Main Report
I stored USDT in Coinbase Wallet and connected it to what was presented as an equity or mining pool. The pool later removed the funds from my wallet, and I lost about $45,000. I had not understood that accepting the voucher could give a third-party contract authority over the tokens.
I contacted Coinbase and was told that clicking the voucher or smart contract had introduced the problem into the wallet and that the transaction could not simply be reversed. From my perspective, I had expected a much clearer warning before an external DApp received the ability to move such a large balance.
The source did not identify the pool's domain, so I am not assigning the incident to a guessed website. I am also not saying that the wallet provider received the stolen funds. The direct allegation is that the connected pool used the approval to drain my USDT.
My warning is to treat token approvals as seriously as transfers. Before connecting a wallet, inspect the spender, allowance, and contract. A seed phrase can remain private while a malicious approval still permits tokens to be moved.
Discussion
No comments yet. Start the discussion below.