User lost $1.77M USDC on Ethereum after signing a phishing permit signature enabling gasless approval exploit.
Security & Exploits ·
A user lost approximately $1.77M in USDC on Ethereum after signing a phishing permit signature that enabled a gasless approval exploit. The compromised wallet address is 0x051bb76ff78366de530e293fdb1158c2079ab664, according to a security alert posted on X.
Permit signatures enable gasless token approvals by allowing a contract to spend tokens on behalf of a user without requiring a separate transaction. In this case, a phishing attack tricked the victim into signing a malicious permit that granted unauthorized access to their USDC holdings. This attack vector exploits the ERC-2612 permit standard, which prioritizes user experience but can create security risks if users sign permits without fully understanding the implications.
The attack underscores ongoing vulnerabilities in how users interact with smart contracts. The security community has recommended several defensive measures including transaction simulation tools, token approval revocation platforms, and security education resources to help users recognize and avoid similar exploits. It remains unclear what method the attacker used to distribute the phishing prompt or whether other accounts were targeted in the same campaign.