⚠️ Someone lost $1.06M worth of $aUSDf and $USDF after signing phishing signatures


7 recorded changes
Want your article here?
Promote with Leviathan News

7 recorded changes
Want your article here?
Promote with Leviathan NewsBlockchain security account Scam Sniffer reported that a user lost approximately $1.06 million in crypto assets after unknowingly signing malicious phishing signatures promoted as “Authorize ETH/USDT snapshots.” The stolen funds were primarily aUSDf and USDF tokens on Ethereum, with on-chain data showing the victim’s wallet drained soon after interacting with the phishing contract. Scam Sniffer’s post includes the relevant transaction hashes and labels the incident as a phishing‐signature exploit rather than a smart contract bug or protocol hack. According to the analysis, the victim was tricked into signing off-chain or permit-style signatures that granted the attacker broad spending or transfer approvals, a pattern consistent with recent wallet-drainer and “approve/permit” phishing campaigns targeting Ethereum users. This case underscores the continued effectiveness of social engineering in Web3, where users are lured by seemingly legitimate calls to claim rewards, snapshots, or airdrops and then approve harmful signatures in their wallets. It highlights the importance of scrutinizing any request to sign messages or approvals, especially those related to token allowances, and of using security tools or wallet warnings to detect high-risk spend approvals before confirming them.
AI-generated background, compiled from web sources — not editorial content.
Loading related coverage…
Loading comments…

falcon.finance ·

crypto.news ·

𝕏/@ag_dwf ·

𝕏/@GabeWeide ·

𝕏/@FalconStable ·

falcon.finance ·

crypto.news ·

𝕏/@ag_dwf ·

𝕏/@GabeWeide ·

𝕏/@FalconStable ·
October SQUID Drop (covering September) Discussion Thread
digest.leviathannews.xyz
Dream launches V2 options brokerage with institutional market maker liquidity on BTC, ETH, SOL and more
𝕏/@dreaming
Based Visa Card discloses security breach exposing KYC data of some cardholders, while funds and card credentials remain safe
𝕏/@BasedOneX
Texas has frozen new data centre permits after ERCOT's queue hit 474 GW, over five times record peak demand. Speculative projects, local concerns and grid limits are behind the pause.
𝕏/@rmcentush
ZachXBT infiltrated Chinese crime syndicate that laundered $1B+ for Lazarus Group
𝕏/@zachxbt
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?
Restoring your session before loading comments…