header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

Security firm Salus: Revenue involved in malicious authorization, attackers exploit permit signatures to steal assets.

BlockBeats news, October 5: Security firm Salus states that Revenue is involved in malicious authorization. Attackers submit the user's permit signature to obtain permission to spend their USDG without limit, then immediately call transferFrom. The authorization and fund transfer are completed in the same transaction, thereby draining the user's wallet. The funds are subsequently split 20% and 80% to two hacker addresses.


The report states that this distribution structure resembles Inferno's drainer-as-a-service model, and its promotion method aligns with FomoPeek's pattern of using KOLs to carry out scams.


Public information shows that Revenue provides an exit channel for X Money. Users can exchange funds into cryptocurrency or send cryptocurrency into X Money without KYC.

举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish