A crypto user who fell victim to a phishing attack six months ago has lost a total of 77,405 USDC after failing to revoke a malicious Permit signature. The initial incident occurred 183 days ago, costing the user approximately 1,625 USDC. The same unrevoked authorization led to a second theft of about 75,780 USDC.
Permit Signature Exploit
The attacker used a malicious Permit transaction to drain the user's wallet in the first attack. Permit signatures are a feature in Ethereum-based tokens that allow users to approve token spending without sending an on-chain transaction, but they can be exploited if signed on phishing sites. Despite the initial loss, the user did not revoke the permission, leaving the door open for a second attack.
Second Theft and Lessons
Months later, the attacker returned to steal the remaining USDC. The incident highlights the importance of regularly reviewing and revoking token approvals, especially after suspected phishing attempts. Tools like Etherscan's token approval checker or Revoke.cash can help users manage permissions. The case serves as a reminder that a single fraudulent signature can lead to repeated losses if not properly canceled.
Broader Security Context
Phishing attacks remain a persistent threat in the crypto space, often targeting users through fake websites or social engineering. In this case, the attacker exploited the user's failure to act after the first breach. As decentralized finance grows, users must prioritize security practices, including using hardware wallets and verifying transaction details before signing.