On July 8, a major phishing attack occurred on the Ethereum network: an unknown user lost 999,999 USDT after signing a malicious token approval transaction. This incident reveals systemic vulnerabilities in the processes of interacting with DeFi protocols.
The attackers initially attempted to withdraw exactly 1 million USDT via a multicall function but then adjusted the amount, debiting the exact balance through several transfers. Ultimately, the theft was carried out in three stages: 639,999 USDT, 159,999 USDT, and 200,000 USDT. The recipient address on Etherscan has already been flagged as phishing, confirming the targeted nature of the attack.
This case is not isolated. Just a few days earlier, on July 4, another wallet owner lost $1.65 million after connecting to a fake exchange and signing a malicious contract. As researcher Ryan Coleman noted, this approval granted attackers unlimited access, allowing an automated fund-draining system to empty the wallet.
Scale of the Threat and Precautionary Measures
In the first six months of 2026, the crypto industry lost $1.32 billion due to security incidents, according to CertiK. Meanwhile, phishing remains the largest source of damage in the first quarter. This underscores the need to strengthen protection measures at the user level.
I recommend that all market participants double-check all signature requests before approval, avoid hasty transactions, and use specialized tools such as scam detection extensions. Additionally, it is critically important to regularly revoke unused token approvals through services like Revoke.cash—this can prevent fund loss even in the event of wallet compromise.
My analysis: Phishing remains the most effective and cheapest tool for attackers, as it exploits the human factor rather than technical vulnerabilities. Until users implement strict verification protocols for every transaction, such losses will continue. The market needs more intuitive and automated security systems that provide real-time warnings about suspicious actions.