PANews reported on October 28th that the GoPlus Chinese community issued a security alert regarding a suspected theft of the x402 cross-chain protocol @402bridge. The creator of the contract starting with 0xed1A transferred the owner to the address 0x2b8F. The new owner then called the contract's transferUserToken method to transfer all remaining USDC from authorized user wallets. Before minting, USDC must be authorized to the @402bridge contract. This resulted in over 200 users having their remaining USDC transferred due to excessive authorization. A total of 17,693 USDC was transferred from the 0x2b8F address, which was then converted to ETH and transferred to Arbitrum through multiple cross-chain transactions.
It is recommended that users who have participated in the project cancel the relevant authorization as soon as possible; remind users to check whether the authorization address is the official address of the interactive project before authorization, only authorize the required amount, and never authorize unlimitedly; and pay attention to regularly check the authorization and cancel useless authorization.


