Invest1 publisher2 min readPublished
Attackers turned single USDG permit signatures from Revenue users into unlimited spending rights
Salus says attackers tied to Revenue turned signed USDG permits into unlimited allowances and drained wallets within the same transaction. No private key was needed, so a USDG holder's risk depends on the signatures they approve.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Salus said the stolen USDG was split between two attacker-controlled addresses, with 20% sent to one and 80% to the other.
- The security firm likened that split to the revenue sharing used by the Inferno drainer-as-a-service operation, but did not establish that Revenue used Inferno infrastructure.
- Salus also said Revenue's promotion resembled FomoPeek's model of using crypto influencers, known as KOLs, to reach potential victims.
- Days earlier, Revenue had reported that its social media accounts were compromised, temporarily suspended swaps and warned users about unauthorized activity.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure A victim who keeps using a wallet that signed one of these permits is still funding an address the attacker can spend from, because an unlimited allowance reaches whatever USDG balance the wallet holds.
- constraint Because approval and transfer settle together, a victim has no moment after signing in which to step in. Refusing the signature is the only defence.
- contradiction Whether Revenue was the hijacked victim or the front of the scheme decides whether users have a project to seek redress from, and Salus's evidence so far points both ways.
Salus's account needs only two token functions [1][2]. A permit lets a holder approve spending with a signed message, without sending a separate approval transaction onchain [8]. The transferFrom function then lets the approved spender pull tokens from another address, up to the allowance [9]. If the allowance is unlimited, the only ceiling is the holder's available balance [11]. The attacker never needs a private key or seed phrase [10].
So the whole attack depends on getting one signature, and malicious sites present the request as a routine wallet interaction [17]. One signature can lose a lot of money. An Ethereum user lost nearly $1 million in July after signing a malicious approval [12]. Salus has not published a total for the Revenue-related transfers [13].
I think the money trail says more than the code does. Under the 20/80 split [4], the larger address takes four dollars for every one the smaller receives [1]. Drainer-as-a-service operations divide stolen assets automatically between affiliates and the developers who supply the software [16]. If Salus's Inferno comparison [5] holds, one address belongs to whoever rents out the kit and the other to whoever brought in the victims.
Salus has looked inside a kit like this before. In August a user lost roughly 550,000 USDC to a fake Hyperliquid site promoted through Google sponsored ads, and Salus linked that campaign's infrastructure to the Inferno ecosystem [14][15]. Its undercover work found a service selling malicious scripts, approval command generation and automated draining, plus cross-chain withdrawals, token swaps and tools to consolidate stolen assets [15]. Because the code comes as a service, an operator spends its money on finding victims: sponsored ads in the Hyperliquid case [14] and, going by Salus's comparison, influencers in Revenue's [6]. None of it goes on cracking keys, because a signed permit makes the key unnecessary [10].
Revenue's role can be read more than one way. Its own front end may have been the trap from the start, and Salus's influencer comparison points that way [6]. Or its hijacked social accounts [7] may have sent users to someone else's trap. Or the resemblance to Inferno may just be a common fee split [5]. In my view the answer does not change where the exposure sits. In Salus's account the funds left through signatures the owners approved [2], so a USDG holder's exposure depends on what they sign. That view would be wrong if any Revenue-linked wallet turns out to have lost USDG without signing a permit, because then the failure would lie in a front end or in the token contract.
What to watch
- A loss total from Salus or from onchain tracing would put a size on the Revenue drain for the first time.
- If Revenue explains how the malicious permit requests reached users, and whether it will restore swaps, that would settle whether it was the victim or the vehicle.
- Any link between the two receiving addresses and known Inferno wallets would turn Salus's comparison into an attribution.