The post 402bridge private key leaks, 227 wallets drained in minutes appeared on BitcoinEthereumNews.com. 402bridge, the cross-layer protocol that builds upon the AI agent payments system x402, has been hacked, resulting in the theft of $17,000 in USDC from more than 200 victims. That’s according to crypto analyst PeckShield, which encouraged 402bridge users to revoke their allowances.  Pseudonymous X user “Ye in Web3” claims that after 402bridge’s contract was deployed, the private keys were leaked. They were then used to transfer ownership of the contract and drain users who had previously approved the contract to spend funds. In just 28 minutes, 227 users were affected. 402bridge added that the private leak led to the compromise of more than a dozen of the team’s test and main wallets. The protocol previously confirmed that private keys are stored on a server, which may have exposed admin privileges.  Due to this private key leak, more than a dozen of the team’s test and main wallets have also been compromised (ex. screenshot below). We have promptly reported the incident to law enforcement authorities and will keep the community informed with timely updates as the… pic.twitter.com/AZfgd1yWKG — 402bridge (@402bridge) October 28, 2025 Read more: ‘AI’ crypto trading agent, aixbt, hacked for $100K It said, “If a hacker obtains the private key, they can take over those privileges and reassign user funds to carry out an attack.” However, Ye in Web3 was also suspicious that the whole affair may be a rug pull coordinated by 402bridge. Specifically, they questioned the validity of 402bridge’s shared screenshot, and asked why the contract would include a feature allowing the contract owner to drain user funds.  For its part, 402bridge claims to have reported the incident to law enforcement authorities and is in the process of investigating and sharing details about the attack.  The founder of crypto security firm SlowMist, Yu Xian, also claimed… The post 402bridge private key leaks, 227 wallets drained in minutes appeared on BitcoinEthereumNews.com. 402bridge, the cross-layer protocol that builds upon the AI agent payments system x402, has been hacked, resulting in the theft of $17,000 in USDC from more than 200 victims. That’s according to crypto analyst PeckShield, which encouraged 402bridge users to revoke their allowances.  Pseudonymous X user “Ye in Web3” claims that after 402bridge’s contract was deployed, the private keys were leaked. They were then used to transfer ownership of the contract and drain users who had previously approved the contract to spend funds. In just 28 minutes, 227 users were affected. 402bridge added that the private leak led to the compromise of more than a dozen of the team’s test and main wallets. The protocol previously confirmed that private keys are stored on a server, which may have exposed admin privileges.  Due to this private key leak, more than a dozen of the team’s test and main wallets have also been compromised (ex. screenshot below). We have promptly reported the incident to law enforcement authorities and will keep the community informed with timely updates as the… pic.twitter.com/AZfgd1yWKG — 402bridge (@402bridge) October 28, 2025 Read more: ‘AI’ crypto trading agent, aixbt, hacked for $100K It said, “If a hacker obtains the private key, they can take over those privileges and reassign user funds to carry out an attack.” However, Ye in Web3 was also suspicious that the whole affair may be a rug pull coordinated by 402bridge. Specifically, they questioned the validity of 402bridge’s shared screenshot, and asked why the contract would include a feature allowing the contract owner to drain user funds.  For its part, 402bridge claims to have reported the incident to law enforcement authorities and is in the process of investigating and sharing details about the attack.  The founder of crypto security firm SlowMist, Yu Xian, also claimed…

402bridge private key leaks, 227 wallets drained in minutes

402bridge, the cross-layer protocol that builds upon the AI agent payments system x402, has been hacked, resulting in the theft of $17,000 in USDC from more than 200 victims.

That’s according to crypto analyst PeckShield, which encouraged 402bridge users to revoke their allowances. 

Pseudonymous X user “Ye in Web3” claims that after 402bridge’s contract was deployed, the private keys were leaked. They were then used to transfer ownership of the contract and drain users who had previously approved the contract to spend funds.

In just 28 minutes, 227 users were affected.

402bridge added that the private leak led to the compromise of more than a dozen of the team’s test and main wallets.

The protocol previously confirmed that private keys are stored on a server, which may have exposed admin privileges. 

Read more: ‘AI’ crypto trading agent, aixbt, hacked for $100K

It said, “If a hacker obtains the private key, they can take over those privileges and reassign user funds to carry out an attack.”

However, Ye in Web3 was also suspicious that the whole affair may be a rug pull coordinated by 402bridge.

Specifically, they questioned the validity of 402bridge’s shared screenshot, and asked why the contract would include a feature allowing the contract owner to drain user funds. 

For its part, 402bridge claims to have reported the incident to law enforcement authorities and is in the process of investigating and sharing details about the attack. 

The founder of crypto security firm SlowMist, Yu Xian, also claimed that “internal sabotage cannot be ruled out.” One such red flag he highlighted was the fact that 402bridge had already encountered a theft two days after it was registered

Xian also noted that this doesn’t imply collective wrongdoing by the whole 402bridge team, as “it’s not a typical rugpull.”

According to Xian, “this is the first publicly known theft case related to 402 protocol services.”

What is x402?

x402 is a payment protocol developed earlier this year by Coinbase that would allow AI agents, as well as humans, to pay for services without requiring an account or any authentication. 

Similar to the Hypertext Transfer Protocol (HTTP) 404 that appears as an error when content isn’t found, x402 is named after HTTP 402, another error that displays “payment required.”

This HTTP wasn’t widely adopted as it was made to be used in a future where microtransactions or digital cash payments made through browsers are the norm. Coinbase claims to have revived the system.

Read more: AI Agent BadCoin fumbles BSC launch, anti-sniping software flags traders

The use cases of its x402 system include:

  • API services paid per request
  • Allowing AI agents to autonomously pay for API access
  • Paywalls for digital content
  • Proxy services that aggregate and resell API capabilities
  • Microservices and tooling monetized via microtransactions

The streamlining of payment services within AI also made ground today when Sam Altman’s OpenAI announced that it had integrated PayPal into its AI software ChatGPT. 

Users will be allowed to search for any services or goods through the AI program and use their linked PayPal wallet to make a purchase. 

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Source: https://protos.com/402bridge-private-key-leaks-227-wallets-drained-in-minutes/

Market Opportunity
CROSS Logo
CROSS Price(CROSS)
$0.12388
$0.12388$0.12388
+0.77%
USD
CROSS (CROSS) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Trading time: Tonight, the US GDP and the upcoming non-farm data will become the market focus. Institutions are bullish on BTC to $120,000 in the second quarter.

Trading time: Tonight, the US GDP and the upcoming non-farm data will become the market focus. Institutions are bullish on BTC to $120,000 in the second quarter.

Daily market key data review and trend analysis, produced by PANews.
Share
PANews2025/04/30 13:50
Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

The post Polygon Tops RWA Rankings With $1.1B in Tokenized Assets appeared on BitcoinEthereumNews.com. Key Notes A new report from Dune and RWA.xyz highlights Polygon’s role in the growing RWA sector. Polygon PoS currently holds $1.13 billion in RWA Total Value Locked (TVL) across 269 assets. The network holds a 62% market share of tokenized global bonds, driven by European money market funds. The Polygon POL $0.25 24h volatility: 1.4% Market cap: $2.64 B Vol. 24h: $106.17 M network is securing a significant position in the rapidly growing tokenization space, now holding over $1.13 billion in total value locked (TVL) from Real World Assets (RWAs). This development comes as the network continues to evolve, recently deploying its major “Rio” upgrade on the Amoy testnet to enhance future scaling capabilities. This information comes from a new joint report on the state of the RWA market published on Sept. 17 by blockchain analytics firm Dune and data platform RWA.xyz. The focus on RWAs is intensifying across the industry, coinciding with events like the ongoing Real-World Asset Summit in New York. Sandeep Nailwal, CEO of the Polygon Foundation, highlighted the findings via a post on X, noting that the TVL is spread across 269 assets and 2,900 holders on the Polygon PoS chain. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 Key Trends From the 2025 RWA Report The joint publication, titled “RWA REPORT 2025,” offers a comprehensive look into the tokenized asset landscape, which it states has grown 224% since the start of 2024. The report identifies several key trends driving this expansion. According to…
Share
BitcoinEthereumNews2025/09/18 00:40
Where money is made

Where money is made

The post Where money is made appeared on BitcoinEthereumNews.com. S&P 500 wasn‘t to break down Friday, but I saw its upside as limited – it proved so, just as much
Share
BitcoinEthereumNews2026/01/26 08:06