• Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated On 07/23/2025
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Crypto investor and wife found dead in Dubai as police investigate possible link to digital assets

Crypto investor and wife found dead in Dubai as police investigate possible link to digital assets

11/08/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Netflix director faces 90 years for allegedly diverting $11M into luxury purchases and crypto

Carl Erik Rinsch convicted of defrauding Netflix of $11 million for personal spending, crypto trades

12/14/2025
HSBC Tokenized Deposit trial enables real-time cross-border payments

HSBC completes tokenized deposit pilot for real-time cross-border payments with Swift

12/13/2025
Citadel SEC Bid Ignites Powerful Industry Backlash as DeFi Leaders Warn of Centralization Risk

Crypto groups challenge Citadel’s call for SEC oversight of DeFi tokenized stocks

12/13/2025
  • Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated On 07/23/2025
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Crypto investor and wife found dead in Dubai as police investigate possible link to digital assets

Crypto investor and wife found dead in Dubai as police investigate possible link to digital assets

11/08/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Netflix director faces 90 years for allegedly diverting $11M into luxury purchases and crypto

Carl Erik Rinsch convicted of defrauding Netflix of $11 million for personal spending, crypto trades

12/14/2025
HSBC Tokenized Deposit trial enables real-time cross-border payments

HSBC completes tokenized deposit pilot for real-time cross-border payments with Swift

12/13/2025
Citadel SEC Bid Ignites Powerful Industry Backlash as DeFi Leaders Warn of Centralization Risk

Crypto groups challenge Citadel’s call for SEC oversight of DeFi tokenized stocks

12/13/2025
Sunday, December 14, 2025
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

Over 200 wallets compromised in x402bridge hack after private key exposure

 Security breach exposes vulnerabilities in x402bridge protocol, leading to $17,693 USDC theft

by Sania Arain
2 months ago
in Crypto News
Reading Time: 3 mins read
0
DeFi hack insurance victory: Nexus mutual reimburses arcadia finance users after $3.5m breach

DeFi hack insurance victory: Nexus mutual reimburses arcadia finance users after $3.5m breach

Share on FacebookShare on Twitter

A hacker stole approximately $17,693 in USDC from more than 200 users of the x402bridge protocol after obtaining a leaked admin private key that granted unrestricted access to user wallets.

The breach, detected by GoPlus Security on October 28, exploited a critical design flaw in x402’s architecture where admin keys stored on backend servers can authorize unlimited token transfers from any wallet that previously approved the contract.

Detection and immediate impact of the x402bridge hack

On October 28, GoPlus Security alerted the community after observing suspicious authorizations linked to x402bridge. The attacker gained control by exploiting an ownership transfer in the smart contract, enabling a function called “transferUserToken” that drained wallets which had previously authorized the contract.

Stolen funds were then converted into ETH and moved through cross-chain transactions to the Arbitrum network, leaving affected users without their stablecoins.

Security advice following the breach

GoPlus Security urged users to promptly revoke any ongoing authorizations on wallets connected to x402bridge and verify authorized addresses carefully before approving new transactions.

The firm advised, “Only authorize the necessary amount and never provide unlimited access to contracts,” emphasizing the importance of regularly reviewing wallet permissions to prevent further losses.

Growing usage of the x402 protocol before the hack

The 402bridge hack comes amidst a period of rapid adoption for the x402 protocol, which experienced a surge in market value, surpassing $800 million. Coinbase’s x402 protocol recently recorded 500,000 transactions in a single week, marking a 10,780% increase from the previous month.

The protocol facilitates instant, automated payments for APIs and digital content using HTTP 402 Payment Required status codes.

Causes and investigation of the exploit

Blockchain security experts like SlowMist concluded the hack most likely resulted from a private key leak but did not exclude possible insider involvement.

The 402bridge team confirmed the private key leak compromised multiple test and main wallets.

“We have promptly reported the incident to law enforcement authorities and will keep the community updated,” the official statement read, as the team investigates the breach’s full scope.

Technical explanation of the vulnerability

The x402 mechanism requires storing private keys on backend servers to call contract methods after users authorize transactions via the web interface.

This backend architecture means the admin private key remains connected online, creating a risk of leakage. If stolen, hackers can assume full admin privileges, enabling them to redirect user funds arbitrarily  precisely what occurred in this hack.

Tags: . crypto newsblockchain bridgeBlockchain Securityblockchain technologyCrypto Exchangecrypto hackcrypto investigationCrypto theftcrypto walletscyber attackcybersecurityDeFi exploitsDeFi Securitydigital assetshacker attackprivate key leaksmart contract vulnerabilitywallet breachweb3 securityx402bridge hack
Share197Tweet123
Sania Arain

Sania Arain

Hello! I’m Sania, a professional freelance content writer with 4 years of experience, specializing in cryptocurrency news and blockchain content. I craft accurate, engaging, and SEO-optimized articles that keep readers informed about the latest trends and developments in the crypto industry My expertise lies in translating complex crypto topics into clear, reader-friendly content that drives engagement and adds value for businesses and platforms alike.

  • Trending
  • Comments
  • Latest
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated On 07/23/2025
FBI nabs Nigerian ‘tech queen’ Sapphire Egemasi in multi-million dollar fraud scheme

FBI arrests Nigerian ‘tech queen’ Sapphire Egemasi in $1.3M heist targeting U.S. government

06/05/2025 - Updated On 06/17/2025
Crypto investor and wife found dead in Dubai as police investigate possible link to digital assets

Crypto investor and wife found dead in Dubai as police investigate possible link to digital assets

11/08/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Netflix director faces 90 years for allegedly diverting $11M into luxury purchases and crypto

Carl Erik Rinsch convicted of defrauding Netflix of $11 million for personal spending, crypto trades

12/14/2025
HSBC Tokenized Deposit trial enables real-time cross-border payments

HSBC completes tokenized deposit pilot for real-time cross-border payments with Swift

12/13/2025
Citadel SEC Bid Ignites Powerful Industry Backlash as DeFi Leaders Warn of Centralization Risk

Crypto groups challenge Citadel’s call for SEC oversight of DeFi tokenized stocks

12/13/2025
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?