📈 Get daily crypto insights that make you smarter about your money

The 1.5 Billion Silent Killer: Why Malicious Approvals Are Now More Dangerous Than Exchange Hacks

A new wave of AI-powered “ice phishing” attacks is sweeping through the crypto market this week, using deepfake technology and social media bots to trick investors into signing away their entire portfolios. New research confirms that these “malicious approvals” have become the most financially devastating threat to crypto holders in 2026, often bypassing the most advanced security hardware by targeting the user’s own permission settings rather than the blockchain’s code.

By Elena Kowalski | June 5, 2026

While most investors spend their time worrying about Bitcoin (BTC) price swings—which currently sees the leading asset trading at $61,884—or whether Ethereum (ETH) can hold the $1,653 level, a far more surgical threat is draining wallets in silence. Unlike a traditional hack where an exchange or a protocol is breached, these attacks target you directly. They don’t steal your password; they trick you into handing over the “keys to the house” through a process known as a malicious approval.

The Exploit Mechanics: Tricking the Vending Machine

To understand how this works, think of your crypto wallet like a vending machine. Normally, you are the only one with the key to take money out. However, decentralized finance (DeFi) requires you to give “approvals” to certain apps so they can move your tokens for you—like giving a subscription service permission to charge your credit card every month.

A malicious approval (often called “ice phishing”) happens when a hacker creates a fake website that looks exactly like a popular trading platform or a “claim” page for a free token. When you click “Connect Wallet” and sign a transaction, you aren’t actually performing a trade. Instead, you are signing a digital contract that gives the hacker “unlimited approval” to spend your tokens.

According to research from Global Ledger published in February 2026, this tactic is now the single biggest drain on investor funds. In 2025 alone, malicious approvals accounted for $1.51 billion in losses, according to Global Ledger’s research. To put that in perspective, while traditional smart contract exploits (flaws in a project’s code) made up 64% of all security incidents, they only resulted in $861.54 million in losses. Malicious approvals were responsible for only 11.76% of incidents but caused nearly twice the financial damage—though this figure was significantly inflated by the massive ByBit exploit alone.

Affected Systems: The Rise of AI Deepfakes

The threat has evolved significantly in the first half of 2026. Security researchers are currently tracking a massive surge in AI-driven social engineering. Attackers are now using deepfake videos of prominent crypto founders and “agentic” AI bots on social media to promote fake airdrops or security “upgrades.”

  • Social Engineering — 76% of stolen funds are moved before the victim even realizes a public disclosure of the exploit has happened.
  • Phishing Clones — Hackers are using high-quality clones of Uniswap and Safe (formerly Gnosis Safe) to hide “control transfer” logic behind buttons labeled “Verify” or “Unlock Wallet.”
  • The 2-Second Drain — In the most efficient cases documented this year, hackers moved funds from a victim’s wallet in just two seconds after the malicious approval was signed.

Even assets like Solana (SOL), currently priced at $65.51, and Binance Coin (BNB) at $589.59, have seen their respective ecosystems targeted by these sophisticated drainers. The speed of these attacks means that by the time you see a warning on Twitter, your assets are likely already sitting in a mixer or a hacker-controlled wallet.

The Mitigation Strategy: Revoking Your Permissions

Protecting yourself from this “silent killer” requires a shift in how you view wallet security. A hardware wallet is a great first step, but remember: if you use a hardware wallet to sign a malicious approval, the hardware wallet will faithfully execute that command. It’s like using a high-security lock to let a burglar into your house because they were wearing a delivery uniform.

The primary defense is Approval Management. You should treat every signature request as a high-risk event. Use tools like Revoke.cash or the built-in “approval dashboards” in modern wallets to see which apps have permission to spend your XRP ($1.12) or Cardano (ADA, $0.1615). If you aren’t actively using a platform, revoke its permission immediately.

Lessons Learned: Behavior Over Code

The data from the past year proves that hackers have realized it is much easier to hack a human than it is to hack a blockchain. While the industry has spent billions auditing smart contracts to prevent the next multi-million dollar protocol exploit, the “retail drain” continues because of simple phishing.

The hard truth for investors is that on-chain transactions are irreversible. Once that permission is granted, the “math” of the blockchain doesn’t care if you were tricked; it only sees a valid signature. This is why education and “transaction simulation” tools—which show you exactly what will happen to your balance before you click sign—are becoming the most important tools in an investor’s kit.

User Action Required: How to Stay Safe Today

If you have been active in the market recently, follow these three steps to secure your holdings:

  • Audit Your Approvals — Visit a reputable revoking tool and clear out any old or “unlimited” permissions.
  • Never Sign Under Pressure — Most malicious sites use “limited time” countdowns to make you panic. Take 30 seconds to verify the URL.
  • Use a “Burner” Wallet — If you want to claim an airdrop or try a new DeFi app, use a fresh wallet with only a small amount of funds, rather than your main “cold storage” account.

Whether you are holding Dogecoin (DOGE) at $0.0832 or Polkadot (DOT) at $0.9839, your greatest security asset isn’t your password—it’s your skepticism.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

21 thoughts on “The 1.5 Billion Silent Killer: Why Malicious Approvals Are Now More Dangerous Than Exchange Hacks”

  1. honeybadger99

    BTC at $61,884 and ETH at $1,653 while $1.5B quietly drains through approval scams. price goes up, security awareness stays flat

  2. coldwallet_andy

    1.5 billion from malicious approvals and people still blindly signing transactions on random dapps. revoke.cash should be bookmarked by everyone at this point

    1. revoke.cash is essential but most people dont know to check their existing approvals until after they get drained. prevention is barely discussed

      1. revoke.cash is great but it should not be needed in the first place. wallets need to show exactly what an approval grants before you sign

        1. Anika S. wallets showing what an approval grants before signing would kill 80% of these scams. the fact that Rabby does this and MetaMask still does not is telling

        2. approval_nag_

          Anika S. wallets showing what an approval grants before signing should be table stakes. the fact that metamask still doesnt clearly show unlimited vs limited approvals in 2026 is embarrassing

  3. the deepfake angle is what scares me. got a video call last month from someone who looked exactly like a dev i know asking me to sign a multisig tx. nearly fell for it

    1. cold_storage_k

      the deepfake video call angle is genuinely new. hardware wallets protect your keys but they dont protect you from signing a tx you think is legit

    2. ^ that is terrifying. the ai deepfake + social engineering combo is next level. hardware wallets dont help when the user is the attack vector

    3. Dmitry Volkov

      got a similar call from someone posing as a Polygon dev. the voice matching is getting scary good with these tools

    4. Tomasz N. the deepfake video call angle is what makes 2026 different. five years ago social engineering meant a fake email. now they clone the face and voice of someone you know

    5. Tomasz N. the deepfake video call thing is genuinely scary. voice cloning was bad enough but real-time video impersonation of people you know changes the threat model completely

      1. Olufemi A. got the same treatment. caller looked like my business partner and asked me to sign a contract update. nearly worked until i noticed the lip sync was off

    6. Tomasz N. the deepfake video call story is terrifying. I got a similar attempt last week, face and voice matched someone from a project I follow. only caught it because they asked me to sign something unusual

  4. approve_zero_

    wallets letting users sign unlimited ERC20 approvals by default is the original sin of DeFi UX. infinite allowance should require explicit opt-in not a default

    1. approve_zero_ infinite allowance as default is the original sin. one checkbox in settings could fix this and wallet teams still have not shipped it

    2. approve_zero_ infinite allowance should literally be opt-in with a warning. wallet teams ignoring this for years while 1.5B drains is negligence

  5. allowance_nun_

    1.5 billion from approvals and still no wallet defaults to exact-amount-only. the UX teams at metamask and rabby should be held accountable

  6. cold_storage_only_

    the scary part is the approvals look completely normal in your wallet activity. unless you actively check revoke.cash weekly you would never know someone drained you

  7. 1.5 billion from approval scams vs how much from exchange hacks this year? the threat model flipped completely and most people still think exchange risk is the bigger problem

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$63,426.00-2.6%ETH$1,882.76-4.2%SOL$73.26-3.9%BNB$565.25-1.5%XRP$1.06-4.6%ADA$0.1570-4.8%DOGE$0.0702-3.3%DOT$0.7601-6.0%AVAX$6.43-3.6%LINK$8.32-5.5%UNI$3.69-5.3%ATOM$1.30-6.2%LTC$46.32-1.3%ARB$0.0777-5.0%NEAR$1.68-8.9%FIL$0.6946-5.8%SUI$0.6808-4.9%BTC$63,426.00-2.6%ETH$1,882.76-4.2%SOL$73.26-3.9%BNB$565.25-1.5%XRP$1.06-4.6%ADA$0.1570-4.8%DOGE$0.0702-3.3%DOT$0.7601-6.0%AVAX$6.43-3.6%LINK$8.32-5.5%UNI$3.69-5.3%ATOM$1.30-6.2%LTC$46.32-1.3%ARB$0.0777-5.0%NEAR$1.68-8.9%FIL$0.6946-5.8%SUI$0.6808-4.9%
Scroll to Top