EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Traders sign phishing token authorization and lose $1 million

2026-07-09 18:31:57
Bookmark

A cryptocurrency user lost nearly $1 million on Wednesday after signing up for a phishing token authorization on Ethereum. Online data shows that in the first half of 2025, the industry\'s losses due to phishing attacks reached US$366 million.

Security monitoring agencies issued an alert on Thursday that a victim lost 999,999 USDT due to an Ethereum phishing token authorization scam. The scammers first tried to steal a full $1 million through multiple calls, but failed due to insufficient funds; seconds later, they successfully transferred the remaining balance in the account through subsequent transfers. \"The script recalculated and transferred the precise remaining balance,\" the alert said.

Social engineering attacks using phishing token authorization have become a common method of cryptocurrency fraud. According to data from the Security Audit Platform, a total of 248 phishing incidents occurred in 2025, with a total loss of US$723 million. Scammers trick victims into making seemingly harmless transactions and gain access to their wallets. Victims mistakenly thought that clicking \"authorize\" would only perform a minor operation, but the malicious link actually gave the attacker the right to transfer funds from his wallet.

The attacker stole $999,999 through three transactions. Scammers will reuse the same wallet.

Earlier this month, a wallet holder lost $1.65 million in a similar incident after connecting to a fake exchange and signing malicious contracts. The researchers commented: \"Authorization gives the attacker unlimited rights, allowing automated coin sweeping tools to clear funds.\"

Blockchain security companies reported in June that at least $14 billion had been collected in online fraud in 2025. Investment fraud remains the main category, and authorized phishing is the way some of these scams are implemented on-chain.

A senior investigator at the company pointed out: \"Scammers reuse the same wallets, legal authorization features in contracts, and withdrawal channels for different victims, which means that every report reveals a broader network.\"

Security agencies advise cryptocurrency users to carefully check all signature requests before authorizing, avoid rushing transactions, and use tools such as fraud detection extensions.

Address poisoning remains a threat. Address poisoning is another attack method used by fraudsters in conjunction with phishing token authorization. Scammers create an address closely similar to the target wallet address and send small amounts of \"dusty\" funds to that address, allowing users to mistakenly send funds to the fraudulent address instead of a legitimate one. The popular Ethereum wallet launched real-time address poisoning detection in June, which compares each pasted address with the addresses the wallet has previously interacted with.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP