That sequence is worth sitting with, because it is not the old horror story of a seed phrase pasted into a fake support chat. Nobody needed the keys. The owner did the authorizing. Once an unlimited allowance exists, the approved address can call transferFrom and move the token up to whatever balance is sitting there. Pair that with a permit signature, and the whole drain can be bundled so tightly that the victim’s only real decision already happened off to the side, in a message they thought was a login or a checkout.
What Investigators Say Actually Happened
Blockchain security researchers described a pattern linked to users of a project called Revenue. Attackers, they said, submitted permit signatures those users had already produced. Those signatures were used to obtain unlimited permission to spend USDG. Immediately afterward, the same flow called the transfer function and moved the tokens. Both steps, according to the write-up, finished inside one transaction.
Funds that left were then split. About 20 percent went to one attacker-controlled address. About 80 percent went to another. That ratio is what pulled extra attention, because drainer-as-a-service shops have long advertised automatic revenue shares between the people who lure victims and the people who supply the scripts. Researchers noted the resemblance. They did not claim they had proved the same infrastructure was in use here. That distinction matters. A familiar split is a clue, not a conviction.
An unlimited approval is not a visit. It is a spare key you handed over, and it keeps working until you change the lock.
A wallet-safety habit worth keeping
I’ve found that readers skim past the word “approval” because it sounds administrative. It is not. In token terms, an approval is a standing order. A permit is a way to create that standing order with a signed message rather than a separate on-chain approval transaction. Convenient for legitimate apps. Perfect for someone who wants the permission and the theft to look like one blur.
The Same-Transaction Detail Is the Nasty Part
Plenty of approval phishing leaves a gap. You sign. Hours later, sometimes days later, a script notices the allowance and sweeps what it can. That gap is miserable, but it is also a window. A revocation tool, a paranoid refresh of the allowance page, a friend who says “revoke that,” can still matter.
Here, researchers say, the window was designed out. Submit the permit. Grant unlimited spend. Call the transfer. Done. By the time a block explorer makes the story readable to a normal person, the USDG is already elsewhere, then split. You can still study the trail. You cannot un-sign the moment.
Is that technically elegant? In a grim way, yes. Is it new in spirit? No. Approval phishing has been a staple of wallet crime for years. What changes is the packaging: gasless permits, social funnels, influencer posts, and services that sit next to a well-known payment brand without belonging to it.
A Split That Looks Like a Business Model
The 20/80 cut is the detail people keep repeating, and I get why. Drainer shops do not always pay affiliates by invoice. Some of them wire the share into the drain itself. Victim signs. Contract or script takes the tokens. A slice routes to the operator. The rest routes to the affiliate who bought the traffic, posted the link, or ran the fake front end. Nobody has to trust the other side with a weekly settlement. The chain does the payroll.
Security teams have described that feature in earlier drainer ecosystems: malicious scripts, approval-command generation, automated draining, cross-chain cash-out, token swaps, and tools for piling stolen assets into fewer wallets. One investigated campaign, tied by researchers to a broader drainer ecosystem after a user lost a large stablecoin sum through a fake trading front end, was linked by those teams to tens of millions of dollars across several incidents. A separate civil complaint, filed by an anonymous investor against a major exchange, alleged that a well-known drainer kit sat behind a 2024 phishing theft of a very large stablecoin balance. Part of that trail was later said to touch a retail account. None of that history proves the Revenue-linked flow used the same kit. It does explain why a neat percentage split makes analysts sit up.
Perhaps the most interesting aspect is how ordinary the business language has become. “Revenue sharing” used to mean a SaaS pricing page. In this corner of crypto crime it means the victim’s balance is the invoice.
What the Service Told Users It Was
Revenue has presented itself as a way to move dollars from a social platform’s money product into crypto without a know-your-customer check. The pitch, as published on its own site, is simple. Sign in with the social account. Create an order. Send dollars to a named payment handle. Receive crypto in a wallet you supply. Advertised payout options have included USDC, USDT, SOL, and ETH. Orders were described as ranging from 10 dollars to 20,000 dollars, with a stated daily cap of 20,000 dollars per account. The published fee was 2 percent plus 50 cents.
The site has also said the social login is there to tie an order to the person sending the payment, that the access requested is read-only, and that access tokens are not retained. It states, plainly, that the service is independent and is not affiliated with or endorsed by the social company or its payments arm. That disclaimer is easy to miss when the product name sits next to the payment brand in every headline. It is not a small point. A bridge that borrows the glow of a famous app is not that app.
The social platform’s own money product has been rolling out to premium subscribers in the United States, with peer-to-peer transfers, deposit accounts, and a debit card. Direct crypto support had not been announced as part of that rollout. A third-party bridge offering “we will turn those dollars into coins” was always going to attract two crowds: people who genuinely wanted the conversion, and people who wanted to stand in the doorway.
The Account Trouble Came First
Questions around the project did not start with the USDG claims. Days earlier, around the first of the month, the project said control of a social account had been compromised by someone associated with its moderation operation. Swaps were temporarily suspended. Users were warned about activity happening under the name. A messaging channel initially said the project had not launched a token and told people to avoid assets claiming an official tie. Later posts promoted a REV token anyway. Conflicting messages are not proof of a drain. They are a reason to slow down, which is exactly what rushed signature requests are built to prevent.
The website, checked after the security disclosure, was still up and still advertising the conversion flow. Safety copy on the site tells users the project will not contact them first in direct messages, and will not ask for passwords, seed phrases, or private keys. It tells them to send the social-money payment only to the named handle after creating an order on the site. Sensible rules. They also miss the attack that does not need a seed phrase at all.
That is the gap I keep coming back to. A project can warn you, correctly, never to hand over the master key, and still leave you exposed to a signature that grants a spender the right to move one token. Both warnings belong on the same page. Most sites only print the first.
Promotion That Looked Familiar
Researchers also said the promotional style resembled another operation that leaned on crypto influencers, often called KOLs, to reach targets. They did not publish evidence that the same people ran both. Influencer distribution is common enough that similarity alone is a weak link. It is still a useful reminder. A familiar face posting a “bridge” is not due diligence. It is distribution.
No public total loss figure has been established for the Revenue-related transactions in the material released so far. Treat any viral number you see in replies as unverified until someone shows the transactions. The mechanism is the story. The dollar sum can wait.
How a Permit Signature Differs From a Normal Send
A normal send is boring in a good way. You choose an amount. You choose a recipient. You pay gas. The chain records that you moved tokens. If you did not intend it, the mistake is at least visible as a transfer from your address.
An approval is a different animal. You authorize a spender, often a contract, to pull up to a ceiling. That ceiling can be the exact amount of a trade. It can also be the maximum number the token’s math allows, which wallets sometimes label in scientific notation or, worse, hide behind a friendly “unlimited” toggle that defaults to on. After that, the spender does not need you. It calls transferFrom, and the token contract checks the allowance, not your latest mood.
A permit compresses the setup. Standards such as a typed-data permit let you sign an off-chain authorization. Someone else submits it, pays the gas, and the allowance appears. Legitimate decks use this so a swap can feel like one click. Phishing sites use it so the dangerous half of the click never looks like a transaction in your history until the damage is already the transaction.
- A seed-phrase theft takes the whole wallet, every chain, every token, forever, unless you move fast to a new wallet.
- An approval theft takes the token you approved, up to the allowance, for as long as that allowance stands.
- A permit theft can create that allowance without a prior approval transaction you would have seen in the activity tab.
- An unlimited allowance removes the ceiling. The next balance you receive can leave the same way.
A similar approval case in July left an Ethereum user down nearly a million dollars after a malicious signature. The pattern is not exotic. It is repeated because it works on people who would never type twelve words into a website.
Why Unlimited Is Worse Than “Just This Trade”
Exact-amount approvals are not harmless. A bad spender can still take the amount you allowed. Unlimited approvals are worse because they survive the trade you thought you were making. You top up the wallet next month. The old spender is still invited. You bridge a different sum. Same door. You forget the site existed. The allowance does not forget you.
In my experience, the people who get caught are not only newcomers. They are also traders who sign twenty prompts a day and have trained themselves to treat the wallet popup as a speed bump. Speed is the product the attacker is buying from you.
| Action you think you took | What the chain may record | What you can still do |
| Signed a “connect” or permit | Unlimited USDG allowance to a stranger | Revoke immediately if funds remain |
| Approved a swap | Spender can pull the token later | Set allowance to zero after use |
| Sent a normal transfer | One movement of a set amount | Trace it; the rest of the wallet may be fine |
| Pasted a seed phrase | Full control, often across chains | Move remaining assets to a fresh wallet |
USDG Sits in a Crowded Stablecoin Neighborhood
USDG is a dollar-pegged token. That is the whole reason it shows up in drains. Attackers like assets that do not need a narrative. No waiting for a memecoin to have liquidity. No explaining a governance token to a cash-out desk. A stablecoin is already the exit, or one hop from it.
Holding a stablecoin is not itself the mistake. Leaving an unlimited allowance on a stablecoin is. If you only keep a trading float in a hot wallet, size that float as if a bad signature could take it this afternoon. The cold wallet is where the rent money lives. The hot wallet is a pocket.
A Practical Reading of the Wallet Popup
Wallets have gotten better at translating typed data. They are not good enough to save you on autopilot. Before you sign anything that is not an obvious send, look for four things.
- The spender address. If you cannot match it to a protocol you already meant to use, stop.
- The token. A permit for USDG is not a permit for “the app.” It is a permit for that balance.
- The amount. Unlimited, max uint, or a wall of nines is a decision, not a default you shrug through.
- The deadline and nonce. A permit that lives too long is a permit you will forget.
If the interface only says “signature request” and hides the fields behind a vague label, that is not a reason to trust it more. It is a reason to use a wallet that shows the raw message, or to refuse the site. I would rather lose a trade than learn what an unlimited stablecoin allowance costs.
Before you sign: Spender known? yes / no Token expected? yes / no Amount exact? yes / no Deadline short? yes / no Any “no” means close the tab.
What to Do If You Already Signed
Speed matters, and so does order. If the drain already landed in the same transaction, revocation will not bring the tokens back. It can still stop a second sweep if the allowance was set and the balance was not fully taken, or if you receive more of the same token later. Do not send a fresh top-up to a wallet that still has a dirty allowance. That is how a “small” loss becomes a second invoice.
Revoke the spender for that token. Check every chain you actually use, not only the one you remember. Approvals are per token and per chain. A clean Ethereum allowance says nothing about a sidechain where you once clicked through a bridge. After revoking, watch the address. If a script retries, you want to see the failed call, not another success.
If there is any chance the seed was also exposed, revocation is not enough. Move what remains to a new wallet created on a device you trust. Leave the old address as a burned house. People hate this step because it is annoying. Annoying is cheaper than a second drain.
How Drainer Shops Actually Get the Click
The kit is rarely the hard part. Distribution is. Fake sites ride on sponsored ads, typo domains, compromised social accounts, and influencer posts that last just long enough to catch a weekend. A moderation insider, a bought reply guy, a hijacked handle: any of those can put a malicious link under a name you already follow. The earlier account-compromise report around this project is a reminder that “the official account said so” is a weaker sentence than it used to be.
Then comes the page. It copies a layout you have seen. It asks you to connect. It frames the permit as a login, a quote, a points claim, an airdrop check. The emotional hook is mild on purpose. Panic is memorable. Mild is what gets signed between meetings.
After the signature, automation does the unglamorous work. Submit permit. Set allowance. Pull tokens. Split proceeds. Swap if needed. Bridge if the exit chain is somewhere else. The affiliate does not have to be a developer. That is the whole pitch of drainer-as-a-service, and it is why a neat percentage split keeps showing up in incident reports even when the brand name on the front end changes.
Separating a Risky Product From a Proven Operator
Careful language is not softness. It is how you avoid accusing a team of running a theft kit when the public evidence is a pattern and a resemblance. What researchers have put forward is serious: permit signatures, unlimited USDG permission, an immediate transfer, a 20/80 split, a promotional style that echoed influencer-led lures, and a project that had already reported a social-account compromise. What they have not established, on the material described so far, is a shared codebase with a named drainer brand, a full loss total, or a courtroom finding.
You can act on the risk without finishing the trial. Do not send fresh funds into a flow that security teams have flagged. Do not treat a third-party bridge as if it were the payment product it sits beside. Do not sign unlimited permits for a stablecoin because a page called the click “verification.” Those are user-level decisions. They do not require you to decide who owns the backend.
The Social-Money Angle Makes People Lower Their Guard
Payments inside a social app feel domestic. You already trust the feed enough to scroll it. A service that says it will turn that balance into crypto borrows some of that domestic feeling. The disclaimer that it is not endorsed by the platform is legally useful and psychologically easy to skip. Brand adjacency is a marketing tactic. It is also a phishing tactic. The two can wear the same jacket.
There is a second lowering of the guard. “No KYC” is a feature for some users and a fog machine for others. Less identity checking can mean less friction. It can also mean fewer moments where a human or a compliance system asks why this order exists. I am not arguing that every conversion desk needs a dossier. I am arguing that the absence of one is not a security feature. It is a choice about friction, and attackers like low friction as much as customers do.
A Cleaner Habit for Anyone Who Still Uses Hot Wallets
You do not have to quit on-chain activity to survive it. You do have to stop treating allowances as paperwork.
- Keep spending balances in a hot wallet. Keep savings in a wallet that does not sign random permits.
- Prefer exact-amount approvals when the app allows them. Revoke after the trade if you will not use that spender again this week.
- Review allowances on a schedule, the way you would review card subscriptions. Monthly is enough for most people. Weekly if you ape into new sites.
- Bookmark the real domain yourself. Do not arrive through a reply, a sponsored ad, or a shortened link when money is involved.
- If a project has just reported a hijacked account, assume every link from that account is guilty until the team proves otherwise on a channel you already trusted.
- When a token claim, a points check, or a “connect to see your quote” asks for a permit on a stablecoin, close it. Quotes do not need spending rights.
Hardware wallets help, and they do not make you immune. They make the signature slower, which is most of the benefit. A slow signature is a signature you might actually read. If you still click through on muscle memory, the device is a paperweight with a screen.
What a Healthy Bridge Flow Would Look Like
Imagine the opposite of this week’s story. You create an order. The site shows the exact payout token, the exact fee, and the exact receiving address you typed. You send dollars to a handle that matches the order, not a handle a stranger whispered in messages. Crypto arrives from an address the operator has published and stuck to. At no point does anyone need permission to spend tokens already in your wallet. The bridge pushes funds to you. It does not pull funds from you.
That last line is the cleanest test I know. If a “we will send you crypto” service asks to spend the crypto you already hold, the request is upside down. Receiving does not require an allowance. Spending does. Anyone who blurs those two is either confused or hoping you are.
Bridge test: they pay you, or they ask to spend what you already have. Only the first one is a bridge.
Why the Influencer Layer Keeps Working
People outsource trust to faces. It is efficient, and it is how every market has ever scaled. Crypto just made the outsourcing instant. A short clip, a reply with a link, a “I use this to move my balance,” and the domain inherits a personality. Researchers said this project’s outreach resembled a model built on that kind of promotion. Even if the operators are unrelated, the lesson transfers. A personality is not an audit. A personality is a distribution channel that expires the moment the account is sold, hacked, or simply careless.
Ask a boring question before you click. Does this person get paid if I sign? If you cannot tell, assume yes. Paid distribution is not evil by itself. Undisclosed paid distribution pointed at a signature request is how allowances get born.
Reading the Split Without Overfitting the Story
Twenty and eighty is memorable, which is a risk of its own. Memorable details get copied into threads until they sound like a fingerprint. Automated splits can be configured. A copycat can choose the same ratio because it has been described in public write-ups. A manual operator can send 20 percent because that was the deal in a chat. Similarity is where an investigation starts. It is not where it ends.
Still, ignore the business shape and you will misunderstand the next incident. These are not always lone hackers writing custom code for one website. Often they are storefronts. The front end changes. The payout logic rhymes. When you see a clean affiliate cut inside the theft transaction, you are looking at a product, not a one-off grudge.
A Note on Tokens That Appear Mid-Crisis
The conflicting messages about a REV token are a side plot, and side plots are where rushed buyers live. A channel says there is no token. Posts appear promoting one. Whether or not any contract was official, the timing is the tell. Account trouble plus a sudden ticker is a classic way to harvest the audience that showed up for the drama. You do not need a position on the project’s intentions to skip the ticker. If the team cannot speak with one voice about whether the asset exists, you do not have enough information to price it.
The same pause applies to “support” accounts that appear in the replies. The website’s own safety text says the project will not contact you first or ask for secrets. Believe that sentence even if you believe nothing else on the page. Anyone who does the opposite is outside the rules the project printed.
What Families and Shared Wallets Should Change
A lot of these losses land on a wallet that more than one person can sign, or on a phone that lives on a kitchen counter. Shared access feels practical until one person approves a spender the other person never sees. If you hold meaningful stablecoin balances with a partner, write down who is allowed to connect new sites. It sounds fussy. It is cheaper than reconstructing a permit from a block explorer at midnight.
I have watched otherwise careful people treat a family hot wallet like a joint checking account, then connect it to a site because a cousin sent a link. Checking accounts do not grant a stranger a standing pull. Token approvals do. The metaphor breaks exactly where the money leaves.
Red Flags Worth Memorizing
None of these prove a crime on their own. Together they are a reason to wait.
- A social account that was just reported compromised, followed by new links.
- Conflicting statements about whether a token exists.
- A conversion service that asks to spend tokens you already hold.
- Unlimited or max-amount permits on a stablecoin.
- A fee and a flow that only make sense if you arrive through an influencer post.
- Pressure to finish “in this session” so a quote does not expire.
- Direct messages offering to fix a failed order by moving the chat off the site.
The last one is old, and it still works, because people who just lost money want a human. The human in the replies is often the second act of the same play.
How to Talk About This Without Spreading a Panic Number
If you warn friends, skip the invented totals. Say what is actually on offer as a claim: permit signatures, unlimited USDG spend, a transfer in the same transaction, a split between two addresses, a project that is not the social platform it references, and an account-compromise report from days earlier. That is plenty. A fake eight-figure caption does not make the warning stronger. It makes the next correction easier for scammers to hide behind.
Point people at revocation, not at a speculative ticker. Point them at the difference between a push payment and a pull allowance. Those two ideas will outlast this particular brand name.
The Longer Pattern Under the Headline
Every cycle grows a new doorway and a crowd willing to stand in it. This season’s doorway is the gap between a social payment balance and a self-custodied wallet. Someone will build a careful version. Someone will build a careless one. Someone will build a lure that wears the careful version’s colors. Users do not have to identify which of the three they are looking at with forensic certainty. They have to refuse any flow that needs spending rights in order to receive funds.
Approval phishing survives because it flatters you. It does not call you greedy in the cartoon sense. It calls you efficient. One signature, no extra gas, no second transaction, done before the meeting. Efficiency is a fine goal right up until the efficient step is the one that empties the stablecoin line.
There is a quieter cost too. Each of these stories teaches a slice of the audience that self-custody is a trap, when the trap was a permission they were never shown clearly. Custody is still the point. The missing piece is literacy around allowances. Seed phrases got the public-service announcements. Permits are still treated like a developer detail. They are not. They are the front door.
A Short Field Guide You Can Reuse
Keep this mental card. It fits the current reports and the next lookalike.
- If you did not mean to grant a spender, do not sign.
- If the amount is unlimited, treat it as a standing debit on that token.
- If the service claims it will pay you, it should not need to pull from you.
- If the account was compromised this week, links from it are paused, not trusted.
- If funds already moved, revoke anyway, then stop topping up that address.
- If a split between attacker wallets shows up in write-ups, read it as a business clue, not as proof of a specific kit.
- If a new token appears in the confusion, it is not your rescue.
None of this requires a lab. It requires a slower thumb. The attackers are counting on the opposite.
Where This Leaves Anyone Still Holding USDG
Holding the token is not the scandal. An allowance you did not mean to grant is the scandal. Open the allowance view for the chains you use. Look for spenders you do not recognize, especially on USDG and on the other stablecoins you actually keep. Revoke the strangers. Leave the ones you will use again only if you can name them out loud without checking a tab.
If you interacted with the conversion site, do not assume the only risk was the social payment you sent. Check whether a wallet you connected also signed a permit. Activity feeds hide signature requests more often than they hide transfers. The absence of an outgoing transfer is not the absence of an allowance. That single misunderstanding is how people get drained a day later and call it a mystery.
And if you are fine this round, write the habit down anyway. The next front end will not use the same name. It will use the same request. Unlimited. Permit. Same transaction. A split you were never meant to see. The defense is still the unglamorous one: read the spender, cap the amount, revoke what you do not need, and never let a bridge pull what it promised to push.
The signature felt smaller than a transfer. That is why it worked.
I keep a plain rule on a note next to the machine. Receive freely. Approve narrowly. Unlimited is a word I want to type myself, not a box I inherit. If this week’s reports are even partly right, a group of users learned the cost of the opposite in the time it takes a transaction to land. The rest of us can borrow the lesson without borrowing the loss.
]]>