Blockchain security account Scam Sniffer reported that a user lost approximately $1.06 million in crypto assets after unknowingly signing malicious phishing signatures promoted as “Authorize ETH/USDT snapshots.” The stolen funds were primarily aUSDf and USDF tokens on Ethereum, with on-chain data showing the victim’s wallet drained soon after interacting with the phishing contract. Scam Sniffer’s post includes the relevant transaction hashes and labels the incident as a phishing‐signature exploit rather than a smart contract bug or protocol hack. According to the analysis, the victim was tricked into signing off-chain or permit-style signatures that granted the attacker broad spending or transfer approvals, a pattern consistent with recent wallet-drainer and “approve/permit” phishing campaigns targeting Ethereum users. This case underscores the continued effectiveness of social engineering in Web3, where users are lured by seemingly legitimate calls to claim rewards, snapshots, or airdrops and then approve harmful signatures in their wallets. It highlights the importance of scrutinizing any request to sign messages or approvals, especially those related to token allowances, and of using security tools or wallet warnings to detect high-risk spend approvals before confirming them.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on USDf

Comments