Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Price Analysis
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Elon Musk and SpaceX composite image with the Indian flag and Bitcoin
    India vs Elon Musk: Starlink’s Global Wall of Bans, and the Crypto Thread Running Through It
    Physical gold Bitcoin (BTC) token standing in front of the US Capitol Building and the American flag
    Why Are U.S. Government Wallets Still Routing Seized Crypto to Coinbase?
    Charlie Lee, creator of Litecoin, standing in front of a blue Litecoin corporate logo wall
    Litecoin Turns 15: Original Bitcointalk Records Show How Charlie Lee Launched LTC in 2011
    Elon Musk with folded arms flanked by a giant Bitcoin coin, Tesla electric car, and SpaceX rocket launch
    Elon Musk’s Tesla and SpaceX Still Hold Over 30,000 Bitcoin: Why Is He Not Selling?
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Price Analysis
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Crypto User Loses $999,999 in USDT to a Single Phishing Signature

One malicious signature was all it took — and the automated script behind it was clinical enough to retry and empty the wallet down to the last dollar.

Written By Dhara Chavda
Edited by Divya Mistry
Published 2026-07-09·Updated 3 months ago
Make The Crypto Times preferred on GoogleGoogle
Crypto User Loses $999,999 in USDT to a Single Phishing Signature
Show AI Summary
A crypto user lost $999,999 in USDT after signing a malicious token approval, which triggered an automated script to drain their wallet in 36 seconds.
The attack began with a failed attempt to pull $1,000,000, but the script adjusted and pulled the exact remaining balance, highlighting the precision of automated wallet-draining attacks.
The theft occurred in two stages: the initial approval phishing and the subsequent automated draining, demonstrating the mechanical precision and speed of these attacks.

A single phishing signature has cost one crypto user $999,999 in USDT, according to the Web3 anti-scam firm Scam Sniffer, in a theft whose clinical execution underscores just how automated and precise wallet-draining attacks have become.

One signature, and a drainer that didn’t miss

The loss, flagged by Scam Sniffer and visible on-chain, followed the victim signing a malicious token approval on Ethereum, the kind of authorization that hands an attacker permission to move a wallet’s tokens. What makes this case a striking illustration is the mechanical precision of what happened next.

🚨 Someone lost $999,999 in USDT after signing a phishing token approval on Ethereum. 🎣

victim: 0x8c949361b49320c48a51f4b1c6f9f83862530f89
tx: https://t.co/54YXrwiVBi

🧵 pic.twitter.com/hnHPeQjNML

— Scam Sniffer | Web3 Anti-Scam (@realScamSniffer) July 9, 2026

The attacker’s automated script first attempted to pull around $1,000,000 from the wallet. That transaction failed because the wallet actually held about $631 less than a full million—the script had asked for more than was there. Rather than give up, the drainer simply adjusted.

Thirty-six seconds later, Scam Sniffer reported, the script recalculated and pulled the exact remaining balance, sweeping the wallet down to essentially nothing and leaving the victim with a loss of $999,999. It is a small detail with a chilling implication: these are not clumsy smash-and-grabs but automated systems that monitor, retry, and optimize in real time to extract the maximum possible amount.

How approval phishing works, and why it’s so dangerous

The attack vector at work here is one of the most common and most misunderstood in crypto, and understanding it is the best defense against it. Unlike a traditional hack, this kind of theft never touches the victim’s password or seed phrase. Instead, it exploits a routine, legitimate feature of tokens like USDT: the “approval.”

When a user interacts with a decentralized application, they are often asked to sign an approval, technically an approve or Permit authorization, that grants a smart contract permission to spend a certain amount of their tokens. This is a normal part of using DeFi.

The danger is that phishing sites disguise a malicious version of this request as something harmless: a fake airdrop claim, an NFT mint, or a “verify wallet” or “login” prompt. The victim, believing they are doing something routine, signs — and in doing so grants the attacker’s contract an allowance, often an unlimited one, over their tokens. From that moment, the thief does not need the victim’s keys or any further action; they can move the authorized funds whenever they choose.

The introduction of gasless signature mechanisms has made this even more insidious, because a malicious approval can be presented as a free, gas-less “signature” that many users assume carries no risk. Once the funds are gone, the transaction is irreversible; there is no bank to call and no chargeback to file.

‘Whale hunting’: The 2026 trend, and how to stay safe

This near-million-dollar loss is not an anomaly but a symptom of a deliberate strategic shift. According to Scam Sniffer data, signature-phishing losses jumped 207% in January 2026 compared with the month before, even as the total number of victims fell by around 11%. That combination points to what security researchers call “whale hunting”—attackers concentrating their efforts on fewer, wealthier wallets, where a single successful signature can yield six or seven figures rather than a few hundred dollars.

The tooling behind these attacks has industrialized into “Drainer-as-a-Service,” where developers rent out ready-made draining kits to lower-level scammers in exchange for a cut, complete with the kind of automated, self-correcting scripts on display in this theft.

The defenses, fortunately, are concrete. Before confirming any signature, users should rely on a wallet that simulates the transaction and shows exactly what it will do — if a prompt to “claim a free NFT” actually reads as authorizing the transfer of your USDT, that is the moment to abort.

Approvals should be treated as ongoing liabilities, not one-time clicks: tools that let users review and revoke standing token allowances can close off the permissions that make these drains possible, and doing so periodically is sound hygiene. Large holdings are safest in a hardware wallet that never interacts with random applications, with a separate low-value “burner” wallet used for airdrops and unfamiliar sites. And any unexpected request to sign, especially one framed as urgent verification, deserves suspicion rather than a reflexive click.

A final caution applies to anyone who has already been hit: victims are frequently targeted a second time by “recovery” services that promise, for an upfront fee, to retrieve stolen crypto. These are almost always a second scam preying on the first, and legitimate recovery never begins with a stranger demanding payment. The uncomfortable truth this case illustrates is that in self-custody, a single careless signature can be as costly as handing over the keys outright — and the scripts waiting on the other side are built to make sure nothing is left behind.

Also Read: Ledger and Trezor Users Are Being Tricked Into Giving Away Millions

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto ScamTether
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Polkadot Launches Native dotUSD Stablecoin Through OpenGov
Polkadot Launches Native dotUSD Stablecoin Through OpenGov
STRK Price Rises 19% as Starknet Targets Quantum-Resistant L1 by 2027
NFL shield logo, Kalshi smartphone screen, and a judge's gavel set before the Supreme Court building.
NFL Urges Supreme Court to Review Kalshi Sports Contracts
Physical Zcash (ZEC) coin standing in front of a red declining market chart.
Zcash (ZEC) Price Falls 13% as Open Interest Drops and ETF Outflows Rise
Physical Bitcoin and Ethereum coins standing against a red declining financial chart.
Bitcoin Falls 3.3%, Ethereum Drops 5.7% as Crypto Selloff Deepens

Find Us on Socials

You may also like

Laptop screen displaying 79Vault logo next to BNB coins spilling from a wallet and a phone showing a CertiK warning symbol

79thVault Hack: $12.5M Drained From 79AU Pool on BNB Chain

Computer monitor displaying the Microsoft logo next to a CBI Cyber Crime Investigation case file folder with CBI officers in the background

Microsoft Tech-Support Racket Robs US Citizens via Bitcoin ATMs

Three glass display blocks featuring logos for Tether, National Bank of Kazakhstan, and Alatau City Authority arranged side by side

Tether, Kazakhstan Central Bank Sign MoU to Explore Tenge Stablecoin and Tokenization

Smartphone displaying the Tether logo held in front of a green Tether screen.

Conduit Files Suit Against Tether Over Frozen $2.76 Million USDT

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram
© 2026 The Crypto Times | Protocols And Tokens Pvt Ltd.
DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information