Key Points:
Phishing is a cyber-attack where victims are tricked into providing sensitive information, such as private keys or passwords, by attackers posing as trustworthy entities. In this case, the Pendle Permit phishing scam, reported by Scam Sniffer, the user was deceived into signing a fraudulent permit, leading to the unauthorized transfer of their assets.
The Pendle Permit phishing scam exploited a feature enabled through EIP-2612, known as Pendle Permit. The protocol removes the need for prior authorization when interacting with smart contracts, allowing for the generation of authorization signatures without on-chain transactions.
As a result, victims can unknowingly sign permits for malicious websites without broadcasting them to the blockchain. The possession of these signatures alone grants authorization, making the system particularly vulnerable to abuse.
According to cybersecurity firm SlowMist, this feature carries significant risks as attackers can easily deceive users into signing malicious permits by imitating legitimate websites.
Wu Blockchain revealed that the victim’s address was identified by Arkham as belonging to a MakerDAO governance delegate, a key role within the MakerDAO ecosystem. Governance delegates are responsible for voting on crucial proposals, governance polls, and executive votes, thereby influencing major decisions within the Maker protocol.
MKR holders and delegates typically vote to progress proposals from initial polls to final executive votes, which are then implemented after a delay period known as the governance security module (GSM).
DISCLAIMER: The information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing. |
Best Cryptos to Buy in December 2024: Qubetics ($TICS) presale explodes, Ethereum (ETH) eyes a…
Palo Alto, California, 21st November 2024, Chainwire
Best Cryptos to Buy: Qubetics presale rockets ahead, Bitcoin nears $100k, and Avalanche prepares to…
London, United Kingdom, 21st November 2024, Chainwire
The move will see developers utilize USDC on Aptos in creating dApps on a wide…
Abu Dhabi, UAE, 21st November 2024, Chainwire
This website uses cookies.