Incident case file
Sign in to watchEthereum Wallet Approval Phishing — Malicious Multicall Drain
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0xc508a8C01bc3835BE67e0e5554B7D91A1bb70Da1 (received $639,543.82) and 0xf84c62572eEaFC90C0BCE3Fb6c85bCB573E68d93 (received $159,885.95).
Timeline: June 30, 2026: victim's wallet funded with exactly $1,000,000 USDT. July 8, 2026, 17:51:47 UTC: legitimate MetaMask gas station swap (unrelated to the attack). 17:51:59 UTC: attacker's script attempts to extract 200,000 USDT via a malicious multicall — transaction FAILS on-chain ('invalid opcode: INVALID'), funds remain with the victim. 17:52:23 UTC: victim receives a worthless fake ERC-20 token (200,000 units, $0 value) from 0xF88183A6897c5C19E6B67BdFFa38d00f128a7d93 — likely bait or a poisoning attempt. 17:52:35 UTC: attacker's recalculated malicious multicall succeeds, draining 639,999.495132 USDT and 159,999.873783 USDT (total $799,999.37) to two separate addresses in a single transaction, exploiting a previously granted unlimited USDT approval. 18:19:11 UTC: a dust transaction from an Etherscan-tagged 'Fake_Phishing' address confirms the address-poisoning pattern around the victim's wallet. July 9, 2026: ScamSniffer publishes the public alert.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)