• Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated On 07/23/2025
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

06/09/2025 - Updated On 07/07/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Giant golden CZ statue erected in Washington days after Trump pardon sparks controversy

Giant golden CZ statue erected in Washington days after Trump pardon sparks controversy

10/28/2025
Kalshi sues New York regulators over alleged overreach in sports contract ban

Kalshi files federal lawsuit after New York orders halt to sports prediction markets

10/28/2025
DeFi hack insurance victory: Nexus mutual reimburses arcadia finance users after $3.5m breach

Over 200 wallets compromised in x402bridge hack after private key exposure

10/28/2025
  • Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated On 07/23/2025
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

06/09/2025 - Updated On 07/07/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Giant golden CZ statue erected in Washington days after Trump pardon sparks controversy

Giant golden CZ statue erected in Washington days after Trump pardon sparks controversy

10/28/2025
Kalshi sues New York regulators over alleged overreach in sports contract ban

Kalshi files federal lawsuit after New York orders halt to sports prediction markets

10/28/2025
DeFi hack insurance victory: Nexus mutual reimburses arcadia finance users after $3.5m breach

Over 200 wallets compromised in x402bridge hack after private key exposure

10/28/2025
Tuesday, October 28, 2025
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

Over 200 wallets compromised in x402bridge hack after private key exposure

 Security breach exposes vulnerabilities in x402bridge protocol, leading to $17,693 USDC theft

by Sania Arain
3 hours ago
in Crypto News
Reading Time: 3 mins read
0
DeFi hack insurance victory: Nexus mutual reimburses arcadia finance users after $3.5m breach

DeFi hack insurance victory: Nexus mutual reimburses arcadia finance users after $3.5m breach

Share on FacebookShare on Twitter

A hacker stole approximately $17,693 in USDC from more than 200 users of the x402bridge protocol after obtaining a leaked admin private key that granted unrestricted access to user wallets.

The breach, detected by GoPlus Security on October 28, exploited a critical design flaw in x402’s architecture where admin keys stored on backend servers can authorize unlimited token transfers from any wallet that previously approved the contract.

Detection and immediate impact of the x402bridge hack

On October 28, GoPlus Security alerted the community after observing suspicious authorizations linked to x402bridge. The attacker gained control by exploiting an ownership transfer in the smart contract, enabling a function called “transferUserToken” that drained wallets which had previously authorized the contract.

Stolen funds were then converted into ETH and moved through cross-chain transactions to the Arbitrum network, leaving affected users without their stablecoins.

Security advice following the breach

GoPlus Security urged users to promptly revoke any ongoing authorizations on wallets connected to x402bridge and verify authorized addresses carefully before approving new transactions.

The firm advised, “Only authorize the necessary amount and never provide unlimited access to contracts,” emphasizing the importance of regularly reviewing wallet permissions to prevent further losses.

Growing usage of the x402 protocol before the hack

The 402bridge hack comes amidst a period of rapid adoption for the x402 protocol, which experienced a surge in market value, surpassing $800 million. Coinbase’s x402 protocol recently recorded 500,000 transactions in a single week, marking a 10,780% increase from the previous month.

The protocol facilitates instant, automated payments for APIs and digital content using HTTP 402 Payment Required status codes.

Causes and investigation of the exploit

Blockchain security experts like SlowMist concluded the hack most likely resulted from a private key leak but did not exclude possible insider involvement.

The 402bridge team confirmed the private key leak compromised multiple test and main wallets.

“We have promptly reported the incident to law enforcement authorities and will keep the community updated,” the official statement read, as the team investigates the breach’s full scope.

Technical explanation of the vulnerability

The x402 mechanism requires storing private keys on backend servers to call contract methods after users authorize transactions via the web interface.

This backend architecture means the admin private key remains connected online, creating a risk of leakage. If stolen, hackers can assume full admin privileges, enabling them to redirect user funds arbitrarily  precisely what occurred in this hack.

Tags: . crypto newsblockchain bridgeBlockchain Securityblockchain technologyCrypto Exchangecrypto hackcrypto investigationCrypto theftcrypto walletscyber attackcybersecurityDeFi exploitsDeFi Securitydigital assetshacker attackprivate key leaksmart contract vulnerabilitywallet breachweb3 securityx402bridge hack
Share196Tweet123
Sania Arain

Sania Arain

Hello! I’m Sania, a freelance content writer with 3 years of experience. I’m passionate about crafting engaging, informative, and SEO-optimized content. I create blog posts, web content, and articles that help businesses communicate their message effectively

  • Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated On 07/23/2025
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

Deutsche Bank eyes stablecoin launch as tokenization wave hits European banking

06/09/2025 - Updated On 07/07/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Giant golden CZ statue erected in Washington days after Trump pardon sparks controversy

Giant golden CZ statue erected in Washington days after Trump pardon sparks controversy

10/28/2025
Kalshi sues New York regulators over alleged overreach in sports contract ban

Kalshi files federal lawsuit after New York orders halt to sports prediction markets

10/28/2025
DeFi hack insurance victory: Nexus mutual reimburses arcadia finance users after $3.5m breach

Over 200 wallets compromised in x402bridge hack after private key exposure

10/28/2025
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?