Revenue users hit by malicious USDG approvals in wallet draining scheme


Revenue has been linked to malicious USDG approvals that allowed attackers to gain unlimited spending permissions before moving funds from users’ wallets in the same transaction.
Summary
- Revenue has been linked to malicious USDG permit signatures that gave attackers unlimited spending permission before funds were moved from users’ wallets.
- Salus said the approval and transfer were completed in the same transaction, with stolen funds subsequently divided 20% and 80% between two attacker addresses.
- The security firm said the fund distribution resembled Inferno’s drainer as a service model, though it did not establish that Revenue was using Inferno infrastructure.
- Revenue had reported a compromise of its social media accounts days earlier and temporarily suspended swaps while warning users about unauthorized activity.
Blockchain security firm Salus said attackers obtained permit signatures from users and submitted them to secure unlimited permission to spend their USDG. Once the approval was granted, the perpetrators immediately called the transferFrom function to move the tokens.
Both steps were completed within a single transaction, according to the security firm, leaving users with little time to react once their signatures had been submitted.
Funds taken through the transactions were then divided between two addresses controlled by the attackers, with 20% sent to one address and 80% to another.
Salus compared the distribution pattern with the revenue sharing structure used by the Inferno drainer as a service operation. The security firm separately said Revenue’s promotional methods resembled FomoPeek’s model of using crypto influencers, commonly known as KOLs, to reach potential victims.
Salus did not establish that Revenue was using Inferno Drainer itself, and the similarities cited by the firm do not by themselves confirm that the two operations shared infrastructure.
Revenue users signed unlimited USDG approvals
At the center of the reported thefts were permit signatures, which can allow token holders to approve spending without first submitting a separate approval transaction onchain.
Once attackers obtained the signatures, Salus said they submitted them to authorize unlimited USDG spending and followed the approval with transferFrom. The function allows an approved spender to transfer tokens from another address within the limits of an existing allowance.
The method fits a common form of approval phishing in which attackers do not need to obtain a wallet’s private key or seed phrase. Instead, the wallet owner signs an authorization that gives another address or smart contract permission to move specific assets.
As crypto.news previously explained in its report on wallet drainer attacks, permit signatures can be particularly difficult for users to identify because permission can be granted through a signed message instead of a conventional onchain approval transaction.
Malicious sites can present such requests as routine wallet interactions while the underlying signature authorizes an attacker to spend the victim’s tokens. An unlimited approval leaves the approved address capable of transferring the affected token up to the holder’s available balance.
A similar approval attack in July saw an Ethereum user lose nearly $1 million after signing a malicious transaction. The approval gave the perpetrators access to move assets from the wallet without requiring another authorization from its owner.
In Revenue’s case, Salus said the approval and subsequent transfer were executed together, with the stolen USDG then routed toward the two addresses.
The security firm has not publicly established a total loss figure for the Revenue related transactions in the information available so far.
Fund split resembles Inferno drainer model
Attention has centered on the 20% and 80% distribution of the funds because drainer as a service operations can automatically divide stolen assets between affiliates and the developers providing the underlying software.
Salus previously investigated a fake Hyperliquid website promoted through Google sponsored advertisements after a user lost roughly 550,000 USDC in August.
Investigators linked infrastructure behind the campaign to the Inferno drainer ecosystem. Salus said its undercover investigation found a service offering malicious scripts, approval command generation, automated draining, cross chain withdrawals, token swaps and tools for consolidating stolen assets.
One feature advertised by the operation was automated revenue sharing, allowing proceeds from successful phishing attacks to be divided among participants without requiring them to manually distribute the funds.
Groups connected to that infrastructure were linked by Salus to approximately $52.74 million in losses across several incidents.
Inferno has appeared in other large approval phishing cases. An anonymous investor sued Coinbase in May over assets connected to a 2024 phishing theft in which the plaintiff claimed roughly $55 million in DAI was stolen after interacting with a fake login page.
The complaint alleged that Inferno Drainer was used in the attack. Part of the stolen cryptocurrency was later traced to a Coinbase retail account, according to blockchain security firm Zero Shadow.
Revenue’s 20% and 80% distribution alone does not establish that Inferno infrastructure was involved in the latest transactions. Salus described the structure as resembling the drainer’s business model.
Revenue markets itself as an X Money crypto bridge
Revenue describes itself as a service for moving funds from X Money into cryptocurrency without know your customer checks.
Its website tells users to sign in with an X account, create an order and send dollars through X Money to the @RevenuePay account. Revenue says it then sends cryptocurrency to the wallet supplied by the user.
Available payout options advertised on the website include USDC, USDT, SOL and ETH.
Orders can range from $10 to $20,000, with a stated daily limit of $20,000 per account. Revenue charges a 2% fee plus $0.50, according to information published on its website.
The service says X authentication is used to connect orders with the person making an X Money payment. Revenue claims the access it requests is read only and says it does not retain users’ X access tokens.
Revenue is not part of X or X Money. Its website states that the service is independent and is not affiliated with or endorsed by X Corp. or X Payments.
X Money itself began rolling out payment services to Premium and Premium+ users in the United States this year, offering peer to peer transfers, deposit accounts and a Visa debit card.
X had not announced direct cryptocurrency support when the service rolled out. Revenue positioned its own service as a separate route for converting X Money balances into crypto held in users’ wallets.
Revenue faced account problems days before USDG claims
Questions surrounding Revenue surfaced several days before Salus disclosed the alleged malicious approvals.
On Oct. 1, the project said control of its social media account had been compromised by someone associated with its moderation operation. Revenue temporarily suspended swaps and warned users about activity taking place under its name, according to reports published at the time.
Its Telegram channel initially warned that Revenue had not launched a token and told users to avoid tokens claiming to have an official connection with the project.
Posts subsequently appeared promoting a REV token, creating conflicting messages around whether the asset had an official relationship with Revenue.
Revenue’s website currently presents safety instructions telling users that the project will never contact them first through direct messages or request passwords, seed phrases or private keys. It tells users to send X Money payments only to @RevenuePay after creating an order through its website.
The latest claims concern a different type of authorization because possession of a private key is not required when a user has already signed permission allowing another party to spend a token.
Salus said Revenue’s promotional approach resembled the methods associated with FomoPeek, where KOLs were used to attract users. The firm did not provide evidence establishing that Revenue and FomoPeek were operated by the same people.
Revenue’s website remained accessible following the security firm’s disclosure and continued advertising X Money to crypto conversions when checked.



