Blockchain security firm Salus discovered that the attack functions by obtaining unlimited spending permissions through permit signatures. Once a user signs this authorization, the attacker immediately executes the transferFrom function. This technique allows the theft to occur without the need for private keys or seed phrases, as the victim has already granted the malicious address the legal right to move tokens within the smart contract environment.
The stolen assets are subsequently split between two attacker-controlled addresses in a 20% to 80% ratio. Salus noted that this distribution pattern mirrors the revenue-sharing model popularized by the Inferno drainer-as-a-service ecosystem, though researchers stopped short of confirming that Revenue is utilizing Inferno’s specific infrastructure. The campaign also bears similarities to the FomoPeek model, which relies heavily on crypto influencers to lure potential victims.
These security concerns emerged shortly after Revenue reported a compromise of its social media accounts on October 1, which led to a temporary suspension of its swap services. While Revenue positions itself as an independent bridge for converting X Money balances into cryptocurrency, the project has faced mounting scrutiny following conflicting messages regarding its native tokens and its lack of formal affiliation with X Corp. Salus has yet to provide an aggregate figure for the total losses associated with these USDG transactions.

Comments (0)
No comments yet. Be the first!