USDC Permit Signature Phishing Hack
What happened
On March 16, 2026, an Ethereum victim wallet lost 1,766,308.43 USDC, approximately $1.77 million, after signing a malicious EIP-2612 permit.
The loss resulted from social engineering around EIP-2612 permit authorization rather than a flaw in USDC's core contract: the victim's valid off-chain signature authorized the attacker as spender.
Case & protocol details
Attack Timeline
The attacker collected an off-chain permit signature through a phishing surface, submitted it with a purpose-built drainer contract, granted itself USDC allowance, and executed three transferFrom calls to controlled wallets.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.