USDC Permit Signature Phishing Hack

TOTAL LOST $1.8M
Medium Phishing Attacks Ethereum

What happened

On March 16, 2026, an Ethereum victim wallet lost 1,766,308.43 USDC, approximately $1.77 million, after signing a malicious EIP-2612 permit.

Technical Root Cause

The loss resulted from social engineering around EIP-2612 permit authorization rather than a flaw in USDC's core contract: the victim's valid off-chain signature authorized the attacker as spender.

Case & protocol details

Classification Other
Protocol Type Exploit/Phishing

Attack Timeline

The attacker collected an off-chain permit signature through a phishing surface, submitted it with a purpose-built drainer contract, granted itself USDC allowance, and executed three transferFrom calls to controlled wallets.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.