Crypto Prices

Cryptocurrency Users Targeted in USDG Approval Scam, Leading to Wallet Drains

15 hours ago
2 mins read
8 views

Recent Cryptocurrency Attack Overview

In a concerning development within the cryptocurrency realm, a blockchain security firm named Salus has reported a sophisticated attack involving malicious USDG approvals. This scheme enabled cybercriminals to acquire unlimited spending permissions, allowing them to drain funds from users’ wallets almost instantly.

Mechanism of the Attack

The attackers exploited the process of obtaining permit signatures from users, submitting these to gain unrestricted access to their USDG tokens. After securing the necessary approvals, they executed a function called transferFrom, which facilitated the swift transfer of tokens while the approval and transfer processes unfolded within the same transaction. This rapid execution left victims with little opportunity to respond or halt the unauthorized activity.

Distribution of Stolen Funds

The stolen funds were subsequently channeled to two separate addresses controlled by the attackers—allocating 20% to one address and 80% to another. Salus highlighted that this distribution pattern echoed the revenue-sharing practices seen with the Inferno Drainer operation, a known entity in malicious fund siphoning. Although Salus noted similarities, it refrained from definitively linking Revenue, the service affected by these attacks, to the Inferno Drainer, suggesting that these parallels alone do not substantiate a direct connection.

Vulnerabilities Exploited

Permit signatures were central to the vulnerabilities exploited in this incident. These signatures are designed to allow token holders to authorize spending without requiring a traditional on-chain approval transaction. Once acquired by the attackers, these signatures were used to permit unlimited transactions, thus enabling the prompt fund transfers that drained victims’ wallets. This method is emblematic of common approval phishing tactics where victims unknowingly give permission through signed messages instead of sharing their wallet’s private key or seed phrase.

Comparative Losses and Ongoing Investigations

In contrast to previous attacks where considerable losses were incurred—such as a recent case in which an Ethereum user lost nearly $1 million after being tricked into signing a similar malicious transaction—this particular theft’s total losses are still under review, with Salus yet to release an official estimate of the damage.

Implications for Revenue and User Safety

Particular attention has been drawn to the distribution of funds seized during these attacks, as it resonates with the operational tactics of automatic fund-sharing used in drainer-as-a-service frameworks. Salus has previously investigated similar infrastructure associated with other phishing activities, linking them to over $52 million in related losses.

Interestingly, while Revenue was implicated in this recent phishing attack, their operations as a service that facilitates cryptocurrency conversions from X Money do not involve KYC requirements. Their processes entail users signing in with an X account, creating orders, and transferring funds to the designated account, from which cryptocurrency is then dispatched to users’ wallets. As a precaution, Revenue has distanced itself from direct associations with X or X Money in an effort to establish credibility amidst rising suspicions.

Company Response and User Guidance

The company had recently reported a compromise of control over its social media accounts, which coincided with a warning to users about emerging unauthorized activities under its name. Amidst these allegations, Revenue has issued clarification stating they have not launched a token and urging users to disregard any messages requesting sensitive information.

As the situation develops, Revenue’s website maintains its promotion of secure X Money to cryptocurrency transactions, providing guidance to users on safe practices to avoid falling victim to such phishing threats. The rise of phishing attacks through smart contract interactions, like those witnessed in this instance, underscores the ongoing vulnerabilities within the crypto sphere as malicious actors continue to devise increasingly sophisticated schemes to exploit unsuspecting users.

Popular