Blockchain security firm Salus has linked Revenue — a service that markets itself as a bridge for converting X Money balances into cryptocurrency without know-your-customer checks — to a wallet-draining campaign targeting holders of the USDG stablecoin.

In an October 4 disclosure, Salus said attackers obtained permit signatures from users, submitted them to secure unlimited permission to spend the victims' USDG, and immediately called transferFrom — completing the approval and the drain within a single transaction. The findings were reported by crypto.news and Bitbase.

How the Drain Worked

Permit signatures are a known weak point in wallet security: a token holder can authorize spending through a signed message rather than a conventional on-chain approval transaction, making malicious requests harder for users to recognize. Once attackers held the signatures, no private key or seed phrase was needed — the authorization and the transfer executed together, leaving victims little time to react.

Stolen funds were divided between two attacker-controlled addresses, with 20% routed to one and 80% to the other. Salus has not published a total loss figure for the campaign.

A Familiar Business Model

The 20/80 split resembles the automated revenue-sharing structure used by Inferno Drainer's drainer-as-a-service operation, in which proceeds are divided between affiliates and the developers supplying the toolkit. Salus was careful with the comparison: it did not establish that Revenue used Inferno infrastructure, noting only that the distribution pattern — and Revenue's reliance on crypto influencers for promotion, similar to FomoPeek's model — matched known playbooks.

The background matters. Salus previously linked infrastructure behind a fake Hyperliquid website, promoted through Google ads after a user lost roughly 550,000 USDC in August, to the Inferno ecosystem, and connected groups behind that infrastructure to approximately $52.74 million in losses across several incidents. Inferno has also surfaced in other large approval-phishing cases, including a 2024 theft of roughly $55 million in DAI that became the subject of a lawsuit against Coinbase in May.

Days of Warning Signs at Revenue

The malicious approvals followed an earlier compromise at the project itself. On October 1, Revenue said control of its social media accounts had been seized by someone associated with its moderation operation, temporarily suspended swaps, and warned users about unauthorized activity under its name. Conflicting posts followed — including promotional messages for a "REV" token after the project's Telegram channel had stated no token existed.

Revenue's website, which remained online after the disclosure, instructs users to sign in with an X account, send dollars via X Money to an @RevenuePay handle, and receive USDC, USDT, SOL or ETH in return, with orders from $10 to $20,000, a 2% fee plus $0.50, and no affiliation with X Corp or X Payments.

For users, the defensive playbook is narrow but effective: revoke active token approvals regularly, treat any signature request from an unvetted service as hostile, and be especially wary of signed-message requests that never appear as a normal transaction in the wallet interface.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.