are met. Although some reports show a decline in overall fishing losses, the continued existence of these methods suggests that user education and wallet protection measures still lag behind evolving social engineering methods.


Impact and Recommendations

This loss is a major personal financial blow to the affected users. No specific protocol is directly exploited; the vulnerability stems from user-signed rights, not smart contract flaws on mainstream platforms.

This latest incident is in line with a broader security trend in 2026-attackers are increasingly targeting client vulnerabilities rather than just smart contract vulnerabilities. Previous reports pointed out that private key leaks accounted for about 40% of the total losses of cryptocurrency hackers, and the second quarter of 2026 became the quarter with the largest number of hacking incidents.

Across the industry, authorized phishing continues to pose a challenge in broader cryptocurrency fraud trends, including AI-assisted attacks and sophisticated wallet theft tools. Users are advised to exercise extreme caution with regard to any signature requests. Key protection measures include:

Install well-known security extensions that flag risk authorizations;

Regularly audit and revoke token permissions through tools such as Revoke.cash;

Independent verification of contract addresses through blockchain browsers before signing;

Avoid interacting with unsolicited links or unverified dApps.

This incident reminds us that in an environment where authorizations can have long-term consequences, careful verification of transactions is crucial. As Ethereum usage grows, strengthening user-side defenses remains the key to reducing such preventable losses.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP