A cryptocurrency user lost nearly $1 million on Wednesday after signing up for a phishing token authorization on Ethereum. Online data shows that in the first half of 2025, the industry\'s losses due to phishing attacks reached US$366 million.
Security monitoring agencies issued an alert on Thursday that a victim lost 999,999 USDT due to an Ethereum phishing token authorization scam. The scammers first tried to steal a full $1 million through multiple calls, but failed due to insufficient funds; seconds later, they successfully transferred the remaining balance in the account through subsequent transfers. \"The script recalculated and transferred the precise remaining balance,\" the alert said.
Social engineering attacks using phishing token authorization have become a common method of cryptocurrency fraud. According to data from the Security Audit Platform, a total of 248 phishing incidents occurred in 2025, with a total loss of US$723 million. Scammers trick victims into making seemingly harmless transactions and gain access to their wallets. Victims mistakenly thought that clicking \"authorize\" would only perform a minor operation, but the malicious link actually gave the attacker the right to transfer funds from his wallet.
The attacker stole $999,999 through three transactions. Scammers will reuse the same wallet.
Earlier this month, a wallet holder lost $1.65 million in a similar incident after connecting to a fake exchange and signing malicious contracts. The researchers commented: \"Authorization gives the attacker unlimited rights, allowing automated coin sweeping tools to clear funds.\"
Blockchain security companies reported in June that at least $14 billion had been collected in online fraud in 2025. Investment fraud remains the main category, and authorized phishing is the way some of these scams are implemented on-chain.
A senior investigator at the company pointed out: \"Scammers reuse the same wallets, legal authorization features in contracts, and withdrawal channels for different victims, which means that every report reveals a broader network.\"
Security agencies advise cryptocurrency users to carefully check all signature requests before authorizing, avoid rushing transactions, and use tools such as fraud detection extensions.
Address poisoning remains a threat. Address poisoning is another attack method used by fraudsters in conjunction with phishing token authorization. Scammers create an address closely similar to the target wallet address and send small amounts of \"dusty\" funds to that address, allowing users to mistakenly send funds to the fraudulent address instead of a legitimate one. The popular Ethereum wallet launched real-time address poisoning detection in June, which compares each pasted address with the addresses the wallet has previously interacted with.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH