Revenue has been linked to malicious $USDG approvals that allowed attackers to gain unlimited spending permissions before moving funds from users’ wallets in the same transaction.
Blockchain security firm Salus said attackers obtained permit signatures from users and submitted them to secure unlimited permission to spend their $USDG. Once the approval was granted, the perpetrators immediately called the transferFrom function to move the tokens.
?@RevenueFamily involves malicious approvals. The perpetrators submit users’ permit signatures to obtain unlimited permission to spend their $USDG, then immediately call transferFrom. The approval and fund transfer are completed in the same transaction, draining users’ wallets… pic.twitter.com/to0fo2Hw5L
— Salus (@salus_sec) October 4, 2026