$908K USDC Stolen in Delayed Smart Contract Exploit
A crypto user lost $908,551 in USD Coin (USDC) after a malicious smart contract approval—signed 458 days earlier—was executed on August 2, 2025. The attack, tied to wallet address 0x67E5Ae and pink-drainer.eth, exploited an old ERC-20 token approval from April 2024, likely via phishing.
Blockchain analysts at Scam Sniffer noted the attacker waited over 15 months before draining funds, underscoring a rising trend of delayed exploits. "Regularly audit and revoke old approvals—wallet security is critical," the firm warned on X. The victim's wallet had minimal activity prior to the theft.