This isn’t an ordinary phishing attempt. Instead, Permit authorization has stretched a “sign once and lose twice” time dimension to 183 days.
In the case disclosed by GoPlus, the attacker had already obtained the user’s malicious Permit authorization 183 days earlier. The first transfer of about $1,625 looks more like a test to verify that the authorization is still valid; the real loss came in the second transfer, when roughly 75,780 USDC was directly transferred away.
The core asset isn’t the private key—it’s the dormant list of authorizations.
What’s most worth watching out for with this kind of attack is this: it doesn’t wait for a technical vulnerability. It waits for you to forget. Unlike private key leakage, Permit authorization doesn’t trigger immediate alerts. It can quietly lie there for six months until one day it’s awakened again.
For traders, this won’t affect the USDC price, but it will continue to increase the on-chain weighting of security tools, authorization management, and risk-control services at the entry points.
So here’s a very practical question: when did you last check your wallet for any non-revoked authorizations?
#Permit #USDC #钓鱼攻击 #钱包安全 #GoPlus