# Ethereum user loses $999,999 in USDT phishing token approval

**Published:** 2026-07-15T23:44:56.470Z  
**Topic:** Crypto Scam  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/682c085a-adb2-4214-ad7e-67bad108394b

Ethereum phishing token approval drains $999,999 USDT on July 8, 2026; see how the multicall hack worked and what to monitor next.

A trader on Ethereum lost exactly 999,999 USDT after signing a malicious token‑approval request on July 8, 2026, highlighting the growing risk of approval‑phishing attacks that let attackers drain wallets without ever touching private keys [3].

| At a glance | |
|---|---|
| Loss amount | 999,999 USDT |
| Date | 8 July 2026 |
| Attack method | Phishing token‑approval via Multicall |
| Catalyst | Single fraudulent signature granting unlimited allowance |

## How the attack unfolded  
Scam Sniffer’s on‑chain analysis shows the attacker first tried to pull a round $1 million using a multicall function, but the transaction failed for insufficient funds. Seconds later an automated script recalculated the exact balance and split the remaining 999,999 USDT into three transfers of 639,999, 159,999 and 200,000 USDT [2]. The victim’s wallet never exposed its private key; the approval gave the malicious contract unlimited access, allowing an “automated sweeper” to empty the account [5]. The recipient address is flagged as phishing on Etherscan [3].

## Context and broader trends  
Approval‑phishing is a leading vector in DeFi scams. Chainalysis reported that on‑chain scams collected at least $14 billion in 2025, with investment scams dominant and approval phishing a common execution method [1]. In the first half of 2026, security firms recorded $366 million in phishing losses, up from $723 million across 248 incidents in 2025 [5]. A 200 % jump in phishing losses this year has been linked to high‑value wallet targeting, underscoring the scale of the threat [4]. MetaMask introduced live address‑poisoning detection in June to help users avoid similar tricks, but the approval‑phishing method bypasses standard wallet alerts because the private keys remain untouched [1].

## What to watch
- **Signature‑request alerts** – monitor any new wallet alerts or extensions that flag unusual token‑approval requests.  
- **Large‑value wallet activity** – watch for spikes in multicall transactions targeting wallets with unlimited allowances.  
- **MetaMask updates** – track further security feature releases that could mitigate approval‑phishing, such as enhanced permission dashboards.  

The incident shows that a single fraudulent signature can empty a high‑value wallet in seconds, narrowing the window for users to revoke approvals. As phishing attacks increasingly automate the extraction process, on‑chain monitoring of approval patterns will be crucial to detect and deter future breaches.

## Sources
1. Cointelegraph — [Trader loses $1M after signing phishing token approval](https://cointelegraph.com/news/trader-loses-1m-after-signing-phishing-token-approval)
2. Theunum — [Ethereum user lost 999 999 USDT after signing the phishing...](https://theunum.io/en/news/read/ethereum-user-lost-999-999-usdt-after-signing-the-phishing-transaction)
3. Forklog — [Ethereum User Loses Nearly $1 Million USDT in Phishing Scam](https://forklog.com/en/ethereum-user-loses-nearly-1-million-usdt-in-phishing-scam/)
4. Cryptorank — [Crypto User Loses $999,999 in USDT to One Phishing Signature...](https://cryptorank.io/news/feed/eba4c-ethereum-phishing-attack-usdt-stolen)
5. Gncrypto — [Trader Loses $999,999 After Approving Phishing Token on Ethereum](https://www.gncrypto.news/news/trader-loses-999999-after-approving-phishing-token-on-ethereum/)

---
Cite as: TrendWatcher, "Ethereum user loses $999,999 in USDT phishing token approval", https://www.trendwatcher.in/article/682c085a-adb2-4214-ad7e-67bad108394b
