News

$11M Lost in Permit Signature Scam: Security Experts Urge Caution with Off-Chain Transactions

  • A user lost $11 million in a phishing attack due to signing multiple fraudulent Permit signatures.
  • Permit signatures, enabled through EIP-2612, allow off-chain transaction authorization, posing significant security risks.
  • Security firms highlight the need for caution with Permit signatures and recommend using security extensions for protection.

In a recent incident, a user suffered a significant financial loss due to a phishing attack. The user lost $11 million worth of aEthMKR and Pendle USDe tokens after signing multiple Permit phishing signatures. This event shows the growing risks associated with digital asset security.The victim, who is a MakerDAO governance delegate, fell prey to the attack by unknowingly signing fraudulent Permit signatures.

Permit Signature Risks

The incident highlights the vulnerabilities associated with Permit signatures, a feature enabled through EIP-2612. This feature allows users to authorize transactions without prior on-chain approval, which can be exploited by malicious actors. The risk is heightened because the signature authorization happens off-chain, making it challenging to detect compromised signatures.

Analysis by Security Firms

Arkham Intelligence and blockchain security firm SlowMist have both analyzed the incident. According to SlowMist, Permit signatures pose significant risks as they can be easily exploited by bad actors. SlowMist noted that some wallets decode and display signature information to help users identify phishing attempts. However, there is often insufficient warning about the risks of Permit signature phishing.

Preventative Measures

Users are advised to exercise caution when interacting with smart contracts and signing off-chain signatures. Installing security extensions, such as those recommended by Scam Sniffer, can enhance protection against phishing attacks. Additionally, users should verify the legitimacy of websites and smart contracts before signing any Permit signatures.

Read CRYPTONEWSLAND on google news

This incident is a reminder of the importance of security in the digital asset space. As the use of smart contracts and digital tokens continues to grow, users must remain vigilant and take necessary precautions to protect their assets from phishing attacks and other forms of cyber threats.

Read also

Godfrey Mwirigi

Godfrey Mwirigi is an enthusiastic crypto writer with an interest in Bitcoin, blockchain, and technical analysis. With a focus on daily market analysis, his research helps traders and investors alike. His particular interest in digital wallets and blockchain aids his audience in their day-to-day endeavors.

Recent Posts

3 Top-performing Altcoins in September: DOT, POL, SOL

Explore #top-performing altcoins— #Polkadot, Polygon, and Solana. #DOT #POL #SOL

15 mins ago

XYO Poised for a Massive Breakout, Analyst Predicts a 1,053% Potential Rally to $0.06949

#XYO shows #strong momentum. Analyst #Javon Marks reveals the potential for a #massive breakout. #XYO…

1 hour ago

Rollblock’s $450B Market Potential: How It Measures Up Against VeChain (VET) and Theta Network (THETA)

This sector’s top altcoin, #Rollblock(RBLK), is projected to take a huge share of the $450…

1 hour ago

Qubetics’ Non-Custodial Wallet- Reshaping  Digital Finance

Discover how #Qubetics offers a non-custodial wallet and its debit card integration with Visa and…

2 hours ago

Sui Network Surges to $17 Billion in DEX Volume: A Strong Competitor to Solana

#Sui Network hits $17B in #DEX volume, ranking 2nd among #non-EVM chains. #SuiNetwork #DEX

2 hours ago

Key Resistance Level Breached: What’s Next for Bitcoin After $65K?

#Bitcoin crosses the $65K #psychological barrier. Can #BTC push toward the #next target of $74K.…

3 hours ago