Search
Results for “Permit phishing vs Token approval”
Permit phishing
Permit phishing is a scam in which a fake site asks you to sign an off-chain message that grants a spending allowance over your tokens. Signing costs no gas and sends no transaction, but whoever holds the signature can submit it and then move your tokens.
What it means for you. Because nothing happens on-chain when you sign, your balance looks unchanged until the attacker acts, which can be much later. Before signing any typed message, read the spender address, the value and the deadline your wallet shows. A Permit request from a site you reached through an ad, a direct message or a surprise token is a warning sign.
Sources: EIP-2612: Permit extension for EIP-20 signed approvals, Dissecting Payload-based Transaction Phishing on Ethereum (arXiv) · checked 4 October 2026
Token approval
A token approval is a permission you sign that lets another address, usually an app's smart contract, move a set amount of a token from your wallet. Under the ERC-20 standard the approved spender can withdraw repeatedly up to that amount, without asking you again.
What it means for you. Many apps request an unlimited approval. If that contract is malicious or later compromised, it can take the approved tokens from your wallet with no recovery, even after you stop using the app. The approval stays active until you revoke it.
Sources: EIP-20: Token Standard, ethereum.org: How to revoke smart contract access, EIP-721: Non-Fungible Token Standard · checked 4 October 2026