The beginning of the story is not a transfer notification that suddenly appeared in the middle of the night, but a signature that has long been forgotten. About 922 days ago, this user signed a Permit authorization for SYN tokens when interacting with a certain contract—on the surface, it seemed to be a “no-confirmation” permission for convenient DeFi operations, yet in reality, it turned out to be a delayed malicious check. From that moment on, the attacker held a wallet key that could unlock funds at any time; he chose to wait patiently. At some point afterward, this dormant malicious authorization, which had been sleeping for nearly two years, was awakened for the first time. The attacker invoked the permission and transferred approximately $97,000 worth of SYN from the user's address; cruelly, after this loss, the authorization remained intact on the chain, neither revoked nor tightened. Therefore, the same Permit was utilized a second time, allowing the attacker to withdraw approximately $122,000 worth of SYN from the same user's wallet, resulting in a total loss of about $219,000. According to GoPlus monitoring, this “double theft” incident caused by long-unrevoked malicious authorization triggered alarms around September 1, 2026, revealing a cruel fact: a seemingly inconsequential oversight can leave a self-destruct button on the chain that can be pressed repeatedly.
How a Signature from 922 Days Ago Buried a Bomb
For this user, everything began with a signature 922 days ago. At that time, he signed a Permit authorization transaction for SYN tokens on-chain, which appeared to be just another step in daily interaction: granting “permissions” to a contract so that confirmations wouldn’t be needed each time. The problem was that this authorization itself was malicious, and from the moment it was signed, it quietly hung on the chain, never revoked for a full 922 days. For the user, this was just a forgotten interaction; for the lurking attacker, it was a “blank check” that could be reused at any time.
Permit authorization is very common in DeFi; it allows third-party contracts to transfer specified tokens on behalf of the user without requiring individual confirmations each time, intended to reduce interaction friction and improve the experience. However, once the signature lands in the hands of a malicious contract, the long-lasting convenience transforms into a risk: as long as the authorization is not revoked and there is still SYN in the wallet, the attacker can repeatedly invoke this old signature within the authorization's effective period, like this time, transferring assets from the same address in two separate times, and the user only realizes the loss when it occurs, that what they pressed 922 days ago was actually a time bomb.
How 97,000 and 122,000 Were Stolen Twice
The first attack occurred after the old authorization had lain dormant for a long time. The attacker did not initiate any new interaction requests to the user, nor did he display any new pop-up window for confirmation, but directly invoked the malicious Permit authorization signed 922 days ago, transferring about $97,000 worth of SYN tokens in one go. To the on-chain contract, this was merely a “normal” token transfer call, as the authorization had already been given, and the permissions were compliant; execution even did not require the user to be online.
The real fatal issue arose after the first theft, as this authorization still hung on the chain, unrevoked. When more SYN accumulated in the wallet, the attacker used the same malicious authorization again at a second point in time, transferring approximately $122,000 worth of SYN. The cumulative loss amounted to about $219,000, and these two transfers did not involve any new signatures; rather, they repeatedly consumed the old authorization that already existed, causing the same vulnerability to be triggered multiple times and turning a single mistake into two significant financial losses.
Why Permit Authorization Became Phishers' Treasure Map
Mechanically, Permit authorization separates the steps of “granting permission” and “using permission”: users only need to sign an offline message in their wallets, effectively giving a certain contract a “blank check” that can move their tokens. Later on, when the contract is called on-chain, the user does not need to confirm again and does not need to pay gas fees again. In contrast, a normal authorization often requires users to actively initiate an on-chain transaction, providing a clear mental and cost reminder for “I am granting permissions.” Because Permit eliminates this step of on-chain confirmation, the entire risk chain quietly shifts from “visible transactions” to “invisible signatures.”
This design is intended to enhance the DeFi interaction experience, but in reality, users frequently bombarded with pop-ups requiring signatures can easily form a habit of “unconscious signing”: as long as operations can continue, they might reflexively confirm without discerning whether this is a regular login, a message signature, or a Permit authorization that would allow assets to be released. In this case, the malicious Permit authorization for SYN tokens was not revoked for about 922 days, and the attacker relied on this already obtained “check” to repeatedly invoke it at two different times, transferring approximately $97,000 and $122,000 worth of SYN respectively. A lack of awareness about authorization management resulted in a long-lasting exposure from what was originally a single mistaken signature, ultimately turning the Permit from a convenient tool into a treasure map that phishers can repeatedly cash in on.
GoPlus Sounds the Alarm: Don't Let Authorizations Become Invisible Bombs
When the malicious Permit that had been “forgotten for 922 days” finally laid out a complete attack path on-chain, GoPlus promptly raised the alarm. Regarding this case of double theft resulting in a total loss of approximately $219,000 in SYN, GoPlus repeatedly emphasized in its security advisory: the vast majority of such incidents do not start complexly but often stem from clicking on unknown links or signing on ambiguous pages. It reminds users to be vigilant against phishing pages and social engineering tactics, not to casually click on links, connect wallets due to airdrops, benefits, or urgent “risk alerts” and especially not to sign permissions that appear “harmless” without understanding their meaning.
In terms of specific responses, GoPlus directly points out “authorization management” as a weak link that many people overlook, suggesting users regularly review and revoke unnecessary or suspicious authorizations to eliminate the possibility of attackers invoking them repeatedly. In addition to paying attention to safety alerts issued by GoPlus, learning about high-risk contract addresses through media reports, users can also leverage the authorization list within their wallets, the authorized records displayed by blockchain browsers, or risk tags provided by security tools to conduct health checks on historical signatures, revoking the permissions for contracts that are no longer in use. Only by identifying and closing these invisible long-term authorizations can the Permit return to its rightful position, becoming a tool controlled by users rather than exploited repeatedly by attackers.
From Individual Cases to Normalcy: Authorization Management Becomes a Mandatory Lesson for Surviving in DeFi
This case of malicious Permit authorization being invoked about 922 days later, with the same contract twice draining SYN assets, illustrates that the so-called “once signed, lifetime effect” historical authorization, as long as it remains on the chain, is like a time bomb buried in the wallet, which can even be detonated three years later. Security platforms like GoPlus have been continuously tracking such malicious authorization phishing and have issued alarms regarding this case. Multiple media outlets have also followed up on the reports, indicating that similar risks are not isolated occurrences and that users' awareness of “authorization as an asset” remains weak. Moving forward, the true changes needed include making the authorization list, risk tags, and expiration reminders visible by default at the product level for wallets, even building infrastructure for “double confirmation before signing.” Moreover, security tools that make revoking unnecessary authorizations a one-click operation, and an upgrade in user habits are equally essential: no longer treating signatures as mere mechanical clicks but regarding each Permit as issuing a long-term check, regularly checking and proactively revoking when necessary to survive long enough in an environment laden with frequent phishing and long-tail malicious contracts.
Join our community to discuss and become stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。



