Scan to download
BTC $67,240.22 +0.52%
ETH $2,063.04 +0.53%
BNB $593.60 +1.03%
XRP $1.31 -0.21%
SOL $80.72 +0.62%
TRX $0.3172 +0.68%
DOGE $0.0919 +0.65%
ADA $0.2483 +0.84%
BCH $440.56 -0.67%
LINK $8.69 +0.63%
HYPE $36.24 +1.97%
AAVE $94.43 -0.32%
SUI $0.8702 -0.16%
XLM $0.1618 -0.55%
ZEC $250.59 +7.10%
BTC $67,240.22 +0.52%
ETH $2,063.04 +0.53%
BNB $593.60 +1.03%
XRP $1.31 -0.21%
SOL $80.72 +0.62%
TRX $0.3172 +0.68%
DOGE $0.0919 +0.65%
ADA $0.2483 +0.84%
BCH $440.56 -0.67%
LINK $8.69 +0.63%
HYPE $36.24 +1.97%
AAVE $94.43 -0.32%
SUI $0.8702 -0.16%
XLM $0.1618 -0.55%
ZEC $250.59 +7.10%

GoPlus: Discover multiple x402 ecosystem projects with risks, including excessive authorization, signature replay, etc

2025-11-17 18:16:57
Collection

According to official news, GoPlus Security Research Institute conducted a detailed security risk scan on more than 30 x402 projects and community-reported risk projects in Binance Wallet and OKX Wallet, discovering that the following projects have issues such as excessive authorization, signature replay, HonyPot (PiXiu token), and unlimited issuance risks.

FLOCK (0x5ab3): The transfer ERC20 function allows the owner to withdraw any amount of any token from the contract. x420 (0x68e2): The cross chain Mint function can mint tokens without restriction. U402 (0xd2b3): The mint By Bond function allows unlimited minting of coins. MRDN (0xe57e): The withdraw Token function allows the owner to withdraw any amount of any token from the contract. PENG (0x4444ee, 0x444450, 0x444428): The manual Swap function allows the owner to withdraw ETH from the contract, and the transfer From function bypasses the allowance check for special accounts. x402 Token (0x40ff): The transfer From function bypasses the allowance check for special accounts. x402b (0xd8af5f): The manual Swap function allows the owner to withdraw ETH from the contract, and the transfer From function bypasses the allowance check for special accounts. x402MO (0x3c47df): The manual Swap function allows the owner to withdraw ETH from the contract, and the transfer From function bypasses the allowance check for special accounts.

app_icon
ChainCatcher Building the Web3 world with innovations.