Search
Results for “Permit phishing vs Permit signature”
Permit phishing
Permit phishing is a scam in which a fake site asks you to sign an off-chain message that grants a spending allowance over your tokens. Signing costs no gas and sends no transaction, but whoever holds the signature can submit it and then move your tokens.
What it means for you. Because nothing happens on-chain when you sign, your balance looks unchanged until the attacker acts, which can be much later. Before signing any typed message, read the spender address, the value and the deadline your wallet shows. A Permit request from a site you reached through an ad, a direct message or a surprise token is a warning sign.
Sources: EIP-2612: Permit extension for EIP-20 signed approvals, Dissecting Payload-based Transaction Phishing on Ethereum (arXiv) · checked 4 October 2026
Permit signature
A permit signature is a signed message, not a transaction, that gives a spender permission to move your tokens. ERC-2612 defines it for ERC-20 tokens. It does the same job as an on-chain approval but costs the signer no gas, because anyone can submit the signature to the token contract.
What it means for you. Signing a permit costs nothing and sends nothing, so it can feel harmless, yet it lets the named spender take tokens up to the stated amount until the deadline. That is why scam sites ask for permits. The spender address, amount and deadline in the signing request are the parts to read before approving.
Source: ERC-2612: Permit extension for EIP-20 signed approvals · checked 4 October 2026