A Malicious Approval Signed Through a Phishing Site
A client connected their wallet to what appeared to be a familiar exchange interface, reached through a sponsored search result, and signed a transaction granting unlimited spending approval to an attacker controlled contract.
The Situation
A client connected their wallet to what appeared to be a familiar exchange interface, reached through a sponsored search result, and signed a transaction granting unlimited spending approval to an attacker controlled contract.
The Challenge
Because the client had signed the transaction themselves, the initial evidence looked identical to a voluntary transfer, requiring careful analysis to establish the deceptive context.
The Investigation
We reviewed the approval transaction, the phishing site's domain registration history, and the draining transactions executed by the attacker's contract.
Findings
The attacker's contract had drained similarly structured approvals from over a dozen other wallets within the same week, consistent with an active phishing campaign.
Outcome
Findings supported revoking the client's remaining token approvals, and the drained funds were traced to a deposit address at a regulated exchange. We pursued the matter through the exchange's legal request process, which resulted in part of the balance being recovered on the client's behalf.
Lessons
Unlimited token approvals are a common attack surface. Periodically reviewing and revoking old approvals is one of the simplest preventative habits available.
Wallet Approval
Signed via a phishing site impersonating an exchange.
Facing a similar situation?
Every case is scoped on its own facts. Tell us what happened.
