Phishing drainer contract exploited 4 victims for $585K in 11 hours, including $221K in WBTC stolen via malicious increaseApproval signature.
Security & Exploits ·
A phishing drainer contract targeted four victims over an 11-hour window, extracting $585K in combined losses, according to a security alert. One victim lost 3 WBTC (approximately $221K) moments after withdrawing from Aave, having signed a malicious increaseApproval signature that granted unauthorized access to their assets.
The attack relied on a single drainer contract deployed against all four targets. The exploit mechanism centered on signature-based approval abuse—a technique that tricks users into signing transactions that appear benign but actually authorize token transfers to attacker-controlled addresses. The victim's withdrawal from Aave immediately preceded the loss, suggesting either tight timing exploitation or deceptive UX layering.
The attack underscores the ongoing risk of approval-based drainers in decentralized finance. What remains unclear is whether the four victims shared any common interaction point—such as visiting the same website or using the same dApp—or whether the attacker conducted broader phishing outreach. No details have surfaced regarding how the initial phishing signature request was delivered to the targets.