One signature, losing 167,000 LINK. The most dangerous on-chain situations are often not caused by private key leaks, but by you signing a malicious authorization yourself.
On October 4, according to Scam Sniffer monitoring, a trader lost LINK worth $167,342 after signing a malicious phishing Permit2 authorization on Ethereum. Even more concerning, this authorization was signed as far back as August 18, 2025, and was only recently used by the attacker.
Many people think that if they didn’t enter their private key or make a transfer, they won’t face any risk. But once a Permit2 authorization is maliciously used, the attacker may later directly transfer the tokens in your wallet.
In simple terms, you think you’re only clicking to sign once—but in reality, you might be granting someone permission to move your assets.
Especially withirdrops, NFTs, DeFi interactions, and phishing sites, users are often tricked into signing authorizations such as Permit and Permit2. Don’t just check whether the transaction amount is 0—also verify the authorization target, the approved amount, the validity period, and the signature contents.
If you previously granted authorization to an unknown or suspicious contract, it’s recommended that you promptly review and revoke any unnecessary permissions. And don’t put all large assets in a single hot wallet. Try to separate your interacting wallet from your storage wallet.
On-chain assets can be transferred freely, but it doesn’t mean authorizations can be signed casually. One mistake can allow an attacker to steal tokens weeks or even months later.
Do you regularly check and revoke wallet authorizations?
On October 4, according to Scam Sniffer monitoring, a trader lost LINK worth $167,342 after signing a malicious phishing Permit2 authorization on Ethereum. Even more concerning, this authorization was signed as far back as August 18, 2025, and was only recently used by the attacker.
Many people think that if they didn’t enter their private key or make a transfer, they won’t face any risk. But once a Permit2 authorization is maliciously used, the attacker may later directly transfer the tokens in your wallet.
In simple terms, you think you’re only clicking to sign once—but in reality, you might be granting someone permission to move your assets.
Especially withirdrops, NFTs, DeFi interactions, and phishing sites, users are often tricked into signing authorizations such as Permit and Permit2. Don’t just check whether the transaction amount is 0—also verify the authorization target, the approved amount, the validity period, and the signature contents.
If you previously granted authorization to an unknown or suspicious contract, it’s recommended that you promptly review and revoke any unnecessary permissions. And don’t put all large assets in a single hot wallet. Try to separate your interacting wallet from your storage wallet.
On-chain assets can be transferred freely, but it doesn’t mean authorizations can be signed casually. One mistake can allow an attacker to steal tokens weeks or even months later.
Do you regularly check and revoke wallet authorizations?