← Radar

Incident case file

Sign in to watch

Ethereum Wallet Approval Phishing — Malicious Multicall Drain

Incident date July 8, 2026

1 views

ClosedEthereumApproval Phishing / Address PoisoningCluster: ETHPHISHING-APPROVAL-2026-07

Estimated loss

$800.0K

Victims identified

1
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: 0xc508a8C01bc3835BE67e0e5554B7D91A1bb70Da1 (received $639,543.82) and 0xf84c62572eEaFC90C0BCE3Fb6c85bCB573E68d93 (received $159,885.95).

Funds moved to: Successful multicall transaction 0x6e882fd802e96c51521869e9f433fec00aac5403d39356820d14e8a3f2e6ffb9 (17:52:35 UTC, July 8, 2026): 639,999.495132 USDT + 159,999.873783 USDT extracted to the two attacker addresses above, totaling $799,999.37. NOTE: an earlier attempted transaction (0x19ddd4f515f71da24859992496c9b1424bb26a6a9d02075f76b7eb258270f37c, 17:51:59 UTC) tried to extract an additional 200,000 USDT but FAILED on-chain ('invalid opcode: INVALID') — those funds never left the victim's walle
Victim: 0x8c949361b49320c48a51f4b1c6f9f83862530f89. Pre-attack funding: victim received exactly 1,000,000 USDT (two transfers of 999,000 + 1,000) from 0x33Be86929b2c6914f81260386d3CABc399c63066 on June 30, 2026, eight days before the attack. Address poisoning detected: two addresses tagged 'Fake_Phishing' by Etherscan (0xF84CD2B29E8326cD0f33DffAfe876d38ACE68d93 and 0xf84e291A05c5E8724be54C4a8292EdA763E68D93) sent dust transactions (0.0001 USDT) to the victim's wallet, using prefixes/suffixes vis

Timeline: June 30, 2026: victim's wallet funded with exactly $1,000,000 USDT. July 8, 2026, 17:51:47 UTC: legitimate MetaMask gas station swap (unrelated to the attack). 17:51:59 UTC: attacker's script attempts to extract 200,000 USDT via a malicious multicall — transaction FAILS on-chain ('invalid opcode: INVALID'), funds remain with the victim. 17:52:23 UTC: victim receives a worthless fake ERC-20 token (200,000 units, $0 value) from 0xF88183A6897c5C19E6B67BdFFa38d00f128a7d93 — likely bait or a poisoning attempt. 17:52:35 UTC: attacker's recalculated malicious multicall succeeds, draining 639,999.495132 USDT and 159,999.873783 USDT (total $799,999.37) to two separate addresses in a single transaction, exploiting a previously granted unlimited USDT approval. 18:19:11 UTC: a dust transaction from an Etherscan-tagged 'Fake_Phishing' address confirms the address-poisoning pattern around the victim's wallet. July 9, 2026: ScamSniffer publishes the public alert.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)