An Ethereum user signed a phishing token authorization, resulting in the theft of 999,999 USDT from his wallet, which gave the attacker the right to withdraw funds from the wallet.
This loss did not stem from a leak of mnemonic words or a loophole in the USDT contract, but occurred through an authorization mechanism. Authorization is a standard ERC-20 privilege that allows another address to spend tokens from a user\'s wallet. If the authorized payer is malicious, an attacker can use this authority to transfer tokens without obtaining the victim\'s private key.
The attacker first tried to withdraw 1 million USDT from the wallet, but the transaction failed because the requested amount exceeded the available balance of US$631. 36 seconds later, the attacker tried again, corrected the amount, and wiped out the remaining 999,999 USDT.
Authorizes currency thieves to continue to target stablecoins
USDT authorizations are high-value targets because stablecoins settle quickly, are pegged to the U.S. dollar, and can be traded in highly liquid channels. Malicious authorizations can turn normal wallet prompts into direct spending authorizations, especially when users sign through fake claim pages, phishing links, fake apps, or damaged front-end interfaces.
Crypto-wallet thieves often use a combination of social engineering, fake or compromised websites, malicious scripts, and wallets controlled by attackers. These pages make the operation seem like a regular process, while wallet prompts generate the authorization or signature needed to transfer funds.
The same authorization model also explains why users need to check spending rights after interacting with unfamiliar applications. Users can reduce the risk of dormant authorization by using a trusted, favorite authorization tool to check old disbursement rights, verify payer addresses, and remove access rights that no longer have practical use.
Wallet hints remain the main line of defense
Users should treat every authorization and signature request as a transaction with financial consequences, rather than a regular login step. Security reviews should start with the following aspects: domain names, connected wallets, authorized tokens, payer addresses, authorized amounts, and whether the request matches the operation the user intended to perform.
Recent coin theft incidents have exposed the same weaknesses in different scenarios. Polymarket users suffered a $2.94 million loss due to a vendor script that stemmed from a compromised front-end dependency rather than a confirmed smart contract vulnerability.
The funds from the incident were then transferred to three new Ethereum wallets, and the attacker transferred the value from the Polygon Bridge to Ethereum after converting the stolen assets.
The latest USDT case belongs to the same broader category of wallet security issues: users signed authorizations, and the attacker acted so quickly that any subsequent revocation operations could not be stopped.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following