Mark RadarMARK RADAR
About
EN
Sign in

Trader Loses $1 Million After Signing Malicious Token Approval

1 reports · First detected 2026-07-09 · Last active 2026-07-09

As decentralized finance and cryptocurrency trading have grown, token-approval phishing through smart contracts has become one of the most serious security threats. These attacks typically trick users into signing seemingly legitimate token approvals that instead give malicious contracts unlimited authority to transfer funds from their wallets. Assets can therefore be drained in an instant even when users safeguard their private keys, underscoring the critical importance of verifying on-chain transaction signatures and managing smart-contract security in decentralized systems.

Blockchain security firm Scam Sniffer detected a major phishing incident on July 8, 2026, in which scammers stole the balance of an Ethereum user’s wallet after the victim mistakenly signed a malicious token approval. The attacker initially tried to transfer $1 million in a single transaction, but the attempt failed because the wallet lacked sufficient funds. An automated script then calculated the wallet’s exact balance, allowing the attacker to transfer about $999,999 in USDT across three transactions.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)