📈 Get daily crypto insights that make you smarter about your money

Malicious USDG Approvals Drained Revenue Users’ Wallets, and the Split Looks Like a Drainer Business Model

Revenue, a service that markets itself as a bridge for moving funds from X Money into cryptocurrency without know-your-customer checks, has been linked to malicious USDG approvals that allowed attackers to gain unlimited spending permissions before moving funds from users’ wallets in the same transaction.

Blockchain security firm Salus said attackers obtained permit signatures from users and submitted them to secure unlimited permission to spend their USDG. Once the approval was granted, the perpetrators immediately called the transferFrom function to move the tokens. Both steps were completed within a single transaction, leaving users with little time to react once their signatures had been submitted.

Funds taken through the transactions were then divided between two addresses controlled by the attackers, with 20 percent sent to one address and 80 percent to another. Salus compared the distribution pattern with the revenue-sharing structure used by the Inferno drainer-as-a-service operation, and separately said Revenue’s promotional methods resembled FomoPeek’s model of using crypto influencers to reach potential victims. The firm stressed it had not established that Revenue was using Inferno Drainer itself, and the similarities alone do not confirm shared infrastructure.

How permit signature attacks work

The thefts center on permit signatures, which allow token holders to approve spending without first submitting a separate approval transaction onchain. Once attackers have the signature, they submit it to authorize unlimited USDG spending and follow the approval with transferFrom, a function that lets an approved spender transfer tokens from another address within the limits of the existing allowance.

The method fits a common form of approval phishing in which attackers never need a wallet’s private key or seed phrase. The wallet owner signs an authorization, often presented by a malicious site as a routine wallet interaction, that gives another address permission to move specific assets. An unlimited approval leaves the approved address capable of transferring the affected token up to the holder’s entire available balance.

Permit signatures are particularly difficult for users to identify because permission is granted through a signed message rather than a conventional onchain approval transaction. In Revenue’s case, Salus said the approval and subsequent transfer were executed together, with the stolen USDG then routed toward the two addresses. The firm has not publicly established a total loss figure for the Revenue-related transactions.

The pattern has recent precedent. A similar approval attack in July saw an Ethereum user lose nearly 1 million USD after signing a malicious transaction that gave perpetrators access to move assets from the wallet without further authorization.

Why the 20-80 split caught investigators’ attention

The fund distribution is what links the incident to a broader criminal economy. Drainer-as-a-service operations automatically divide stolen assets between affiliates who run the phishing and the developers who provide the underlying software, which is exactly the kind of automated split the Revenue transactions display.

Salus has documented this economy before. The firm previously investigated a fake Hyperliquid website promoted through Google sponsored advertisements after a user lost roughly 550,000 USDC in August. Investigators linked the infrastructure behind that campaign to the Inferno drainer ecosystem, and Salus said its undercover investigation found a service offering malicious scripts, approval command generation, automated draining, cross-chain withdrawals, token swaps and tools for consolidating stolen assets. One advertised feature was automated revenue sharing, dividing phishing proceeds among participants without manual distribution. Groups connected to that infrastructure have been linked to approximately 52.74 million USD in losses across several incidents.

Inferno has surfaced in other large approval phishing cases. An anonymous investor sued Coinbase in May over assets connected to a 2024 phishing theft in which the plaintiff claimed roughly 55 million USD in DAI was stolen after interacting with a fake login page. The complaint alleged Inferno Drainer was used in the attack, and part of the stolen cryptocurrency was later traced to a Coinbase retail account, according to blockchain security firm Zero Shadow.

A service built on top of X Money

Revenue’s own business model is central to the story. The service describes itself as a route for moving funds from X Money into cryptocurrency without KYC checks. Its website tells users to sign in with an X account, create an order and send dollars through X Money to the @RevenuePay account, after which Revenue says it sends cryptocurrency to the user-supplied wallet. Advertised payout options include USDC, USDT, SOL and ETH, with orders ranging from 10 to 20,000 USD, a stated daily limit of 20,000 USD per account, and a fee of 2 percent plus 0.50 USD.

Revenue is not part of X or X Money. Its website states the service is independent and unaffiliated with X Corp. or X Payments. X Money itself began rolling out payment services to Premium and Premium+ users in the United States this year, offering peer-to-peer transfers, deposit accounts and a Visa debit card, with yields of up to 6 percent advertised at launch. X had not announced direct cryptocurrency support when the service rolled out, which is the gap Revenue positioned itself to fill.

Warning signs predated the drainer report

Questions surrounding Revenue surfaced several days before Salus disclosed the alleged malicious approvals. On October 1, the project said control of its social media account had been compromised by someone associated with its moderation operation. Revenue temporarily suspended swaps and warned users about activity taking place under its name. Its Telegram channel initially warned that Revenue had not launched a token and told users to avoid tokens claiming an official connection to the project, but posts subsequently appeared promoting a REV token, creating conflicting messages about whether the asset had any official relationship with Revenue.

Salus also noted that Revenue’s promotional approach resembled the methods associated with FomoPeek, where key opinion leaders were used to attract users, though the firm provided no evidence that the two operations were run by the same people. Revenue’s website remained accessible after the disclosure and continued advertising X Money to crypto conversions when checked.

The uncomfortable lessons for DeFi users

The incident is a textbook illustration of why approval hygiene matters more than key custody in many modern attacks. Users who never leaked a seed phrase still lost funds because a signed message is itself an authorization. Security teams consistently recommend the same defenses: revoke unused allowances regularly using onchain approval tools, treat any signature request from an unfamiliar site as hostile, and be especially wary of permit-enabled tokens, where the signature may not even appear as a transaction in the wallet’s history.

It is also a lesson about counterparty risk in gray-market bridges. A no-KYC conversion service operating on top of a payments product that has no official crypto integration was never a supervised institution. When its community was hit by wallet-draining approvals days after a social media compromise, the users holding signed, unlimited allowances were the ones who paid for it.

USDG itself, the token targeted by the approvals, is a regulated stablecoin issued under New York Department of Financial Services oversight, which offers its holders no protection against a signature they granted themselves. The security of a permit-enabled token is ultimately only as strong as the last request the user signed.

Source: Salus via crypto.news, Oct 5, 2026. This article is for informational purposes only and does not constitute investment advice. Digital assets are volatile and carry the risk of loss.

12 thoughts on “Malicious USDG Approvals Drained Revenue Users’ Wallets, and the Split Looks Like a Drainer Business Model”

  1. permit + transferFrom in the SAME tx. no approval tx in your history, nothing to catch. this is the single scariest attack pattern for normal users right now

    1. permit is the nasty part, no approval tx ever shows in your history. anyone who signed one of those REV promo messages is probably still sitting on a live allowance

    2. usdg_whale_watcher

      @revokeobv the 20/80 split matching inferno affiliate structure is the detail that convinces me this wasnt some solo dev. thats drainer-as-a-service plumbing

  2. no KYC bridge for X Money straight into crypto was the red flag sitting right there in the marketing. anyone who signed that permit handed over unlimited USDG spend

  3. A no-KYC bridge bolted onto a payments product that has zero official crypto support, promoted by influencers. Every red flag was flying before anyone got drained.

    1. the no-KYC pitch was the product and the attack vector at the same time. a bridge that skips identity checks was always going to end in drainer affiliate money

  4. the 20/80 split between two addresses matching Inferno revenue sharing is a pretty specific fingerprint. Salus hedging on shared infra but the pattern says enough

    1. @mei the FomoPeek style influencer push is the part that should get more attention. The drainer tech is nothing without the distribution channel

  5. permits make approvals invisible, thats the part that gets me. if you ever signed one of those REV promo messages go check your allowances today, dont wait for a drain tx to find it

  6. revoke_reminder

    approval + transferFrom in the same tx means you have zero seconds to react. check your allowances on revoke.cash today, not after

  7. their own telegram warning no REV token exists, then REV promo posts appear days later. compromised account or inside job, either way nobody should touch it

    1. compromised account fits the timeline better imo. official no-token warning, then promo posts days later reads like someone got phished and the keys went straight to the affiliate crew

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$85,542.00+0.3%ETH$2,707.46+0.2%SOL$120.00-1.2%BNB$786.49-0.2%XRP$1.50-0.2%ADA$0.2643+6.1%DOGE$0.0947-0.8%DOT$1.21+0.4%AVAX$10.88-1.7%LINK$13.88-2.0%UNI$9.07+0.7%ATOM$1.81+2.6%LTC$70.47-1.0%ARB$0.2058+1.6%NEAR$5.10+1.9%FIL$1.11+5.7%SUI$1.19-2.5%BTC$85,542.00+0.3%ETH$2,707.46+0.2%SOL$120.00-1.2%BNB$786.49-0.2%XRP$1.50-0.2%ADA$0.2643+6.1%DOGE$0.0947-0.8%DOT$1.21+0.4%AVAX$10.88-1.7%LINK$13.88-2.0%UNI$9.07+0.7%ATOM$1.81+2.6%LTC$70.47-1.0%ARB$0.2058+1.6%NEAR$5.10+1.9%FIL$1.11+5.7%SUI$1.19-2.5%
Scroll to Top