Revenue Family Accused of Draining USDG via Malicious Permit Authorizations

AI Market Summary
Reports allege the Revenue Family project used malicious permit-based authorization to obtain unlimited USDG approvals and drain user funds via same-transaction transferFrom, splitting proceeds across two attacker addresses. The incident reinforces ongoing smart-contract and social-engineering risks around bridges and "withdrawal" tooling, likely weighing on near-term risk appetite in smaller DeFi ecosystems and increasing scrutiny of signature-based approvals.
Impact level
● Medium
Affected assets
BTC/USDT+1.48%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Odaily Planet Daily cited Salus monitoring as warning that Revenue Family, a project presenting itself as X Money's withdrawal bridge, may be linked to a malicious authorization scheme. The alert said attackers诱導 users to sign permit messages, securing unlimited USDG allowances and then using transferFrom to move funds immediately within the same transaction. The siphoned assets were reportedly split 80/20 between two hacker-controlled addresses. Revenue Family previously stated on Oct. 1 that its social media accounts had been taken over by internal auditors, that it had paused exchanges, and that REV is not an official token.