GoPlus Security said the victim had first lost about $1,625 in a phishing attack 183 days earlier and did not revoke the related token approval.
A user lost about $75,780 in USDC after failing to revoke a malicious Permit authorization signed 183 days earlier, GoPlus Security said. The same wallet had already been hit in a phishing attack tied to that Permit transaction, losing about $1,625 in USDC at the time. The incident underscores how Permit signatures (token approvals by signature) can leave lingering risks if compromised permissions are not canceled after an initial exploit.