• About Us
  • Careers
  • Contact
No Result
View All Result
Tuesday, October 28, 2025
DeFi Planet
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Markets
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAO
    • Metaverse
    • Glossary
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Markets
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAO
    • Metaverse
    • Glossary
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer
No Result
View All Result
DeFi Planet
No Result
View All Result
Home News Crime

402bridge Suffers Private Key Leak, Over 200 Users Lose USDC in Protocol Breach

28 October 2025
in Crime, News
Reading Time: 4 mins read
104 4
source: thisismoney.co.uk

source: thisismoney.co.uk

Quick Breakdown 

  • GoPlus detected a suspected exploit on x402bridge, leading to $17,000 in USDC losses.
  • The breach originated from a private key leak tied to the project’s backend system.
  • 402bridge has paused operations and reported the incident to law enforcement.

GoPlus flags suspicious activity on 402bridge

Web3 security firm GoPlus Security has issued a warning about an apparent exploit affecting x402bridge, a cross-layer payment protocol under the x402 ecosystem. The firm’s Chinese social media account revealed that the incident led to more than 200 users losing their USDC following unauthorized token transfers.

The breach, detected on October 28, occurred shortly after the protocol launched on-chain. According to GoPlus, the exploit stemmed from excessive user authorizations that allowed malicious transfers of stablecoins directly from connected wallets.

1/ #x402 大坑❗️ 过度(无限)授权要你命……

x402跨链协议 @402bridge 疑似被盗,合约 0xed1AFc4DCfb39b9ab9d67f3f7f7d02803cEA9FC5 的 Creator 把 Owner转给了0x2b8F95560b5f1d1a439dd4d150b28FAE2B6B361F,然后新 Owner调用合约中 transferUserToken 方法转移所有已授权用户钱包剩余的USDC。… pic.twitter.com/hegqhap3Od

— GoPlus中文社区 (@GoPlusZH) October 28, 2025

Attack vector: ownership transfer and exploited privileges

Blockchain data shows that the contract creator (address beginning with 0xed1A) transferred ownership to another address (0x2b8F), effectively granting it administrative privileges. These permissions allowed the new owner to modify key contract settings and execute sensitive functions.

Shortly after taking control, the exploiter triggered the “transferUserToken” function — draining all remaining USDC from wallets that had granted approvals to the protocol. In total, approximately $17,693 worth of USDC was stolen before being swapped for ETH and later bridged to Arbitrum through multiple cross-chain transactions.

GoPlus and security experts warn users

GoPlus urged users to immediately revoke any active authorizations related to 402bridge and verify all approved contract addresses. The firm reminded the Web3 community to avoid granting unlimited token allowances and to regularly audit wallet authorizations to prevent similar incidents.

Following the exploit, 402bridge confirmed the breach was caused by a private key leak that compromised several team wallets, including test and main accounts. The protocol has since halted all operations, taken its website offline, and reported the incident to law enforcement authorities.

In an earlier technical post, the team explained that the x402 mechanism relies on a web interface where users approve transactions. These approvals are relayed to a backend server that requires the admin’s private key to execute contract methods — a setup that inadvertently exposed sensitive admin credentials online.

The compromise enabled the attacker to assume full administrative control, redirecting user funds to malicious addresses. In March GoPlus security was listed on Binance following HODLer airdrop distribution.

 

If you would like to read more articles like this, visit DeFi Planet and follow us on Twitter, LinkedIn, Facebook, Instagram, and CoinMarketCap Community.

Take control of your crypto portfolio with MARKETS PRO, DeFi Planet’s suite of analytics tools.”

Share63Tweet39Share11
Favour Okosodo

Favour Okosodo

Experienced web content writer with a strong command of SEO, specializing in creating concise, engaging content that drives traffic and enhances conversions across diverse industries.

Related Posts

source: in.marketscreener.com
Crypto

Citi and Coinbase Partner to Power Institutional Digital Asset Payments

28 October 2025
source: kucoin.com
Crypto

KuCoin Pay and DFX.swiss Partner to Launch Crypto Payments at SPAR Stores in Switzerland

28 October 2025
source: prnewswire.com
Crypto

S&P Global Assigns “Junk” Rating to Michael Saylor’s Strategy, Citing Bitcoin Exposure and Liquidity Risks

28 October 2025
source: news.bitcoin.com
Crypto

Trump’s Pardon of Binance Founder Sparks Push to Ban Elected Officials from Owning Crypto

28 October 2025

Editors Picks

Mining vs. Staking: Which Crypto Validation Method Will Shape the Future?

Mining vs. Staking: Which Crypto Validation Method Will Shape the Future?

byOlajumoke Oyaleke
15 July 2025
0

Where Are the Ethereum-Killers Now?

Where Are the Ethereum-Killers Now?

byOlayinka Sodiqand1 others
6 January 2025
0

source: investorplace.com

How to Find the Newest Cryptocurrencies Before They’re Listed

byOlayinka Sodiq
30 December 2024
0

Exploring the Role of AI in Enhancing DeFi Security

Exploring the Role of AI in Enhancing DeFi Security

byOlayinka Sodiq
1 October 2024
0

The Ultimate Guide to How NFT Royalties Work

The Ultimate Guide to How NFT Royalties Work

byAdedamola Ojedokun
17 April 2024
0

Read More

Chain of Thoughts

The Aesthetics of Web3: Why Vibe Matters in Decentralized Communities

The Aesthetics of Web3: Why Vibe Matters in Decentralized Communities

byOlu Omoyele
27 September 2025
0

...

Zero-Knowledge Everything: Trust, Privacy, and Verification in the Digital Age

Zero-Knowledge Everything: Trust, Privacy, and Verification in the Digital Age

byOlu Omoyele
30 August 2025
0

...

What Happens When AI Gets a Wallet?

What Happens When AI Gets a Wallet?

byOlu Omoyele
31 July 2025
0

...

The Game-changing Triumvirate: Blockchain, Data Science, and Artificial Intelligence

The Game-changing Triumvirate: Blockchain, Data Science, and Artificial Intelligence

byOlu Omoyele
30 June 2025
0

...

Markets Update

Can Confidential Lending Unlock Trillions for DeFi Markets?

8 hours ago

Impact of Large Ethereum Validator Exits on ETH Price

8 hours ago

Leading Asset Classes in the On-Chain Real-World Asset Tokenization Trend

9 hours ago

KuCoin Pay Partners with Swapped Connect to Streamline Direct CEX Payments for Web3 Users

12 hours ago

Are Ethereum-Based Treasuries Emerging as the Berkshire Hathaway of Crypto?

3 days ago

Is the Crypto Market Now Majorly Driven by Institutions?

3 days ago
Read More

Events

  • No events
  • Spotlight

    All about Ethereum
    All about Algorand
    All about Bitcoin
    All about Gora

    Press Releases

    Swiss Bitcoin App Relai Acquires MiCA License in France

    bychainwire
    27 October 2025
    0

    River Public Sale – 48-Hour Dutch Auction Lowest Price Settlement, Claim and Refund Instantly After End

    bychainwire
    27 October 2025
    0

    Jiuzi Holdings, Inc. Partners with SOLV Foundation on $2.8B TVL Bitcoin Initiative to Advance Crypto Treasury Strategy

    bychainwire
    27 October 2025
    0

    MultiBank Group and Khabib Nurmagomedov Launch an Exclusive Worldwide Multi-Billion-Dollar Joint Venture to Build the World’s First Regulated Tokenized Sports Ecosystem.

    bychainwire
    25 October 2025
    0

    RIVER Gains 5x Following Binance Perp Listing, Supported by Time-Encoded Airdrop Conversion

    bychainwire
    24 October 2025
    0

    Read More

    ADVERTISING

    ABOUT

    TEAM

    CAREERS

    CONTACT

    TERMS & CONDITIONS

    PRIVACY POLICY

    © Copyright 2025 DeFi Planet

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • News
      • People
      • Business
      • Crime
      • Regulation
      • Crypto
      • CBDC
    • Markets
      • Bitcoin
      • Ethereum
      • Stablecoins
      • Altcoins
      • Crypto ETFs
      • Memecoins
    • Policy
    • Articles
      • Press Releases
      • Opinion
      • Explainers
      • Guest Post
      • Sponsored
    • Directory
      • Companies
      • People
      • Products
      • Wallets
    • Multimedia
      • Videos
      • Podcasts
    • Learn
      • DeFi Basics
      • Tutorials
      • Reviews
      • Blockchain Fundamentals
    • Research
      • Case Studies
    • Explore
      • DeFi
      • Crypto Gaming
      • NFT
      • DAO
      • Metaverse
      • Glossary
    • Jobs
    • Markets Pro
      • DeFi Planet Pro
      • Spend Crypto
      • Swap Crypto
      • Coin Prices
      • Crypto Exchanges
      • Crypto Analyzer

    © Copyright 2024 DeFi Planet   |   Terms & Conditions   |   Privacy Policy

    -
    00:00
    00:00

    Queue

    Update Required Flash plugin
    -
    00:00
    00:00