A user lost a total of $219,000 in SYN tokens after failing to revoke a malicious Permit approval signed 922 days earlier. Monitoring by GoPlus showed the attacker first drained $97,000 worth of SYN through the phishing-linked authorization. Because the approval remained active, the same user was hit again in a second theft worth $122,000 in SYN. The case highlights the continued risk of leaving malicious token approvals unrecalled after an initial compromise.