rising3월 19일· 2 sources

The Authorization Abuse Epidemic: Why Permit2 Signature Phishing Is Now Crypto's Deadliest Attack Vector

권한 남용의 확산: Permit2 서명 피싱이 암호화폐 최대 공격 벡터가 된 이유

Why it matters

Authorization abuse via Permit2 signature phishing has overtaken smart contract exploits as crypto's primary attack vector in early 2026, with a single phishing attack accounting for $282 million (75%) of January losses. The article explains how Permit2's off-chain approval mechanism—originally designed for better UX and lower gas fees—creates an invisible attack surface that social engineering exploits, and discusses defenses for builders and users.

2
Sources
+0
24h
Growth
182d
Active
authorization abusebiometric authenticationcrypto securityencryptionerc-20mobile banking securitypermit2phishingsocial engineering

Sources

Related Issues