金色财经|11月 17, 2025 10:37
Security Research Institute: Multiple x402 ecological projects have been found to have risks, including excessive authorization, signature replay, etc
On November 17th, GoPlus Security Research Institute conducted a detailed security risk scan of over 30 x402 projects and community warning risk projects in Binance Wallet and OKX Wallet, and found that the following projects have risks of excessive authorization, signature replay, HonyPot (Pixiu token), and unlimited issuance.
FLOCK (0x5ab3): The transferERC20 function owner can extract any number of arbitrary tokens from the contract.
X420 (0x68e2): The crosschainMint function allows unlimited token minting.
U402 (0xd2b3): The mintByBond function bond allows unlimited coinage.
MRDN (0xe57e): The withdrawToken function owner can extract any number of arbitrary tokens from the contract.
PENG (0x4444ee, 0x444450, 0x444428): The manualSwap function owner can extract ETH from the contract, while the transferFrom function bypasses the allowance check for special accounts.
X402Token (0x40ff): The transferFrom function will bypass the allowance check for special accounts.
X402b (0xd8af5f): The manualSwap function owner can extract ETH from the contract, while the transferFrom function bypasses the allowance check for special accounts.
X402MO (0x3c47df): The manualSwap function owner can extract ETH from the contract, while the transferFrom function bypasses the allowance check for special accounts.
Share To
HotFlash
APP
X
Telegram
CopyLink