Users of the Revenue platform have been affected by a wallet-draining attack involving malicious USDG approvals. As of early October 2026, security firm Salus reported that attackers obtained permit signatures granting unlimited spending permissions on users’ USDG holdings. The approvals and subsequent transfers occurred within the same transaction. Stolen funds were split between two attacker-controlled addresses.
The project continues to face scrutiny after earlier reports of compromised social media accounts. It has restricted certain services such as swaps and redemptions. Victim funds remain unrecovered in the identified flows. Investigators rely partly on on-chain transaction patterns while routing analysis through permit-signature mechanics. This highlights the difference between standard token approvals and same-transaction draining techniques.
The Drivers of the Current Situation
The main issue is the exploitation of USDG permit signatures linked to Revenue activity. Salus stated that attackers submitted users’ signatures to secure unlimited spending rights and immediately executed transferFrom calls. No separate approval transaction was required in the observed cases. The distribution of stolen assets followed a 20/80 split between two addresses.
Revenue has limited its public response to prior warnings about unauthorized activity. Some users still face drained balances. The security firm points to similarities with known drainer-as-a-service models such as Inferno, though it did not confirm direct use of that infrastructure. Promotion methods were also noted as resembling influencer-driven schemes. Only permit-based unlimited approvals enabled the rapid extraction. The project had already suspended operations and denied association with certain tokens days earlier.
A full accounting requires additional victim reports and fund tracing. Limited recovery under single-transaction drains forms a narrower path. Security researchers are actively examining the related addresses. The situation is an approval-phishing challenge tied to the reported malicious signatures.
Impact and Broader Context
Questions about Revenue users being hit by malicious USDG approvals in a wallet-draining scheme keep growing. The attack method creates uncertainty for users of permit-enabled interfaces. It also affects trust in off-ramp and bridge-style platforms. Security firms and on-chain analysts continue to monitor related flows and signatures.
The issue drives debate on wallet-security practices. It raises questions about how effectively users can verify permit requests, the limits of same-transaction protections, risks of unlimited approvals, effects on platform reputation, and competition between legitimate services and phishing operations. Stakeholders stress that users should carefully review spending permissions. Salus and related reports say the pattern matches established drainer techniques while noting the absence of confirmed infrastructure links.
The recent findings forced renewed attention onto permit-signature risks. The current security review shows how post-drain analysis will determine attribution and any recovery potential.
New on-chain movements, additional victim disclosures, or platform statements will clarify the scope of the scheme and its resolution.
This analysis uses Salus reports, on-chain monitoring data, and related coverage. Incident details and fund recovery remain subject to ongoing investigation and possible further developments.
