PANews reported on October 28th that the GoPlus Chinese community issued a security alert regarding a suspected theft of the x402 cross-chain protocol @402bridge. The creator of the contract starting with 0xed1A transferred the owner to the address 0x2b8F. The new owner then called the contract's transferUserToken method to transfer all remaining USDC from authorized user wallets. Before minting, USDC must be authorized to the @402bridge contract. This resulted in over 200 users having their remaining USDC transferred due to excessive authorization. A total of 17,693 USDC was transferred from the 0x2b8F address, which was then converted to ETH and transferred to Arbitrum through multiple cross-chain transactions. It is recommended that users who have participated in the project cancel the relevant authorization as soon as possible; remind users to check whether the authorization address is the official address of the interactive project before authorization, only authorize the required amount, and never authorize unlimitedly; and pay attention to regularly check the authorization and cancel useless authorization.PANews reported on October 28th that the GoPlus Chinese community issued a security alert regarding a suspected theft of the x402 cross-chain protocol @402bridge. The creator of the contract starting with 0xed1A transferred the owner to the address 0x2b8F. The new owner then called the contract's transferUserToken method to transfer all remaining USDC from authorized user wallets. Before minting, USDC must be authorized to the @402bridge contract. This resulted in over 200 users having their remaining USDC transferred due to excessive authorization. A total of 17,693 USDC was transferred from the 0x2b8F address, which was then converted to ETH and transferred to Arbitrum through multiple cross-chain transactions. It is recommended that users who have participated in the project cancel the relevant authorization as soon as possible; remind users to check whether the authorization address is the official address of the interactive project before authorization, only authorize the required amount, and never authorize unlimitedly; and pay attention to regularly check the authorization and cancel useless authorization.

GoPlus: x402 cross-chain protocol @402bridge suspected of being stolen, reminding users not to over-authorize

2025/10/28 11:46

PANews reported on October 28th that the GoPlus Chinese community issued a security alert regarding a suspected theft of the x402 cross-chain protocol @402bridge. The creator of the contract starting with 0xed1A transferred the owner to the address 0x2b8F. The new owner then called the contract's transferUserToken method to transfer all remaining USDC from authorized user wallets. Before minting, USDC must be authorized to the @402bridge contract. This resulted in over 200 users having their remaining USDC transferred due to excessive authorization. A total of 17,693 USDC was transferred from the 0x2b8F address, which was then converted to ETH and transferred to Arbitrum through multiple cross-chain transactions.

It is recommended that users who have participated in the project cancel the relevant authorization as soon as possible; remind users to check whether the authorization address is the official address of the interactive project before authorization, only authorize the required amount, and never authorize unlimitedly; and pay attention to regularly check the authorization and cancel useless authorization.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Share Insights

You May Also Like