Non-custodial · read-only

Permit & Permit2 phishing

A Permit signature costs no gas and never shows up as a transaction, which is exactly what makes it the phishing world's favorite way to set up a drain. Here's how it works and how to defend against it.

Scan your wallet: free Watch 24/7 on Telegram

Public address only. No wallet connection. Nothing to sign.

What a Permit signature is

EIP-2612's Permit lets you authorize a spender's token allowance with an off-chain signature instead of sending an on-chain approve transaction, the spender submits your signature later to activate it. Permit2 is a shared allowance contract used across many dapps that does the same job at wider scale, covering tokens that don't natively support Permit.

Why it's the phishing sweet spot

Signing costs no gas and produces no on-chain transaction at the moment you sign, so it never lands in your wallet's activity history the way an approve() call would. It's a signTypedData request, which many wallets still show as a plain, unfamiliar-looking prompt, easy to click through without registering what's being granted.

How phishers harvest them

A fake claim, mint, or airdrop page asks you to 'verify' or 'claim' by signing what's actually a Permit or Permit2 authorization. Because nothing visibly happens on-chain until the attacker chooses to redeem it, a victim can sign today and only get drained days or weeks later, breaking the natural instinct to check 'did anything just happen?' right after signing.

Defenses that actually work

Read every signTypedData prompt for a Permit or Permit2 domain and spender before signing, the same way you'd read a transaction. Veriql's Guardian decodes these payloads and throws a warning on an unlimited-amount Permit2 signature to an unverified spender before you approve it. Because a signed permit can sit dormant, also scan your address afterward, an activated Permit2 allowance shows up exactly like a normal approval and can be revoked the same way.

FAQ

Does signing a Permit cost gas?

No: signing itself is free. Only the spender's later on-chain call to redeem the signature costs gas, and that's typically paid by whoever submits it, not necessarily you.

How do I know if I've already signed one?

Scan your address: once a Permit or Permit2 signature has been redeemed on-chain, it becomes a normal allowance in the token's storage and shows up in a scan exactly like any other approval, unlimited or not.

Related