The post 402bridge hack leads to over 200 users drained of USDC appeared on BitcoinEthereumNews.com. GoPlus has detected unusual authorizations linked to 402bridge, leading to more than 200 users losing USDC in excessive authorizations made by the protocol. Summary The x402bridge protocol suffered a breach caused by a leaked admin private key, allowing an attacker to steal about $17,693 in USDC from over 200 users. The hack reveals vulnerabilities related to the x402 mechanism which relies on private keys stored on a server to enable admin privileges to on-chain addresses that may distribute and authorize transactions excessively. On Oct. 28, the web3 security company GoPlus Security’s Chinese social media account alerted users of a suspected security breach involving the x402 cross-layer protocol, x402bridge. The hack occurred just days after the protocol was launched on-chain. Before minting USDC (USDC), the action must first be authorized by the Owner contract. In this case, excessive authorizations led to more than 200 users losing their remaining stablecoins in a series of transfers. GoPlus (GPS) noted that the creator of the contract beginning with 0xed1A made an ownership transfer to the address 0x2b8F, granting the new address special administrative privileges held by x402bridge team, such as the ability to modify key settings and move assets. Shortly after gaining control, the new owner address executed a function called “transferUserToken.” This function allowed the address to drain all remaining USD Coins from wallets that had previously granted authorization to the contract. 402bridge suffered a breach that led to the hacker draining USDC from user wallets | Source: GoPlus Security In total, the 0x2b8F address drained about $17,693 worth of USDC from users before exchanging the stolen funds into ETH. The newly-converted ETH was later transferred to Arbitrum through multiple cross-chain transactions. As a result of the breach, GoPlus Security recommended users who hold wallets on the protocol to cancel any ongoing authorizations… The post 402bridge hack leads to over 200 users drained of USDC appeared on BitcoinEthereumNews.com. GoPlus has detected unusual authorizations linked to 402bridge, leading to more than 200 users losing USDC in excessive authorizations made by the protocol. Summary The x402bridge protocol suffered a breach caused by a leaked admin private key, allowing an attacker to steal about $17,693 in USDC from over 200 users. The hack reveals vulnerabilities related to the x402 mechanism which relies on private keys stored on a server to enable admin privileges to on-chain addresses that may distribute and authorize transactions excessively. On Oct. 28, the web3 security company GoPlus Security’s Chinese social media account alerted users of a suspected security breach involving the x402 cross-layer protocol, x402bridge. The hack occurred just days after the protocol was launched on-chain. Before minting USDC (USDC), the action must first be authorized by the Owner contract. In this case, excessive authorizations led to more than 200 users losing their remaining stablecoins in a series of transfers. GoPlus (GPS) noted that the creator of the contract beginning with 0xed1A made an ownership transfer to the address 0x2b8F, granting the new address special administrative privileges held by x402bridge team, such as the ability to modify key settings and move assets. Shortly after gaining control, the new owner address executed a function called “transferUserToken.” This function allowed the address to drain all remaining USD Coins from wallets that had previously granted authorization to the contract. 402bridge suffered a breach that led to the hacker draining USDC from user wallets | Source: GoPlus Security In total, the 0x2b8F address drained about $17,693 worth of USDC from users before exchanging the stolen funds into ETH. The newly-converted ETH was later transferred to Arbitrum through multiple cross-chain transactions. As a result of the breach, GoPlus Security recommended users who hold wallets on the protocol to cancel any ongoing authorizations…

402bridge hack leads to over 200 users drained of USDC

GoPlus has detected unusual authorizations linked to 402bridge, leading to more than 200 users losing USDC in excessive authorizations made by the protocol.

Summary

  • The x402bridge protocol suffered a breach caused by a leaked admin private key, allowing an attacker to steal about $17,693 in USDC from over 200 users.
  • The hack reveals vulnerabilities related to the x402 mechanism which relies on private keys stored on a server to enable admin privileges to on-chain addresses that may distribute and authorize transactions excessively.

On Oct. 28, the web3 security company GoPlus Security’s Chinese social media account alerted users of a suspected security breach involving the x402 cross-layer protocol, x402bridge. The hack occurred just days after the protocol was launched on-chain.

Before minting USDC (USDC), the action must first be authorized by the Owner contract. In this case, excessive authorizations led to more than 200 users losing their remaining stablecoins in a series of transfers.

GoPlus (GPS) noted that the creator of the contract beginning with 0xed1A made an ownership transfer to the address 0x2b8F, granting the new address special administrative privileges held by x402bridge team, such as the ability to modify key settings and move assets.

Shortly after gaining control, the new owner address executed a function called “transferUserToken.” This function allowed the address to drain all remaining USD Coins from wallets that had previously granted authorization to the contract.

402bridge suffered a breach that led to the hacker draining USDC from user wallets | Source: GoPlus Security

In total, the 0x2b8F address drained about $17,693 worth of USDC from users before exchanging the stolen funds into ETH. The newly-converted ETH was later transferred to Arbitrum through multiple cross-chain transactions.

As a result of the breach, GoPlus Security recommended users who hold wallets on the protocol to cancel any ongoing authorizations as soon as possible. The security firm also reminded users to check whether the authorized address is the official address of the project before approving any transfers.

In addition, users are encouraged to only authorize the necessary amount and never grant unlimited authorizations to contracts. Overall, they are urged to regularly check authorizations and revoke unnecessary ones.

The hack occurs just a a few days after x402 transactions began seeing a boom in usage. On Oct. 27, the market value of x402 tokens surpassed $800 million for the first time. Meanwhile, Coinbase’s x402 protocol recorded 500,000 transactions in a single week, indicating a 10,780% increase compared to the previous month.

The x402 protocol enables both humans and AI agents to make transactions using HTTP 402 Payment Required status code to enable instant, programmatic payments for APIs and digital content. This means that they can make instant stablecoin payments over HTTP.

What caused the alleged hack on 402bridge?

On-chain sleuths and blockchain security firms like SlowMist have concluded that the breach was most likely caused by a private key leak. However, they did not rule out the possibility of insider involvement. Due to the breach, the project has halted all activity and its website is now offline.

The official account for 402bridge has since addressed the exploit, confirming that it was indeed caused by a private key leak which led to more than a dozen team test wallets and main wallets on the protocol getting compromised in the process. The team is currently investigating the incident and has reported it to the authorities.

“We have promptly reported the incident to law enforcement authorities and will keep the community informed with timely updates as the investigation progresses,” said 402bridge.

In a separate post that was shared earlier, the protocol explained how the x402 mechanism works. It requires users to sign or approve transactions via the web interface. The authorization is then sent to a back-end server that extracts the funds and mints the tokens.

“When we onboard to x402scan.com, we need to store the private key on the server in order to call contract methods,” said the protocol.

“This step may expose admin privileges because the admin private key is connected to the internet at this stage, potentially leading to a leak of permissions,” the team continued.

As a result, if the private key is stolen by a hacker, then they are able to take over all admin privileges and reassign user funds to the hacker’s contract.

Source: https://crypto.news/402bridge-hack-leads-to-over-200-users-drained-of-usdc/

Market Opportunity
USDCoin Logo
USDCoin Price(USDC)
$1.001
$1.001$1.001
0.00%
USD
USDCoin (USDC) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Haier Shines at Australian Open 2026: Official Partner Elevates the Game with Smart Innovation and Purpose

Haier Shines at Australian Open 2026: Official Partner Elevates the Game with Smart Innovation and Purpose

MELBOURNE, Australia, Jan. 25, 2026 /PRNewswire/ — Haier, the world’s No.1 major home appliance brand, continues its strategic partnership with the Australian Open
Share
AI Journal2026/01/26 11:30
Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

The post Polygon Tops RWA Rankings With $1.1B in Tokenized Assets appeared on BitcoinEthereumNews.com. Key Notes A new report from Dune and RWA.xyz highlights Polygon’s role in the growing RWA sector. Polygon PoS currently holds $1.13 billion in RWA Total Value Locked (TVL) across 269 assets. The network holds a 62% market share of tokenized global bonds, driven by European money market funds. The Polygon POL $0.25 24h volatility: 1.4% Market cap: $2.64 B Vol. 24h: $106.17 M network is securing a significant position in the rapidly growing tokenization space, now holding over $1.13 billion in total value locked (TVL) from Real World Assets (RWAs). This development comes as the network continues to evolve, recently deploying its major “Rio” upgrade on the Amoy testnet to enhance future scaling capabilities. This information comes from a new joint report on the state of the RWA market published on Sept. 17 by blockchain analytics firm Dune and data platform RWA.xyz. The focus on RWAs is intensifying across the industry, coinciding with events like the ongoing Real-World Asset Summit in New York. Sandeep Nailwal, CEO of the Polygon Foundation, highlighted the findings via a post on X, noting that the TVL is spread across 269 assets and 2,900 holders on the Polygon PoS chain. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 Key Trends From the 2025 RWA Report The joint publication, titled “RWA REPORT 2025,” offers a comprehensive look into the tokenized asset landscape, which it states has grown 224% since the start of 2024. The report identifies several key trends driving this expansion. According to…
Share
BitcoinEthereumNews2025/09/18 00:40
A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

The post A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release appeared on BitcoinEthereumNews.com. KPop Demon Hunters Netflix Everyone has wondered what may be the next step for KPop Demon Hunters as an IP, given its record-breaking success on Netflix. Now, the answer may be something exactly no one predicted. According to a new filing with the MPA, something called Debut: A KPop Demon Hunters Story has been rated PG by the ratings body. It’s listed alongside some other films, and this is obviously something that has not been publicly announced. A short film could be well, very short, a few minutes, and likely no more than ten. Even that might be pushing it. Using say, Pixar shorts as a reference, most are between 4 and 8 minutes. The original movie is an hour and 36 minutes. The “Debut” in the title indicates some sort of flashback, perhaps to when HUNTR/X first arrived on the scene before they blew up. Previously, director Maggie Kang has commented about how there were more backstory components that were supposed to be in the film that were cut, but hinted those could be explored in a sequel. But perhaps some may be put into a short here. I very much doubt those scenes were fully produced and simply cut, but perhaps they were finished up for this short film here. When would Debut: KPop Demon Hunters theoretically arrive? I’m not sure the other films on the list are much help. Dead of Winter is out in less than two weeks. Mother Mary does not have a release date. Ne Zha 2 came out earlier this year. I’ve only seen news stories saying The Perfect Gamble was supposed to come out in Q1 2025, but I’ve seen no evidence that it actually has. KPop Demon Hunters Netflix It could be sooner rather than later as Netflix looks to capitalize…
Share
BitcoinEthereumNews2025/09/18 02:23