
Crypto users lose $472K to address poisoning and Permit2 phishing
- —$305K in DAI lost after attacker dusted the victim from lookalike address 0x085ccc…18f1dd vs intended 0x085adc…18f1dd
- —Victim copied the address from transaction history without verifying it fully
- —$167,342 in LINK stolen after a phishing Permit2 approval signed on August 18, 2025
- —The Permit2 approval was exploited on October 3, more than a year after signing
Why it matters: The incidents show address poisoning and Permit2 approvals remain effective attack vectors, with old signatures exploitable months later.
Source: Incrypted