Crypto User Loses $908K in Sophisticated Phishing Scam: Highlights Dormant Wallet Vulnerabilities
August 3, 2025
Security experts emphasize the importance of regularly revoking old wallet approvals, even for inactive wallets, to prevent unauthorized access.
Users are advised to regularly check wallet activity, verify URLs and transaction details, and remain cautious of unfamiliar platforms.
This incident serves as a critical reminder for the Web3 community to prioritize wallet hygiene and stay vigilant against evolving phishing tactics.
In July 2025 alone, bad actors stole over $142 million from the crypto space across 17 separate attacks, underscoring the ongoing risks in cryptocurrency security.
Best practices for avoiding similar attacks include disconnecting wallets after use, regularly checking and canceling token approvals, and conducting thorough research on dApps before use.
The scammer monitored the victim's wallet for nearly 16 months, waiting for a substantial deposit before executing the theft.
On August 2, 2025, the attacker drained the wallet in a single transaction, transferring $762,397 via MetaMask and $146,154 via Kraken.
The attack stemmed from a rogue ERC-20 approval transaction signed on April 30, 2024, which allowed the scammer ongoing access to the victim's funds.
The incident underscores the risks associated with dormant wallets that retain old permissions, making them vulnerable to exploitation.
A crypto user fell victim to a phishing scam, losing over $908,000 after a dormant Web3 wallet was hacked, highlighting the increasing sophistication of such attacks.
This method, known as Permit Phishing, exploited a feature of ERC-20 tokens that permitted token transfers without further user confirmation.
The article highlights a growing trend in sophisticated crypto scams, including advanced phishing techniques and impersonation.
Summary based on 4 sources
Get a daily email with more Crypto stories
Sources

Cointelegraph • Aug 3, 2025
Crypto victim loses $908K in sophisticated phishing attack
Live Bitcoin News • Aug 2, 2025
Dormant Web3 Wallet Drained of $908K in Rare Phishing Attack
Live Bitcoin News • Aug 3, 2025
Crypto Victim Loses $908K in Sneaky Phishing Heist
AMBCrypto • Aug 3, 2025
$908K USDC stolen, 458 days after approval: ‘Your wallet security matters!’