SlowMist Exposes Unauthorized Approvals Leading to Crypto Thefts

In a recent report, the SlowMist Security Team has uncovered a series of crypto thefts caused by authorization issues, shedding light on a critical problem stemming from past permissions. Victims unknowingly clicked on “Approve” authorization at some point in the past, leading to a cascade of thefts. The stolen funds were not a result of complex methods or vulnerabilities but were traced back to long-ago granted “Approve” authorizations, acting like delayed fuses.

Unauthorized Transfer Scheme Unveiled

Upon investigating the on-chain transactions, SlowMist identified a key factor: victims had authorized a contract address over two years ago. The timeline between the authorization transaction and the subsequent unauthorized transfer spanned 767 days.

FBS The Best Forex Broker

Slowmist Crypto Thefts report

The stolen funds were pilfered through a methodical process. The balance of the stolen address and the Allowance authorized to the malicious contract were checked. The malicious contract invoked the transferFrom function of USDT-BEP20, transferring the Token assets to the hacker’s profit address.

The hacker’s address successfully stole around $200,000, utilizing various platforms for transactions. Further analysis revealed the malicious contract’s association with the original project ‘King’. King’s connections with Kingfund Finance hint at a potential collaboration. Digging deeper into Kingfund Finance uncovered its history as a ‘RugPull’ project, absconding with substantial funds and shutting down its official channels.

Trending Now: Scammers Execute Rugpull Scams in Recent Token Launches

Security Alerts and Proactive Measures against Crypto Thefts

Using Dune analysis, SlowMist discovered another case where a user authorized the same malicious contract address in January 2022, leading to continuous fund theft. The creator of this malicious contract had transferred most funds to Tornado Cash.

Slowmist Dune analysis

SlowMist advises users to regularly check their authorization status using tools like RevokeCash, ScamSniffer, and Rabby. If unusual authorizations are detected, prompt revocation is recommended.

SlowMist, a leader in blockchain security, emphasizes a holistic approach to ensure the blockchain ecosystem remains innovative, secure, and reliable. Their comprehensive security solutions have gained the trust of leading projects worldwide.

Copyright © 2026. All Rights Reserved. FXDailyReport.Com
Risk Warning: Trading CFDs is a high risk activity and you may lose more than your initial deposit. You should never invest money that you cannot afford to lose. FXDailyReport.com will not accept any liability for loss or damage as a result of reliance on the information contained within this website including data, quotes, charts and buy/sell signals. Please be fully informed regarding the risks and costs associated with trading the financial markets.