Security firm Salus: Revenue involved in malicious authorization, attackers exploit permit signatures to steal assets.
October 5: Security firm Salus states that Revenue is involved in malicious authorization. Attackers submit the user's permit signature to obtain permission to spend their USDG without limit, then immediately call transferFrom. The authorization and fund transfer are completed in the same transaction, thereby draining the user's wallet. The funds are subsequently split 20% and 80% to two hacker addresses.
The report states that this distribution structure resembles Inferno's drainer-as-a-service model, and its promotion method aligns with FomoPeek's pattern of using KOLs to carry out scams.
Public information shows that Revenue provides an exit channel for X Money. Users can exchange funds into cryptocurrency or send cryptocurrency into X Money without KYC.