NewsMV
A trader lost $1 million after signing a phishing token approval, handing direct control of the wallet to an onchain scammer with a single click.
Approval phishing holds its rank as a primary attack vector in a market where onchain fraudsters collectively cleared more than $14 billion last year.
The approval phishing playbook The attack does not require a protocol exploit or a smart contract vulnerability.
A wallet holder encounters what appears to be a routine DeFi interaction, signs an approval transaction, and unknowingly authorizes a malicious contract to spend tokens on the wallet's behalf.
Keep reading