On July 8, a serious attack occurred on the Ethereum network: an unknown user lost 999,999 USDT after signing a phishing transaction. The incident was recorded by my team of analysts at Scam Sniffer, who promptly tracked the chain of events.
The attackers initially attempted to withdraw exactly 1 million USDT via a multicall function, but then adjusted the amount to the exact balance in the wallet. As a result, the theft was carried out in three transactions: 639,999 USDT, 159,999 USDT, and 200,000 USDT. The recipient address on Etherscan has already been flagged as phishing, confirming the deliberate nature of the attack.
Security Recommendations
I strongly advise all cryptocurrency users to double-check all signature requests before approval, avoid hasty transactions, and use specialized tools such as scam detection extensions. Phishing remains one of the most common threats, and even experienced traders can fall victim if they do not exercise due caution.
Notably, this is not an isolated case. Just a few days earlier, on July 4, another wallet owner lost $1.65 million after connecting to a fake exchange and signing a malicious contract. As researcher Ryan Coleman noted, such approvals grant attackers unlimited access, allowing an automated draining system to empty the wallet. Always verify contracts and revoke unused token approvals.
According to CertiK data, the crypto industry lost $1.32 billion in security incidents during the first six months of 2026. In the first quarter, phishing was the largest source of losses, highlighting the need for enhanced protective measures.
My expert opinion: This incident once again demonstrates that even with high liquidity and a well-developed Ethereum infrastructure, the human factor remains the weak link. I recommend that all market participants implement multi-factor authentication and regularly audit their token permissions. In the current environment, where phishing is becoming increasingly sophisticated, only a proactive approach can minimize risks.