GoPlus: Multiple early x402 projects have high-risk vulnerabilities, including excessive authorization, signature replay, honeypot traps, and unlimited minting.

robot
Abstract generation in progress

According to Deep Tide TechFlow news, on November 17, a report by GoPlus Security revealed that the agency conducted security risk scans on over 30 x402 ecological projects and found multiple projects with serious security vulnerabilities.

The scan results indicate that the main risk types include excessive authorization, signature replay, honeypot traps, and infinite minting, among others. Specifically, the transferERC20 function of the FLOCK project allows the owner to withdraw any amount of tokens from the contract; the crosschainMint function of the x420 project allows for unlimited minting; and the manualSwap function of the PENG project permits the owner to withdraw ETH from the contract.

Several security incidents have occurred previously, including an excessive authorization vulnerability attack on @402bridge on October 28, resulting in the malicious transfer of USDC from over 200 user accounts; on November 12, Hello402 faced infinite minting and liquidity issues.

FLOCK-2.26%
PENG-0.08%
ETH-1.05%
USDC0.01%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)