A phishing token approval on Ethereum.
On July 9, Scam Sniffer flagged an Ethereum wallet emptied of 999,999 USDT. The owner signed one message on a phishing site, giving up no password or seed phrase.
The message was a token approval. Spending a token such as USDT takes two steps: You approve a contract to move up to a set amount, then it transfers within that limit. The allowance can be set to unlimited. The phishing page disguised a malicious approval as a harmless click, and the signature gave the attacker's contract standing permission over the balance.
After that the attacker needed no key. A script tried to pull a round million, missed by about $631, then recalculated and swept the exact remainder 36 seconds later.
A token approval stands until the owner revokes it. A wallet can sit in self-custody and still be emptied by a permission signed once and forgotten.
Source: https://crypto.news/ethereum-phishing-scam-drains-nearly-1-million-from-crypto-wallet/
Related
SciPHR