On July 8, 2026, another high-profile security incident occurred on the Ethereum network: an unknown user lost 999,999 USDT after signing a phishing transaction. This case once again drew attention to the problem of fraudulent schemes targeting inexperienced or careless holders of crypto assets.
How the Theft Was Carried Out
The attackers initially attempted to withdraw exactly 1 million USDT via a multicall function but then adjusted their actions. Ultimately, the funds were stolen in three consecutive transactions: 639,999 USDT, 159,999 USDT, and 200,000 USDT. The recipient address on Etherscan has already been flagged as phishing, confirming the nature of the attack.
A Similar Case a Few Days Earlier
This is not an isolated incident. Just four days prior, on July 4, another wallet owner lost $1.65 million after connecting to a fake exchange and signing a malicious contract. As researcher Ryan Coleman noted, the confirmation granted attackers unlimited access, allowing an automated fund-draining system to empty the wallet. This highlights a systemic vulnerability: users often trust unverified interfaces.
Scale of the Problem in 2026
According to data from CertiK analysts, the crypto industry lost $1.32 billion due to security incidents in the first six months of 2026. Notably, in the first quarter, phishing was the largest source of losses. These figures indicate that, despite advances in security technology, the human factor remains the primary vulnerability.
My Expert Opinion: Phishing in cryptocurrencies is not just a coincidence but a result of insufficient user awareness. Every transaction signature should be checked at least twice, and ideally, hardware wallets and specialized extensions for detecting fraudulent schemes should be used. The market is moving toward greater security, but for now, victims are paying for their haste with millions of dollars.