Revenue Users Lose Funds in Malicious USDG Approval Scheme
Revenue users have fallen victim to a wallet-draining scheme involving malicious USDG approvals. Attackers obtained permit signatures from users, allowing them to secure unlimited spending permissions before immediately transferring funds from the victims' wallets, all within a single transaction. The stolen USDG was then split 20% and 80% between two attacker-controlled addresses, a distribution pattern reminiscent of the Inferno drainer as a service model, according to blockchain security firm Salus.
Salus noted that the approval and transfer occurred in the same transaction, leaving users with little time to react. While the security firm did not confirm Revenue's direct use of Inferno infrastructure, the revenue-sharing structure mirrored that of known drainer operations. Revenue had previously reported a compromise of its social media accounts, temporarily suspending swaps and warning users about unauthorized activity.
The attack hinged on permit signatures, which allow token holders to approve spending without a separate onchain transaction. Once attackers secured these signatures, they authorized unlimited USDG spending and executed the transfer via the transferFrom function. This method aligns with common approval phishing schemes, where users unknowingly grant permission to move assets without exposing their private keys.
Salus compared the Revenue incident to similar approval attacks, such as a July case where an Ethereum user lost nearly $1 million. The firm also linked the fund distribution pattern to Inferno's automated revenue-sharing system, which has been tied to approximately $52.74 million in losses across multiple incidents. Revenue markets itself as an X Money crypto bridge, enabling users to convert X Money balances into cryptocurrency without KYC checks.