Danger signal

Permit Abuse

The permit() implementation transfers tokens instead of just approving.

Analyzer: Source-Code Analysis
Slug: permit_abuse

What it means

The source's permit (EIP-2612 gasless approval) contains transfer logic. A signed permit - which users expect to set an allowance - can move funds directly.

Why it matters

Permit signatures are collected off-chain by phishing kits at scale. A token whose permit transfers is a drainer with an ERC-20 facade.

How RektRadar detects it

Source regex on permit bodies containing transfer calls, raised as danger.

From our dataset

4,094
tokens carried this flag
1,298
of them classified scam
31.7%
of tokens with this flag end up classified scam
78
flagged in the last 30 days

Top brand-jacked tickers carrying this flag: $UNI-V2, $AI, $ELON, $BTC, $TRUMP

Pool version of the flagged tokens that trade: V4 4,058 · V2 2 · V3 1

Snapshot from RektRadar's token_analysis database as of 2026-06-20.

Recent tokens with this signal

Loading recent tokens…

Analyze a token →