Phishing drainer exploited four wallets for $585K in 11 hours using increaseApproval signature after Aave withdrawal.
Security & Exploits ·
A phishing drainer compromised four wallets for a combined $585,000 in Ethereum-based assets over 11 hours. One victim, at address 0x5d908c88bE270889C0953E7dfF1C8E1D699cEeA3, lost 3 WBTC (approximately $221,000) after signing a malicious increaseApproval transaction shortly after withdrawing funds from Aave. All four accounts were targeted by the same drainer contract.
The attack exploited a window of opportunity following the Aave withdrawal. The victim signed the phishing increaseApproval signature, which enabled the attacker to drain the WBTC holdings. Security researchers documented the sequence of events, linking the Aave withdrawal directly to the approve and drain transactions that followed.
In response, security tools including RevokeCash, Tenderly, Web3 Antivirus, Delegate.xyz, and Rabby Wallet have been recommended as protective measures. What remains unclear is how the phishing vector was delivered to the victims and whether the drainer targets users conducting specific DeFi operations or operates opportunistically across broader wallet populations.