It takes just a single click of “Approve” to wipe out nearly an entire wallet. A crypto user lost 999,999 USDT - nearly $1 million - after signing a single malicious approval request on the Ethereum network. In an instant, the attacker secured the permissions needed to sweep the victim’s wallet.
According to blockchain security platform Scam Sniffer, the attacker initially attempted to withdraw a flat $1 million via a multicall transaction, but failed because the wallet balance was slightly below that amount. Seconds later, they adjusted the script and successfully swept the exact remaining balance. “The script recalculated and withdrew the exact balance,” Scam Sniffer revealed - illustrating the cold efficiency of automated phishing operations.
The Silently Deadly ‘Token Approval’ Scam
Security researchers identify token approval phishing as one of the most common social engineering attacks in crypto. The reason is simple yet deceptive: victims unwittingly grant unlimited spending allowances while believing they are merely approving a routine, harmless transaction. Once that permission is granted, attackers can siphon funds at any time without requiring additional signatures.
The scale is staggering. According to security firm CertiK, phishing scams caused $723 million in losses across 248 incidents throughout 2025. The pattern remains largely uniform - victims are tricked into signing malicious token approvals, allowing assets to be drained seamlessly.
Not an Isolated Incident - and Threats Continue to Evolve
This incident follows a series of heavy losses in rapid succession. Earlier this month, a crypto holder lost approximately $1.65 million after connecting to a fake exchange and signing a malicious smart contract that granted “unlimited access” to automated sweepers. Shortly before that, a trader lost nearly $2 million not through phishing, but because a decentralized exchange routed an Ether swap through a low-liquidity pool - opening a single-block arbitrage exploit that drained most of the transaction’s value.
The Final Line of Defense Lies at Your Fingertips
The common thread across all these cases is the moment of signature. Scam Sniffer reminds users to scrutinize every signature request, avoid rushing into approvals, and utilize scam detection tools before confirming transactions. In a world without an “undo” button and no banks to freeze fraudulent transfers, a split-second of diligence before pressing “Approve” can be the difference between a secure wallet and savings lost forever.
Reported by crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




