Revenue Users Hit by Malicious USDG Approvals in Wallet Draining Scheme
A wallet-draining scheme abused USDG permit signatures to give attackers unlimited spending rights, then moved funds inside a single transaction. Salus says the signatures were collected from users before the transactions were submitted.
This article may contain affiliate links. Commercial relationships are disclosed in the affiliate policy.
What happened
A wallet-draining operation abused USDG spending permissions to empty user balances. According to blockchain security firm Salus, the attackers collected permit signatures from users and then submitted them, which granted unlimited spending rights over the affected stablecoin balances. Because a permit and its execution can land in the same transaction, the drain completed before most users had any chance to notice the approval.
The mechanism matters more than the loss total. A standard token approval lets a spender move an unlimited amount until it is revoked. A permit compresses the grant and the withdrawal into one signed authorisation, so the whole balance can leave in a single step with no intermediate state to interrupt.
What a permit actually changes
Two approval styles are routinely confused in wallet interfaces:
- Approval — you authorise an address to spend. The permission stays open until you revoke it, and the spender can move funds across many transactions.
- Permit — you sign a one-time authorisation with an expiry and an amount. Whoever holds that signature can execute it once, immediately.
The second form is what makes the drain fast. A user signing what looks like a routine DeFi approval may instead be signing a permit that carries no visible spending cap in the interface.
What to check before signing
- Read the full request. If the amount field is empty, unlimited, or larger than the balance you intend to move, stop.
- Treat any request to sign a permit as a spending action, not a login step.
- Revoke open approvals on the affected asset after the incident, on a reputable block explorer, and confirm the revocation landed before adding funds back.
Evidence boundary
This account is limited to what Salus reported and what the linked source describes. The full loss figure, the list of affected addresses and any recovery action are not confirmed in the material available here, so this note does not state them.