Swap security

Does a one-time Permit2 signature leave a standing allowance?

A consumed SignatureTransfer authorization does not create a recurring spender allowance, but the token approval to Permit2 can remain.

A Permit2 SignatureTransfer authorizes a nonce-scoped transfer rather than a recurring spender allowance. Once successfully consumed, that authorization cannot simply be replayed. The underlying token allowance to Permit2 is a separate permission and can remain active.

Distinguish the module

SignatureTransfer documentation describes the one-time transfer flow. AllowanceTransfer instead manages reusable spender permissions with amount and expiration limits. A screen saying Permit2 does not establish which module you are authorizing.

The signature can also cover more than one token in a batched request. “One time” describes reuse, not necessarily a small financial amount or a single asset.

Review the first use

Verify the permitted token amount, spender context, deadline and any bound execution details. A malicious first use can still cause the full authorized loss. Replay protection does not make the initial authorization safe.

If the attempted transaction reverts atomically, do not assume a nonce was consumed merely because the signature appeared in a wallet history. Check the actual state and outcome.

After the swap

Review the token-level allowance if you no longer want Permit2 to have access. If an unused signature may have leaked, use scheme-specific invalidation guidance rather than relying only on the one-time label.

This distinction prevents two opposite mistakes: assuming every Permit2 signature leaves a recurring spender allowance, and assuming a one-time signature removes every underlying permission. Each claim concerns a different layer.

Sources & verification (3)

Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.

  1. Signature Transfer | Uniswap Developers

    Single-use transfer authorizations and unordered nonce protection.

    https://developers.uniswap.org/docs/protocols/permit2/concepts/signature-transfer
  2. Allowance Transfer | Uniswap Developers

    Amount, expiration, signature deadline and owner-token-spender nonce scope.

    https://developers.uniswap.org/docs/protocols/permit2/concepts/allowance-transfer
  3. Permit2 Overview

    Token approval layer and distinction between SignatureTransfer and AllowanceTransfer.

    https://developers.uniswap.org/docs/protocols/permit2/overview

Continue reading

Permit2 has two permission layers: what should you review? Can I revoke a permit signature that has not been used?