Security firm Salus has issued a critical alert regarding the Revenue Family project, identifying it as a facilitator for malicious activity targeting decentralized finance (DeFi) users. According to on-chain analysis, the project—which positioned itself as an outbound bridge for X Money—has been linked to a sophisticated exploit involving malicious authorization. The breach resulted in the unauthorized drainage of USDG stablecoins, with the attackers utilizing deceptive permit signatures to bypass standard security protocols and access user wallets.
Mechanism of the Malicious Authorization
The technical details provided by security researchers indicate that the perpetrators exploited the permit function within the smart contract architecture. By tricking users into providing permit signatures, the attackers obtained unlimited USDG authorization without requiring separate approval transactions.
- The exploiters submitted user permit signatures to gain control over assets.
- Malicious actors executed transferFrom calls within the same transaction to instantly siphon funds.
- Stolen assets were distributed between two primary hacker addresses at an 80/20 ratio.
This method of exploitation is particularly dangerous as it allows attackers to bypass the traditional two-step "approve and transfer" process, often catching users off guard during bridge interactions.
Project Response and Claims of Internal Hijacking
The situation surrounding Revenue Family escalated on October 1, 2026, when the project management issued a public statement addressing the irregularities. The team claimed that their social media accounts were hijacked by internal auditors, leading to a breakdown in communication and operations. In an effort to distance the platform from the ongoing exploit, the project officially suspended all exchanges and took the unusual step of denying that REV functioned as the ecosystem's official token.
The project claimed that its social media accounts were hijacked by internal auditors, suspended exchanges, and denied that REV was the official token.
Despite these claims, security agencies remain focused on the flow of funds to the identified hacker addresses. The incident highlights the persistent risks associated with cross-chain bridges and the necessity of verifying contract permissions before interacting with emerging DeFi protocols. Investors are advised to monitor their wallet authorizations and revoke any permissions granted to the Revenue Family or associated X Money bridge contracts to prevent further loss of capital.
Frequently Asked Questions
Quick answers to the most common questions about this topic.