Trader Loses $1 Million After Signing Malicious Token Approval
As decentralized finance and cryptocurrency trading have grown, token-approval phishing through smart contracts has become one of the most serious security threats. These attacks typically trick users into signing seemingly legitimate token approvals that instead give malicious contracts unlimited authority to transfer funds from their wallets. Assets can therefore be drained in an instant even when users safeguard their private keys, underscoring the critical importance of verifying on-chain transaction signatures and managing smart-contract security in decentralized systems.
Blockchain security firm Scam Sniffer detected a major phishing incident on July 8, 2026, in which scammers stole the balance of an Ethereum user’s wallet after the victim mistakenly signed a malicious token approval. The attacker initially tried to transfer $1 million in a single transaction, but the attempt failed because the wallet lacked sufficient funds. An automated script then calculated the wallet’s exact balance, allowing the attacker to transfer about $999,999 in USDT across three transactions.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →