A Malicious Approval Signed Through a Phishing Site
A client connected their wallet to what appeared to be a familiar exchange interface, reached through a sponsored search result, and signed a transaction that granted unlimited spending approval to an attacker controlled contract.
The Situation
A client connected their wallet to what appeared to be a familiar exchange interface, reached through a sponsored search result, and signed a transaction that granted unlimited spending approval to an attacker controlled contract.
The Challenge
Because the client had signed the transaction themselves, the initial evidence looked identical to a voluntary transfer, requiring careful analysis to establish the deceptive context.
The Investigation
We reviewed the approval transaction, the phishing site's domain registration history, and the subsequent draining transactions executed by the attacker's contract.
Findings
The attacker's contract had drained similarly structured approvals from over a dozen other wallets within the same week, indicating an active phishing campaign.
Outcome
Findings were used to support revoking the client's remaining approvals, and the drained funds were traced to a deposit address at a regulated exchange. We pursued the matter through the exchange's legal request process, which resulted in part of the balance being recovered on the client's behalf.
Lessons
Unlimited token approvals are a common attack surface. Reviewing and revoking old approvals periodically is one of the simplest preventative habits available.
Wallet Approval
Signed via a phishing site impersonating an exchange.
Facing a similar situation?
Every case is scoped on its own facts. Tell us what happened.
