A crypto user lost nearly a million bucks on Wednesday. The cause? Signing a phishing token approval on Ethereum.
Scam Sniffer flagged the incident Thursday. The victim lost 999,999 USDT to an approval phishing scam. Attackers first tried draining a rounded $1 million through multicalls but failed due to insufficient funds. Seconds later, they recalculated and pulled the exact remaining balance. Clean, automated, ruthless.
This isn’t a one-off. Onchain scammers raked in over $14 billion last year, per Chainalysis. Phishing losses hit $723 million across 248 incidents in 2025, according to CertiK. And $366 million was lost to phishing in just the first half of this year.
Approval phishing works like this: scammers trick you into clicking “approve” on what looks like a minor transaction. In reality, that click gives them unlimited access to your wallet. An automated sweeper then drains everything.
“Scammers reuse the same wallets, legitimate approval features, and cash-out routes across victims,” Chainalysis senior investigator Renato Bastos said. “Each report exposes a wider network.”
Earlier this month, someone lost $1.65 million after connecting to a fake exchange and signing a malicious contract. Same playbook, different day.
Scam Sniffer’s advice? Double-check every signature request. Don’t rush transactions. Use scam detection extensions. Also worth noting: address poisoning is a related threat where scammers create nearly identical wallet addresses and send tiny “dust” transactions, hoping you’ll accidentally send funds to the wrong address. MetaMask added live detection for this in June.
The takeaway’s simple. One careless approve click can cost you everything. Treat every signature request like it might be the trap.
