Salus: Revenue tied to malicious permit-based approvals in wallet-draining attack

AI Market Summary
Salus reports a malicious authorization (permit) exploit tied to "Revenue", where attackers used user signatures to gain unlimited USDG spend and drained wallets in single-transaction transferFrom calls. The proceeds split 20/80 across two addresses, resembling an Inferno drainer-as-a-service pattern and KOL-amplified fraud distribution. Claims that Revenue enables non-KYC crypto on/off-ramping for X Money raise compliance and counterparty-risk concerns, pressuring crypto risk sentiment.
Impact level
● Medium
Affected assets
BTC/USDT+0.81%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
BlockBeats, Oct. 5 — Security firm Salus said Revenue was involved in a malicious authorization scheme. Attackers used users' permit signatures to grant unlimited spending approval for USDG, then immediately executed transferFrom. Both the approval and the asset transfer occurred within the same transaction, draining victims' wallets. Salus reported that the stolen funds were later split between two hacker-controlled addresses, with 20% sent to one address and 80% to the other. The distribution pattern reportedly mirrors Inferno's drainer-as-a-service model, while the promotion approach resembles the KOL-driven scam tactics associated with FomoPeek. Public information indicates Revenue serves as an off-ramp for X Money. Users can convert funds to cryptocurrency, or transfer cryptocurrency into X Money, without KYC.