Security researchers alert victims of 'ETH-BASE' fake liquidity-mining scam with unlimited USDT approvals to known drainer address; recommend immediate revocation via revoke.cash.
Security & Exploits ·
Victims of the "ETH-BASE" fake liquidity-mining scheme have been alerted to unlimited USDT token approvals granted to a known drainer address (0xfa13960c7D15295f1e005B2DB67e8cB475c2e4a3), exposing their funds to theft at any time. Security researchers identified the scam and issued onchain warnings recommending immediate revocation through tools like revoke.cash, with the incident reported to the FBI's Internet Crime Complaint Center.
Token approvals represent a critical vulnerability in how users interact with decentralized applications. When users approve a contract to spend tokens on their behalf—typically during initial interactions with platforms—they can unknowingly grant unlimited access to malicious addresses. Unlike hardware wallets or other security measures, approvals bypass key security protections because attackers need only the approval itself to transfer funds, not access to the user's private keys.
The scope of victims and the full mechanics of how the ETH-BASE scheme directed users toward the drainer address remain unclear from available reports. A detailed investigation has been published, though the extent of funds at risk and whether revocation will fully restore security for affected wallets is not specified in the alerts issued.