Another high-profile incident in the world of cryptocurrencies: an unknown investor lost $999,999 in USDT stablecoins. The reason is a classic, but no less devastating, phishing attack on the Ethereum network. The victim, without realizing it, signed a fraudulent token approval request, which gave the attackers direct access to the funds.

According to blockchain data, the hacker acted swiftly. After obtaining the signature, the stolen USDT were split into three parts and withdrawn in two consecutive Ethereum blocks — 25489460 and 25489463. The entire operation took just a few minutes. The attacker did not need the victim's wallet private keys. It was enough to fraudulently obtain approval for a transaction that granted unlimited access to the token.

This case is a vivid illustration of how modern phishing works. An unlimited token limit was set in the victim's wallet, allowing the hacker to withdraw funds without additional confirmations. Moreover, using the Multicall mechanism, the attacker combined several operations into one transaction, minimizing the time available to revoke the approval. Standard notifications from many wallets simply did not have time to react.

Attack Scheme: From Uniswap to HyperSwap

Such methods are becoming increasingly sophisticated. Fraudsters actively use fake interfaces of popular platforms like Uniswap and HyperSwap. In the case of fake Uniswap, victims lost hundreds of thousands of dollars by signing dubious contracts. An attack through a fake HyperSwap airdrop led to an instant balance wipeout after a single signature. According to analysts, phishing losses have increased by 200% this year, as attackers specifically target large balances.

How to Protect Yourself: Expert Advice

The only reliable way to protect yourself is your own vigilance. Before signing any request, you must carefully check the contract address and the level of permissions requested. Any "default" actions should be excluded. Regularly revoke unused or unlimited permissions for contracts. This is a simple but extremely effective preventive measure.

Expert Opinion: The current situation resembles an arms race. Wallet developers are implementing increasingly complex security mechanisms, but they cannot replace conscious user behavior. The time between one careless click and the complete loss of funds is shrinking to seconds. The only path to security is forming a habit of thoroughly checking every transaction, even if the interface seems familiar. Don't trust — verify.