How USDT Is Stolen: The 6 Most Common Attack Methods
USDT is the most-stolen asset in crypto — not because it's harder to secure, but because attackers know exactly what it's worth the moment they take it. Here's how they do it.
Of all the assets stolen in crypto theft cases handled by blockchain forensics firms, USDT — Tether's dollar-pegged stablecoin — consistently tops the list. Not Bitcoin. Not Ethereum. USDT.
The reason is simple: USDT is liquid the moment it lands. Unlike Bitcoin or Ethereum, which require the attacker to sell through an exchange before realising value, USDT is already denominated in dollars. It can be moved to an exchange, a P2P buyer, or directly to a cash-out point without any conversion risk. For attackers, it's as close to digital cash as crypto gets.
Understanding how USDT is stolen isn't just academic. Every method described below has a corresponding countermeasure — and if your USDT has already been taken, knowing which method was used determines where the recovery effort should focus.
Why USDT is the most-targeted stablecoin
USDT runs on multiple blockchains simultaneously — Ethereum (ERC-20), Tron (TRC-20), BNB Smart Chain (BEP-20), Solana, and others. This multi-chain presence is exactly what makes it so attractive to attackers. Funds can be moved from one network to another in minutes, making tracing significantly harder than with single-chain assets.
The Tron network in particular has become the dominant vehicle for USDT theft. TRC-20 transactions cost fractions of a cent and confirm in seconds — which means an attacker can route stolen USDT through dozens of intermediate wallets within minutes of the initial theft, creating a long chain that takes professional forensics tools to follow.
With that context established, here are the six methods used to steal USDT, from the most common to the most sophisticated.
Method 1: Phishing websites and fake exchange login pages
This is the most common attack vector by a significant margin. An attacker creates a near-perfect replica of a legitimate exchange or DeFi protocol — Binance, Bybit, MetaMask, Uniswap — and drives traffic to it through search ads, Telegram spam, or compromised social media accounts.
The URL typically differs from the real site by one character: "bínance.com" with an accented i, "metamask-io.com" with a hyphen, or a completely different domain that looks plausible in a link preview. When you enter your credentials or connect your wallet and sign a transaction on the fake site, the attacker immediately gains either your login details (for exchange accounts) or permission to transfer your USDT (for wallet-based attacks).
What makes phishing particularly effective for USDT theft is the speed of execution. Modern phishing kits are fully automated. The moment your credentials are captured, bots log in and initiate withdrawals before any 2FA confirmation prompts can be noticed. The time from credential capture to empty balance is often under 60 seconds.
The tell: Always verify the exact URL in your browser's address bar before entering any credentials or signing any transaction. Not just the domain name — the full URL including subdomain and TLD.
Method 2: Malicious token approval and drainer smart contracts
This is the DeFi-specific attack that has cost users hundreds of millions of dollars across the Ethereum ecosystem and increasingly on other networks as well.
When you interact with a DeFi protocol, you typically sign an "approval" transaction granting the protocol's smart contract permission to move your tokens on your behalf. This is a legitimate mechanism. The attack exploits it by creating a fake DeFi site — a fake yield farm, a fake DEX aggregator, a fake NFT marketplace — that prompts you to sign an unlimited approval granting the attacker's contract permission to move all your USDT.
The approval itself doesn't drain your wallet. It just grants permission. The actual drain happens later, sometimes hours or days after the approval was signed, when the attacker calls a function on their contract to sweep all approved tokens in a single transaction.
This timing gap is what makes drainer attacks so dangerous. You sign a transaction, nothing seems to happen, you assume it was harmless — and then a day later your USDT is gone. If you've recently signed any transaction on an unfamiliar site, check your active approvals immediately using revoke.cash.
Free download
First 30 Minutes After Crypto Theft
PDF checklist: 6 steps to take immediately. Every hour of delay lowers your recovery chances.
Download free checklist →Method 3: Fake P2P trades and payment reversals
Peer-to-peer trading platforms — where buyers and sellers transact directly, with the exchange acting only as escrow — have become a significant vector for USDT theft, particularly on Binance P2P and Bybit P2P.
The most common variant: you're selling USDT for fiat. A buyer sends the payment and you release the USDT from escrow. Then the buyer files a dispute with their bank or payment service, claiming the transfer was unauthorised or fraudulent. The bank reverses the fiat payment — and you're left with neither your USDT nor the money.
A second variant targets buyers: a seller accepts your payment for USDT, then files a false complaint claiming they never received it, and the platform (if not properly investigating) may side with the seller. The USDT never transfers, the fiat is gone.
A third, more sophisticated variant involves colluding with a money mule: the payment you receive was itself stolen from a third party. When that third party reports the theft, your account gets frozen — along with your own legitimately-held USDT — while the investigation proceeds.
Mitigation: On P2P platforms, only trade with highly-rated counterparties, always confirm fiat receipt in your actual bank account (not just a screenshot), and never release USDT escrow based on a payment confirmation that you haven't independently verified.
Method 4: SIM swap attacks leading to exchange account takeover
Your phone number is a single point of failure for most people's crypto security. If an attacker can convince your mobile carrier to transfer your phone number to a SIM card they control — a social engineering attack known as SIM swapping — they immediately inherit control of every SMS-based 2FA linked to that number.
The attack sequence is methodical. The attacker researches their target (usually via social media or data breaches to find the phone number and carrier), contacts the carrier posing as the victim claiming a lost or damaged phone, and requests a SIM transfer. Once successful, they initiate a password reset on your exchange account using the SMS 2FA they now control, change the password, and begin withdrawals.
For USDT holders on exchanges, SIM swaps are particularly dangerous because most exchanges allow withdrawal of USDT within minutes of gaining access, and fiat off-ramps for USDT are numerous. By the time you realise your phone has lost signal — the first sign of a SIM swap — the attacker may already have initiated withdrawals.
Mitigation: Switch from SMS 2FA to an authenticator app (Google Authenticator, Authy) on every exchange. Also place a SIM lock or PIN on your mobile account — most carriers offer this as a security feature that prevents number transfers without the PIN.
Method 5: Malware and clipboard hijacking
When you copy a wallet address to paste it into a transfer form, there is a brief moment when that address exists in your clipboard. Clipboard hijacking malware monitors the clipboard in real time, detects when a string matching a crypto wallet address format is copied, and replaces it with the attacker's address — all before you paste.
The substitution is seamless. You copy the correct address, glance at what you've pasted, and it looks right — because wallet addresses are long, random-looking strings that humans cannot meaningfully verify by eye. The transfer goes to the attacker's wallet.
A closely related attack uses keyloggers to capture exchange passwords and 2FA codes as they're typed, then replays them to log in and withdraw USDT from an exchange account.
Both malware variants typically enter systems through pirated software, malicious browser extensions, or email attachments. Crypto users who download cracked software or trading bots from unverified sources are at particularly high risk.
Mitigation: Always verify the first four and last four characters of any wallet address after pasting. Better practice: verify the entire address. Use a hardware wallet that displays the receiving address on the physical device screen, which cannot be spoofed by clipboard malware.
Free · no registration
Report the scam — we'll tell you exactly where to file
Fill in a short form and get a personalised filing guide: FBI IC3, FTC, Interpol or your exchange. Free.
Report a scam →Method 6: Social engineering and pig butchering scams
Pig butchering — a long-con investment fraud named after the practice of fattening a pig before slaughter — is the method that accounts for the largest individual losses per victim. These are not impulsive smash-and-grab attacks. They are weeks- or months-long relationship manipulation campaigns.
A target receives a message from an attractive stranger on WhatsApp, Telegram, Instagram, or a dating app. The relationship develops gradually — friendly conversation, often romantic overtones, built over days or weeks. Eventually the "friend" mentions they've been making excellent returns on a crypto investment platform, and offers to show the target how it works.
The platform is entirely fake, but it looks legitimate — complete with fake trading charts, fake account balances, and fake customer support. Small initial deposits show large "profits," which the victim can withdraw to confirm the platform is real. Then larger deposits are encouraged. When the victim tries to withdraw a significant amount, obstacles appear: taxes owed, fees required, account verification pending. Every demand for more money is designed to keep the victim paying rather than accepting the loss.
USDT is almost always the requested deposit currency — because it's instant, borderless, and genuinely difficult to reverse. By the time the victim realises the platform is fraudulent, their USDT is long gone through chains of TRC-20 wallets.
What makes USDT recovery different from BTC or ETH
USDT has one recovery mechanism that BTC and ETH do not: Tether Limited can freeze it.
As the issuer of USDT, Tether Limited maintains administrative access to the token smart contract on Ethereum and Tron. They have the ability to add any wallet address to a blacklist, making the USDT at that address permanently non-transferable. The frozen tokens cannot be moved, swapped, or spent.
Tether has used this power hundreds of times — primarily in response to law enforcement requests and documented exchange hacks. In documented cases, Tether has frozen USDT for exchanges hit by hacks, law enforcement agencies investigating fraud, and victims of large-scale theft who acted quickly enough.
The word "quickly" is doing real work in that sentence. Tether will not freeze funds that have already moved to another address — they can only freeze funds at the address where they currently sit. And stolen USDT moves fast. On TRC-20, funds can pass through five or six intermediate wallets within 15 minutes of the initial theft.
This is why the recovery window for USDT theft is measured in hours, not days. Every exchange that receives stolen USDT can also freeze it upon receiving a credible theft report — but only if the funds arrive before the freeze request does.
The first 2–4 hours after USDT theft are the entire window where freezing is realistically possible. After that, you're working with tracing and legal channels — still valuable, but much harder.
The Tether blacklist: how it works and when Tether acts
Tether's blacklist is a publicly verifiable function in their smart contract. Any blocked address is readable on-chain — you can verify which addresses have been blacklisted by querying the contract directly or using blockchain explorers that index this data.
In practice, Tether's intervention threshold for individual theft cases is high. They prioritise cases involving law enforcement agencies, large amounts, and documented evidence of fraudulent origin. This means getting a freeze from Tether directly — as a private individual — typically requires going through formal legal channels: a police report, ideally with Interpol involvement, and a formal letter to Tether's legal team.
The more accessible route for smaller cases is through centralized exchanges. If stolen USDT lands on Binance, Bybit, OKX, or any KYC-compliant exchange, that exchange has the ability to freeze the receiving address independently, without involving Tether. And exchanges respond faster than Tether does — especially when presented with a transaction hash and a clear explanation of the theft within hours of the incident.
USDT stolen? The first hours are critical.
Describe the situation — we'll start tracing immediately and contact the relevant exchanges
What to do if your USDT was stolen — right now
The sequence matters as much as the speed. Do these steps in order, simultaneously where possible:
- Document everything immediately. Find the transaction hash of the outgoing transfer — on Etherscan for ERC-20, Tronscan for TRC-20. Screenshot it. Note the receiving address, the amount, and the exact timestamp.
- Contact every exchange the funds may have reached. Paste the transaction hash into a block explorer and follow where the funds went. If the destination address belongs to an exchange (many are labelled), contact that exchange's security or compliance team directly via their official channel and provide the transaction evidence. Request an emergency freeze.
- Secure your remaining accounts. Change passwords on every exchange and wallet-linked email. Enable authenticator-based 2FA if you haven't already. Revoke all token approvals from any wallet involved in the theft.
- File a police report. Even if it feels futile, a police report creates an official record of the theft that is required for exchange freeze requests, Tether intervention, and any eventual legal proceedings. Some jurisdictions now have dedicated cybercrime units that actively pursue crypto theft cases.
- Contact a blockchain forensics firm. If the funds moved through multiple addresses or into mixers, professional tracing tools are necessary to follow the trail. The earlier a forensics investigation starts, the more of the chain remains intact before funds are fully laundered.
If you're already past the first few hours, don't assume recovery is impossible. Even when freezing isn't an option, professional blockchain analysis can map the complete movement of funds, identify destination points, link the attack to known threat actors, and prepare evidence for legal action that has resulted in fund recovery months after the initial theft.
For a complete step-by-step protocol covering the first 30 minutes after any crypto theft, read our guide: Crypto Stolen from Wallet: What to Do Right Now.
Frequently Asked Questions
Can stolen USDT be recovered?
How does USDT get stolen through phishing?
Can Tether (USDT issuer) freeze stolen funds?
What network is USDT most often stolen on — Ethereum or Tron?
What should I do if my USDT was stolen?
Get a free recovery assessment
Send your TX hash, address, or a description of the situation — within 15 minutes you'll get an honest answer: is recovery realistic in your case, and what it would take.