Signed Away: The Permit-Phishing Attack That Emptied USDG Wallets Behind a Fake 'X Money Bridge'

AnsemEagle
Weekly

The transaction settled in under twelve seconds. No gas. No confirmation dialog that mattered. No pop-up a normal user would have recognized as a threat.

At 14:07 UTC, a wallet holding USDG signed a permit. Moments later, that balance was gone β€” split 80/20 across two addresses that had never touched the protocol before and, if the on-chain trail holds, will never touch it again.

Here is the part that should stop you cold. The victim never approved a spend transaction. They signed a message. Off-chain. Gas-free. And that signature authorized an unlimited withdrawal β€” the maximum uint256 value, the entire balance β€” which an attacker's contract swept in a single atomic call. No revocation window. No time to hit cancel. The authorization and the theft executed in the same block.

I have been chasing ghosts in smart contract code since 2020, when I hand-coded a flash-loan arbitrage script over three sleepless nights for $4,200 across fourteen Uniswap V2 transactions. Back then, the attack surface was the pool. In this cycle, the attack surface is the signature. And this week, Salus β€” the security firm that surfaced the incident β€” alleges a project operating under the name Revenue Family used precisely that gap to drain user USDG.

The project says its social accounts were hijacked by an "internal review person." The security firm says the project itself ran the malicious authorization. Both cannot be true. And the distance between those two stories is where your money lives.

Context: Why a Signature Became the Weapon

Let me back up, because the mechanism here is not new β€” and that is exactly why it keeps working.

EIP-2612 introduced something called the permit function. Before it, if you wanted to let a contract spend your tokens, you had to send an on-chain approval transaction: pay gas, wait for confirmation, then let the spender move funds. Permit collapsed those two steps into one. You sign a message off-chain β€” no gas, no transaction β€” and the signature itself becomes the authorization. A contract submits it, verifies the signature against your address, and moves your tokens. Elegant. Efficient. And, as this week demonstrates, a loaded weapon pointed at anyone who does not read what they sign.

That is the crux. A permit signature is not a login. It is not a "verify you are human." It is a technically binding authorization to move a specific amount of a specific token from your wallet to a specific spender, and in most jurisdictions it is a legally binding one too. Most users experience it as a wallet prompt with a Sign button and a wall of hexadecimal they scroll past. The semantic gap between what they think they are doing and what they are actually doing is the entire attack.

Now layer in the brand. Revenue Family, per Salus, positioned itself as a "withdrawal bridge" tied to X Money β€” the payment infrastructure X has been building out. That framing matters more than the code. X Money is early, it is high-profile, and it carries the trust of a platform hundreds of millions of people already use every day. A project that borrows that name does not need to hack anyone. It only needs users to relax. And relaxation is the vulnerability.

The timeline is still open, and that is a problem for anyone trying to reach a clean verdict. On October 1, Revenue Family claims its social accounts were compromised. On October 5, the thefts surface publicly. The project then announced it had paused exchange operations and, in a separate statement, denied that REV β€” a token circulating with its name attached β€” is its official token. Three statements, four days, zero verifiable identities.

I want to be blunt about the information quality here, because a lot of coverage will not be. This is an in-progress event with a low information density β€” roughly seven data points, no confirmed contract addresses for the stolen asset, no disclosed team, no audited figures on total losses. Every serious analyst should flag that. What we can analyze with rigor is the mechanism and its industry meaning. What we cannot do is pretend to know the scale.

Core: Deconstructing the Attack Chain

Let me take the attack apart piece by piece, because the danger lives in the assembly, not in any single step.

Step one is the lure. A user is directed to what looks like an X Money withdrawal bridge. This is almost certainly a cloned front-end or a phishing link β€” permit attacks require the user to actively interact, so the attacker has to manufacture a reason for the signature. In 2025 I deployed a counter-agent to probe a hundred suspected scam bots and mapped a coordinated network of fifteen projects mimicking legitimate influencers. The tell in those operations was rarely visual. The domains were fresh, the contracts were unverified, and the withdrawal flow always, without exception, ended in a signature request.

Step two is the signature itself. The victim signs a permit. Because it is off-chain, there is no gas cost to the attacker and no on-chain trace until execution. The wallet displays a signature request, not a transaction. Users have been trained by years of sign-in-with-your-wallet prompts to treat this as harmless. It is not harmless. It is the whole ballgame.

Step three is the authorization. The permit grants an allowance. In this case, per the reported mechanism, the allowance was set to the maximum β€” effectively infinite. That single parameter is the difference between a bounded loss and a total wipe. If a user caps an allowance, the attacker can only move that much. Set to max, the attacker can move everything, forever, until the approval is revoked.

Step four is the sweep. The attacker's contract calls transferFrom β€” the standard ERC-20 function that lets an approved spender move tokens from a holder's account β€” and pulls the funds. Crucially, the authorization and the transfer execute in the same transaction, atomically. There is no window between you granting permission and your funds moving for a fast user to revoke. In earlier phishing waves, attackers sometimes left a gap between approval and drain, and sharp users could front-run the theft by revoking. Not here. The attack closes that door deliberately. That single design choice tells you the operator understands the countermeasures and built around them.

Step five is the split. Funds route 80/20 into two addresses. That ratio is not cosmetic. Splitting proceeds across multiple wallets is a textbook money-laundering and profit-sharing pattern. It suggests either a two-party operation or a deliberate attempt to complicate tracing and pre-position funds for bridging or mixing. The 80/20 number is a forensic fingerprint, not an accident.

Stack the steps and the profile is unambiguous. This is not a protocol exploit. It is a user-authorization exploit. There is no zero-day. No reentrancy bug. No oracle manipulation. No governance attack. The smart contracts did exactly what they were written to do. The failure was human β€” a signature given under a false premise β€” and the attacker's craft was in packaging a mature technique inside a trusted brand.

That distinction matters because it dictates the defense. You cannot patch this at the protocol layer. You patch it at the interface, at the wallet, and at the user's habits. Scanning the block for the missing brick, you find the brick was never missing β€” the wall was built on a lie.

Core: The USDG Question Nobody Has Answered

Here is where the reporting gets thin, and I would rather be honest about that than paper over it with confident-sounding speculation.

The stolen asset is called USDG. That name is doing a lot of work, and it is ambiguous in a way that changes everything.

Possibility one: USDG is Global Dollar, the compliant stablecoin issued through Paxos and the Global Dollar Network, with names like Kraken and Robinhood attached to it. If that is the case, this is not a small story. An attack that drains a regulated, institutionally backed stablecoin strikes directly at the trust narrative underpinning the entire safe-compliant-dollar-on-chain thesis β€” the exact thesis that brought traditional finance into this market.

Possibility two: USDG is a project-issued dollar-pegged token local to this ecosystem, with no institutional backing and no redemption guarantee. Possibility three: USDG is simply shorthand for the user's dollar-stablecoin balance in general.

I cannot resolve that from the source material, and neither, apparently, can the security firm β€” because the contract address has not been nailed down in what is public. This single unresolved fact determines the event's magnitude. Treat any confident claim about scale as noise until the token contract is confirmed on-chain. That is not hedging. That is discipline.

Then there is REV. The project actively denies REV is its official token. That denial is more interesting than any confirmation would have been. When an operator rushes to disown a token bearing its own name, you are usually looking at one of two things: a cut-and-run, where the team severs itself from a token right before it collapses, or a repudiation of responsibility, where the team distances itself from fallout it knows is coming. Either way, "our token is not our token" is not a sign of health. It is a sign of a project trying to control a narrative it has already lost.

I will not pretend there is a tradable thesis here, because there is not. There is no supply schedule to model, no emissions to project, no revenue to capture, no governance to influence. This is a theft, not a token economy β€” and the moment you start treating a theft like an investment, you have become the mark. The absence of an analyzable token model is itself the finding.

Core: The Ecosystem Niche of Brand Parasitism

Zoom out and the strategic picture sharpens.

Revenue Family occupies what I would call a parasitic niche. It does not build infrastructure. It does not create value. It borrows the credibility of a bigger name and converts that borrowed trust into user signatures. The dependency graph is brutally simple.

Upstream sits X and X Money β€” a brand the project is not authorized to use, as far as any public record shows. In the middle sits Revenue Family, the phishing carrier. Downstream sits the user's wallet, and below that, the two hacker addresses receiving the 80/20 split. Nothing in this graph produces value. It only transfers it, downward, from people who trusted a logo to people who rented one.

What makes this category durable is that it scales with attention, not with technology. Every time a major platform announces a payment or crypto feature β€” X Money now, whatever Apple or Tesla or Meta ships next β€” a cohort of look-alike projects appears within days, wearing the new brand like a costume. The attack does not require sophistication. It requires timing. Brand parasitism is the cheapest exploit in Web3, because the cost of manufacturing trust is zero when you can simply borrow someone else's.

And note what the project's own statements do to this graph. By claiming its accounts were hijacked, Revenue Family tries to reposition itself from attacker to victim β€” to insert itself into the downstream role alongside users. If that were true, we would be looking at a compromised operator. If it is false, we are looking at an operator using a hijack story as a pre-planted alibi. The October 1 date β€” four days before the thefts went public β€” leans hard toward the second reading. Beneath the surface, the nest was empty.

I have seen this exact shape before. During the 2021 Axie Infinity boom, I embedded with Play-to-Earn communities in Jakarta and interviewed fifty scholars and managers. What I found was a structure where 80% of revenue flowed to administrators, not players β€” a machine that looked like an economy but functioned as an extraction engine. The lesson transfers directly. When the incentives point at harvesting users rather than serving them, the branding is just the packaging on the harvest.

Core: Regulatory Posture and the Accountability Gap

On the legal side, let me be precise about what this is and what it is not.

Malicious authorization theft maps onto theft, fraud, and unauthorized computer access β€” criminal categories, not securities questions. The Howey test is a distraction here. Whether REV is a security only matters if REV turns out to be the project's fundraising instrument, and right now nobody credible will even confirm it belongs to them. Chasing a securities analysis on an unconfirmed token is how analysts waste a week and miss the actual crime.

The compliance posture, to the extent one exists, is nonexistent. No KYC. No AML. No disclosed legal entity. No registration. That is not an oversight; it is a design choice. Anonymous teams running phishing operations do not build compliance rails because compliance rails leave fingerprints. Every procedural safeguard a legitimate business carries is, to this operator, a liability to be avoided.

Which brings us to the accountability gap, and it is wide. Anonymous team, plus on-chain funds split 80/20, plus cross-border jurisdiction, equals a recovery probability close to zero. Enforcement requires an entity to charge, a jurisdiction to charge it in, and funds that have not been bridged or mixed. This operation has none of the first, an unclear second, and a live path to the third. Plan for prevention, because there is no plan for recovery.

There is one more thread worth pulling. The X Money brand angle cuts both ways for X itself. If the platform is being impersonated at scale, X has standing to pursue trademark and unfair-competition claims, and every week it stays silent, the borrowed trust keeps compounding for whoever wears the costume next. A brand clarification is not just public relations. It is the cheapest defense the platform can deploy, and its absence is conspicuous.

Contrarian: The Story the Churn Is Skipping

Now the angle the breaking-news cycle is missing.

The dominant narrative frames this as a security incident: phishing strikes again, users got careless, use a hardware wallet. All true, and all boring. The unreported story is that the project's "we were hacked too" defense and the security firm's "you were the hacker" accusation are structurally incompatible β€” and the market is pricing neither.

Watch the language closely. Revenue Family says an "internal review person" hijacked its accounts. Read that again. Not an external attacker. Not a compromised third-party service. An internal person. That phrasing smuggles in an admission β€” that there was an organization with internal roles, with access controls, with people positioned to compromise accounts. Projects that are pure phishing shells do not usually describe their own org chart. The alibi is more revealing than the crime.

And the timing seals it. October 1, the alleged hijack. October 5, the thefts surface. If your accounts are compromised on the first, you have four days to warn users, freeze flows, and pull the plug. Instead, the thefts ran. Either the operator was incompetent at the one job that mattered β€” protecting users during a known compromise β€” or the compromise story was written after the fact to explain the drain. Speed eats stability for breakfast, and here the speed was in the cover story, not the response.

Signed Away: The Permit-Phishing Attack That Emptied USDG Wallets Behind a Fake 'X Money Bridge'

Here is the deeper point the headlines miss. The market's reaction function is broken for events like this. There is no token to short with conviction, no clean counterparty to price, no venue that will reprice on a brand-abuse story until the brand owner moves. So the information gets absorbed as ambient fear and forgotten by the next news cycle. That is the attacker's real edge. Not the code β€” the fact that no one is structurally incentivized to remember.

There is a second blind spot. Most coverage will frame this as a user-education failure, which quietly absolves the interfaces. But the wallet UX here is complicit. A prompt that renders an infinite-approval permit as a generic Sign button is not a neutral tool; it is a design decision that trades user safety for friction reduction. The industry keeps shipping frictionless signing and then blaming users for signing. Volatility is just liquidity with a pulse β€” and this market pulses toward whoever absorbs the least friction, even when that friction was the only thing standing between a user and an empty wallet.

Contrarian: The Verification Protocol

Because this is an in-progress event wrapped in competing claims, I ran my standard verification protocol before publishing anything, and I want readers to see the method rather than just the conclusion.

First, source triangulation. The theft claim originates with Salus, a security firm with a reputational stake in accuracy. The counterclaim originates with the accused project, which has a direct interest in denial. I weight these unequally β€” not because security firms are infallible, but because the accused party's statements are self-serving by construction. When a party under accusation denies the accusation, that denial carries near-zero independent evidentiary weight.

Signed Away: The Permit-Phishing Attack That Emptied USDG Wallets Behind a Fake 'X Money Bridge'

Second, on-chain verification. The mechanism described β€” permit signature, infinite allowance, atomic transferFrom, 80/20 split β€” is fully consistent with observable on-chain behavior for this attack class. Nothing in the reported method requires unverifiable assumptions. This raises my confidence in the mechanism even though I cannot confirm total losses.

Third, timeline coherence. The four-day gap between the alleged account compromise and the public surfacing of thefts is the strongest single signal in the whole dataset, and it points away from the project's stated innocence.

Signed Away: The Permit-Phishing Attack That Emptied USDG Wallets Behind a Fake 'X Money Bridge'

Fourth, unresolved variables. The USDG contract address and the total victim count remain open. I refuse to fill those gaps with speculation. Where the data stops, my confidence stops with it.

That is the discipline this beat demands. A story you cannot verify is not a story you report as fact.

Takeaway: What to Watch From Here

So here is what I am watching, and what you should watch with me.

First, the two hacker addresses and the 80/20 split. If those funds touch a centralized exchange, a bridge, or a mixer, the trail stops being academic and becomes a compliance problem for whoever received them. That is the first real leverage point in this entire case, and it is trackable.

Second, the USDG contract address. The moment it is confirmed β€” Global Dollar or otherwise β€” the event's magnitude resolves from a small-project incident into something stablecoin issuers have to answer for. Until then, everyone claiming to know the scale is guessing.

Third, X's response. A public brand clarification would be the cheapest, most effective counter in this mess. Silence is a gift to the next impersonator.

Fourth, the REV token's behavior. If it shows violent swings or gets delisted, the market is pricing the project's statements in real time β€” and revealing whether it believes the hijack story at all.

And fifth, the wallet layer. This case is the strongest argument yet for forcing allowance caps and human-readable permission prompts into every signing flow. If the industry does not build that friction back in voluntarily, regulators eventually will.

The pattern is older than the brand it is wearing. Users sign what they do not read, attackers rent trust they did not earn, and the market forgets faster than it learns. Follow the scholar, not the token β€” and this week, the scholar left the nest empty. The question is not whether the next fake bridge appears. It is whether anyone is still watching the door when it does.