Danger signal

Permit Abuse

The permit() implementation transfers tokens instead of just approving.

Analyzer: Source-Code Analysis
Slug: permit_abuse

What it means

The source's permit (EIP-2612 gasless approval) contains transfer logic. A signed permit - which users expect to set an allowance - can move funds directly.

Why it matters

Permit signatures are collected off-chain by phishing kits at scale. A token whose permit transfers is a drainer with an ERC-20 facade.

How RektRadar detects it

Source regex on permit bodies containing transfer calls, raised as danger.

From our dataset

4,015
tokens carried this flag
2,829
of them classified scam
70.5%
of tokens with this flag end up classified scam
225
flagged in the last 30 days

Top brand-jacked tickers carrying this flag: $UNI-V2, $ELON, $AI, $Elon, $TRUMP

Pool version of the flagged tokens that trade: V4 3,978 · V2 3 · V3 2

Snapshot from RektRadar's token_analysis database as of 2026-08-17.

Recent tokens with this signal

Loading recent tokens…

Analyze a token →