Tools Crypto Exploit Tracker exploit-0062
Exploit record
USDC Permit Signature Phish
- Loss
- $2M
- Attack vector
- Phishing
- Chain
- Ethereum
- Sector
- Wallet
What happened
On March 16, 2026, a victim lost $1.76M in USDC after signing a malicious Permit approval that handed spending rights to an attacker-controlled contract.
No fancy contract math here. The victim was tricked into signing what looked like a routine approval flow, but the Permit granted the attacker's contract the power to transfer the victim's USDC. The funds were drained immediately, swapped into ETH, and split across several wallets. Another reminder that one bad signature can be as fatal as a leaked seed phrase.
On-chain references
- Exploit txetherscan.io/tx/0xfd7417af8433e3d9bcbed3f965307c800a24eb4e98…
- Victim walletetherscan.io/address/0x051bb76ff78366de530e293fdb1158c2079ab…
- Malicious contract
0x9F68523efdc91ADbE53c3776Aa927f41aB4FE17E
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
