USDT Approval Phishing Drain: Desk Triage and Revoke Playbook
Unlimited USDT approve/Permit2 phishing empties balances via transferFrom while isBlackListed stays false. Desk triage, revoke steps, and lawful freeze-request paths.

An approval-phishing drain and an issuer freeze look similar in a support ticket—“my USDT is gone / won’t move”—and they are not the same failure mode. Unlimited approve / Permit2 phishing empties the balance via transferFrom while isBlackListed usually stays false. Issuer blacklist keeps a visible balance and reverts outbound transfers. Triage the plane first, revoke remaining allowances, then open lawful exchange/issuer/LE tickets for funds that still sit on-chain.
Educational only. Not legal advice. Not a recovery service. Not instructions to evade freezes, mix funds, or hide proceeds. Fake “revoke experts” and Telegram drainers are hostile; use official wallet revoke paths and official issuer/LE channels only.

Check a wallet before you act
Run a FreezeRadar scan for issuer-freeze signals, sanctions exposure, counterparty risk, and freezeable asset sensitivity before moving funds.
Direct answer
USDT approval phishing is a spender authorization attack. The victim signs (or Permit2-signs) permission for a malicious or compromised contract to move USDT. The attacker later calls transferFrom. Wallet balance drops. Explorer shows attacker outflows. On-chain blacklist reads for the victim address are typically clean. Disconnecting the dapp in MetaMask does not revoke the allowance: you need an on-chain revoke (set allowance to zero), which MetaMask documents as distinct from disconnecting. Recovery of already-moved tokens is lawful tracing plus venue/issuer holds where funds still land (not a “secret revoke that reverses the drain”).
Failure-mode table (desk first screen)
| Signal | Approval / Permit2 drain | Issuer USDT blacklist | Seed / key compromise | Exchange account hold |
|---|---|---|---|---|
| On-chain USDT balance | Often near-zero after drain | Still visible | Often emptied by attacker sends | May be credited then locked in venue ledger |
isBlackListed / getBlackListStatus | Usually false | true | Usually false | Irrelevant to personal address |
| Explorer pattern | Victim approve (or Permit2) → spender transferFrom / multicall drain | AddedBlackList event; outbound reverts | Native + token sends signed by victim key | Deposit credited; in-app “under review” |
| First fix | Revoke remaining allowances; rotate if SRP risk | Issuer / lawful review lane | New phrase + migrate survivors | Venue security ticket |
| Internal FR tell-apart | This post | Exchange hold vs issuer | Seed phishing vs freeze | Same hold-vs-blacklist post |
Mislabeling a drain as “Tether froze me” burns the hour that matters for exchange holds on the outbound cluster. Mislabeling a blacklist as “I need to revoke MetaMask” does the reverse.
What an unlimited USDT approval actually grants
MetaMask’s primary explainer (What are token approvals?) is the desk vocabulary:
- Connecting a wallet shares the address. It does not move tokens.
- Calling
approve(spender, amount)on the token contract (here, official USDT) authorizes that spender to pull up toamountviatransferFrom. - An unlimited approval uses the max
uint256(2^256 − 1). The spender can pull the entire present and future USDT balance until you revoke. - Revocation is itself an on-chain transaction that sets the allowance back to zero. It costs gas. It does not reverse completed
transferFromdrains.
USDT on Ethereum (0xdAC17F958D2ee523a2206206994597C13D831ec7) is a standard ERC-20 allowance surface for this attack. TRC-20 and other deployments have their own approve/allowance semantics. Always name the chain and contract in the ticket. Do not treat a Tron allowance story as an Ethereum revoke, or the reverse.
Permit2 (fold, don’t invent a second article)
Uniswap’s Permit2 shifts part of the risk to off-chain typed signatures with deadlines/nonces after a one-time on-chain approve to the Permit2 contract. MetaMask’s signature-phishing and token-approval docs warn that a “sign this message” prompt can authorize large token moves without looking like a classic approve confirmation. Desk rule: if the customer says “I only signed a message,” still pull Permit2 / allowance state before closing the ticket as “not a drain.”
Desk triage playbook (first 30–60 minutes)
Worked composite (not a case file): L1 reports “MetaMask USDT drained after a Uniswap-looking site.” Balance was 48k USDT ERC-20; now ~0. Customer insists “Tether blacklisted me.”
- Name chain + address + token contract. Confirm official USDT, not a fee-on-transfer clone.
- Read blacklist on that contract (
isBlackListed/getBlackListStatus). Operator landing: read USDT blacklist yourself. If true, stop and open the issuer lane—not revoke theater. - Pull allowance and tx trail. Look for
Approvalevents to unknown spenders, thenTransferwithfrom = victiminitiated by the spender. Note Permit2 signatures if present. - Classify plane using the table above. Title the ticket
APPROVAL_DRAINvsISSUER_BLACKLISTvsSEED_COMPROMISEvsVENUE_HOLD. - Contain. Instruct: do not import the seed into “recovery” apps; do not send remaining gas tokens to DM addresses; revoke hostile allowances from a clean device path when safe; if SRP may be exposed, treat as seed compromise and migrate to a new phrase (seed vs freeze).
- Freeze-request path only for funds still reachable. Destination clusters on CEX deposit addresses → venue security tickets with hashes. Stablecoin still sitting in attacker EOAs on freezable contracts → packet via contact issuer / exchange / LE and the evidence-packet deepener when live. Glossary anchors: phishing address, stolen funds.
Revoke steps desks can safely point to (no third-party “magic”)
Primary MetaMask Help Center path: How to revoke smart contract allowances/token approvals. Core facts to repeat to L1:
- Disconnect ≠ revoke.
- Revoke costs gas; do it on the correct network.
- Use MetaMask Portfolio allowance tools where supported, or the chain explorer’s token-approval checker, or established revoke dashboards the victim verifies themselves. Never use a link from a Telegram “helper.”
- Revoke stops future pulls. It does not claw back completed drains.
Unlimited approvals that are still live after a partial drain are unfinished incidents. Close the allowance before you close the chat.
What to put in the victim / desk packet
Before five overlapping support forms:
- Victim address(es) per chain; official USDT contract ID.
- Approximate first malicious signature / approve time (timezone labeled).
- Approval tx hash(es) and spender address(es).
- Drain tx hash(es) and destination addresses / CEX deposit tags if known.
- Screenshot of the phishing URL (do not re-click).
- Statement of channels used (wallet vendor support, exchange security, local LE / IC3 where applicable).
- Explicit note: seed phrase was not shared with any “agent.”
Then parallelize: exchange holds on landing addresses; LE intake with the same hash list; issuer plane only when freezeable balances remain and criteria fit—not as a substitute for revoke hygiene.
Unlimited approve vs “I disconnected the site”
Support queues still treat three different clicks as one:
- Disconnect in the wallet’s connected-sites list — stops the origin from seeing the account in-session. Allowances remain.
- Revoke — on-chain
approve(spender, 0)(or equivalent UI) sotransferFromfails going forward. - Custom spending cap at approval time — MetaMask lets users edit the requested amount before confirm; limited caps bound loss if the contract later turns malicious, but they do not help after an unlimited approve already drained.
Desk script for L1: “If USDT left after you clicked Approve or signed a Permit2-looking message, disconnecting is hygiene, not remediation. We need the spender address, the approval hash, and a revoke on the same chain—then we chase destinations.”
Composite revoke order (survivors still in the wallet)
- Move any non-approved assets you still control to a destination you trust only if the key is not believed exposed. If SRP may have been typed into the phish, skip to new-phrase migration first.
- Fund gas on the correct network from a clean source if needed—watch for sweeper bots on fully compromised keys (MetaMask’s hacked-account guidance).
- Revoke the known hostile spender(s) and any other unlimited USDT spenders you do not recognize.
- Re-read allowances. Screenshot zeroed lines for the packet.
- Only then open venue/issuer tickets for the outbound cluster, with revoke evidence attached so responders do not confuse ongoing allowance risk with a finished drain.
Honest limits
An allowance read proves what spenders could pull; it does not prove intent, and it does not certify that a phishing site is “the” unique cause. FreezeRadar indexes freeze/blacklist evidence and related wallet risk; it does not reverse transferFrom, does not operate a revoke relay, and does not guarantee exchange or issuer action. Permit2 and legacy approve phishing share an ops outcome (balance gone, blacklist false) but different signature UX—desks must inspect both. Novel drainers may evade wallet simulation until labeled. This page does not teach evasion, mixing, or “cleaning” drained proceeds.
Related FreezeRadar surfaces
- Seed phishing drain vs issuer freeze
- Exchange hold vs issuer USDT blacklist
- Contact issuer, exchange, law enforcement
- Glossary: phishing address · stolen funds
- Scan · Methodology
Key takeaway
Approval phishing drains USDT through spender permissions (approve / Permit2 → transferFrom), usually with a clean isBlackListed read. Triage that plane apart from issuer freeze and seed theft, revoke remaining allowances on official paths, and escalate reachable outflows through lawful exchange/issuer/LE packets—not Telegram “unfreeze/revoke experts.” Screen related addresses on /scan before the next receive or CEX deposit.
Cover: Unsplash photo-1563986768609-322da13575f3 — digital / network security stand-in for approval-phishing signing risk. Unsplash License — https://unsplash.com/photos/1563986768609-322da13575f3. Light resize long edge 720px + optimize for FreezeRadar. Not an endorsement of any wallet vendor or revoke dashboard.
Sources (5)
What are token approvals?
MetaMask
Primary explainer: approve vs connect, unlimited approvals, revoke limits.
How to revoke smart contract allowances/token approvals
MetaMask Help Center
Primary: disconnect ≠ revoke; gas; Portfolio/explorer revoke paths.
Signature phishing
MetaMask Help Center
Primary: Permit2 / off-chain signature phishing patterns.
Tether USD (USDT) verified contract — Read Contract
Etherscan
Official Ethereum USDT; allowance and blacklist reads.
Revoke.cash
Revoke.cash
Secondary tooling note: disconnect does not revoke; revoke is preventive.
Related reading
Continue exploring FreezeRadar knowledge content.
On this page
Get posts like this by email
A daily or weekly digest of FreezeRadar freeze activity.
By FreezeRadar Team
Wallet risk intelligence and stablecoin compliance analysis from FreezeRadar.


