Users targeted by 'ETH-BASE' fake liquidity-mining scam retain unlimited USDC approvals to a drainer contract; security researchers urge immediate revocation.
Security & Exploits ·
Victims of an "ETH-BASE" fake liquidity-mining scheme retain unlimited USDC token approvals to a known drainer contract at address 0x60CE723c20b6b7fa17F3C71D01ae8bD11D9aB8f4, exposing their funds to ongoing theft risk. Security researchers have issued warnings urging affected users to revoke these approvals immediately using revocation tools, and have filed a report with the FBI's Internet Crime Complaint Center.
The scam operated by convincing users to grant approval permissions to a smart contract under the guise of a liquidity-mining opportunity. Once approved, the contract gained the ability to transfer USDC holdings without further user action. A detailed investigation documents the scheme's mechanics and identifies the drainer address; users can revoke approvals through services like Revoke.cash, which provides approval inspection and revocation across multiple blockchain networks.
What remains unclear is the total number of affected wallets, the volume of funds at risk, and whether the drainer contract has already initiated transfers from victim accounts. The investigation report provides the specific technical details, but the scope of losses and ongoing activity has not been disclosed.