Contact
← All insights
Crypto Incidents

Permit2 phishing: Why a Dangerous Signature May Not Take Effect Immediately

A dangerous signature may be given today but used to drain tokens days or weeks later.

Updated 2026-10-064 min read

Imagine: a dangerous signature may be given today but used to drain tokens days or weeks later. On screen, everything may look familiar, so the dangerous moment is easy to miss.

The main thing to know right away: The key is not to panic and not to try to "fix" the situation with random transfers. First, stop the repeat risk, save the original data, and only then sort out what happened.

How the scheme works

Permit2 and similar mechanisms allow permissions to be granted via a message signature. This is dangerous because the user may not see the usual on-chain transaction at the moment of phishing: the attacker uses the signature later and only then initiates the drain.

In this situation, it is important to separate two things: the attack mechanism itself and what has already happened to the assets. A dangerous signature may be given today but used to drain tokens days or weeks later. After an incident, a technical review begins not with guesses, but with a specific operation and its continuation on the blockchain.

What to do if this has already happened

Record the site and time when the suspicious signature was given, even if the drain occurred much later. In an investigation, the interval between the compromising signature and the actual withdrawal matters.

  1. Stop repeating the action that led to the incident: do not sign new requests and do not send additional payments.
  2. Save the tx hash, full addresses, network, asset, amount, and time of the operation.
  3. Record the correspondence, domain, profile, app, or signature screen — everything that explains the context of the operation.
  4. If there is a risk that the wallet is compromised, move the remaining assets to a new safe wallet without using the exposed seed phrase.
  5. If the amount is significant, it makes sense to trace the further route of the funds and identify service points along the way.

What to save for the review

For this specific topic, it is especially useful to save: the text/parameters of the Permit/Permit2 signature, the spender, and the permission expiration, if available.

For an initial review, prepare the data in one message or file — this reduces the risk of losing an important detail:

  • tx hash / txid
  • full sender and recipient addresses
  • network, asset, amount, and time
  • screenshots and correspondence
  • domain, profile, or app, if they are related to the incident

What you should better not do

  • Do not share your seed phrase or private keys with "helpers" or a "recovery service."
  • Do not pay an unknown intermediary a "tax," "insurance," or "unlock fee."
  • Do not delete correspondence or transaction history before everything is saved.

Important: a transaction and an address are verifiable on-chain facts. The owner's identity, motive, and legal status should not be automatically inferred from a single graph.

When it makes sense to bring in a specialist

If the amount is significant, the route has already branched, or exchanges, swap services, bridges, and other services have appeared along it, a manual review helps separate available actions from useless ones. To start, public data is usually enough — private keys are not needed.

Frequently asked questions

Why did the drain happen several days after visiting the site?

A signature-permission can be used later. Therefore, during the review, you need to look not only at the wallet's latest session, but at suspicious signatures over a broader period.

Can a confirmed transaction be canceled?

As a rule, no. Further actions depend on the route of the funds and on whether services have appeared along it that can restrict the movement of assets.

Can you immediately identify the scammer by address?

No. The blockchain shows addresses and operations. Identity requires additional data: a service's KYC, public sources, case materials, or other confirmations.

In short

A dangerous signature may be given today but used to drain tokens days or weeks later. If this has already happened, first stop the repeat risk and save the original data. Then you can review the route and the real points for further action.

QuantoLog

Need to understand what happened and where the funds went?

Provide the tx hash, network, and a short description of the situation. A seed phrase and private keys are not needed for an initial assessment.

Submit data for assessment