Salus Flags Revenue Over USDG Permit Wallet Drains
Published October 6, 2026, 04:52 UTC. Claims are from security firm Salus and have not been independently verified by MABOnChain. No total loss figure has been published.
Blockchain security firm Salus said in a post on X on Sunday, October 4, that Revenue, a service that advertises converting X Money balances into crypto, "involves malicious approvals" used to drain users' USDG stablecoin. Salus said attackers submitted users' signed permits to get unlimited permission to spend their USDG, then moved the tokens out in the same transaction.
What Salus found
"The approval and fund transfer are completed in the same transaction," Salus wrote. The stolen funds were then split between two attacker addresses, 20% to one and 80% to the other, according to crypto.news and Blockfence, both citing Salus.
Salus said that split resembles the revenue-sharing model of Inferno Drainer, a "drainer as a service" operation that rents wallet-draining tools to scammers. crypto.news noted that Salus did not establish that Revenue used Inferno's infrastructure. Salus also said Revenue's promotion through crypto influencers resembled the methods of another scheme, FomoPeek, without showing the two were run by the same people.
Salus had not published a total loss figure as of the crypto.news report. The report did not include a response from Revenue.
What Revenue is
Revenue describes itself as a way to move money from X Money into crypto without know-your-customer (KYC) checks, according to crypto.news. Users sign in with an X account, create an order and send dollars to an @RevenuePay account through X Money. Revenue says it then sends USDC, USDT, SOL or ETH to the user's wallet. Its website says it is independent and not affiliated with or endorsed by X Corp. or X Payments.
On October 1, Revenue said control of its social media account had been compromised and temporarily suspended swaps, crypto.news reported. Posts then appeared promoting a REV token, even though Revenue's Telegram channel had earlier warned it had not launched one. Revenue later said it had regained control of the accounts, Blockfence reported. Blockfence said there is no confirmed evidence linking the account takeover to the malicious USDG signatures, and no evidence that the USDG token contract itself was hacked.
How a permit drain works
A permit is a signed message that approves another address to spend your tokens. Unlike a normal approval, it does not need its own on-chain transaction, so it can look like a harmless login or "sign to continue" request. The attacker does not need your seed phrase or private key. Once the permit is submitted, the approved address can move that token up to the full balance in the wallet.
How to protect yourself
- Read every signature request. Be wary of any request that mentions "permit," "approve" or an unlimited amount, especially from a site you reached through a promoted post or a direct message.
- Use a separate wallet with a small balance for new or unfamiliar services.
- Review and revoke token approvals you no longer need, using your wallet's settings or a block explorer's token approval checker.
- Be cautious with services that offer to skip identity checks, and with tokens claiming to be "official" after a project reports an account compromise.
For more warning signs, see our guide on how to spot crypto scams and our report on fake rewards vote sites that drain wallets.
This article is news reporting and is not investment advice.
Sources
- Salus (@salus_sec), post on X about Revenue and USDG permit approvals (Oct. 4, 2026), primary source
- crypto.news, Revenue users hit by malicious USDG approvals in wallet draining scheme (Oct. 5, 2026)
- Blockfence, Revenue Users Hit by Malicious USDG Permit-Signature Wallet Drains (Oct. 5, 2026)
MABOnChain Daily Brief
The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.
Prefer chat? Join us on Telegram
Keep reading
70 Fake Rewards Vote Sites Target Pendle, xStocks Users
Malwarebytes found 70 copycat sites posing as Pendle, xStocks, Zama and others, using a fake rewards vote to push visitors into wallet connections.
Ledger Phishing: Fake Google Ads Steal Recovery Phrases
Zscaler says fraudulent Google ads under a verified advertiser sent Ledger users through Google-hosted pages to a fake setup that steals recovery phrases.
Belgium Flags 51 Scam Platforms; BaFin Warns on Crypto Site
Belgium's FSMA added 51 fraudulent trading platforms to its warning list, and Germany's BaFin warned about btcx(.)investments under its crypto law.
CFTC Seeks Comment on Federal Rules for Crypto Exchanges
The CFTC published an early notice on Regulation CTX and Regulation CAM, a possible federal license for crypto trading with leverage. Nothing is final yet.



