PANews
PANews|11月 12, 2025 00:56
[GoPlus: Risks of Unlimited Minting and Centralized Manipulation in the Hello 402 Contract] The GoPlus Chinese community disclosed on the X platform that the Hello 402 contract contains some relatively hidden risks—unlimited minting and centralized manipulation concerns. 1. The administrator address has extremely high permissions, fully controlling the minting and distribution of H402 tokens. For example: - The `addTokenCredits` function allows the administrator to allocate H402 token minting shares to users without checking whether it exceeds the `MAX_SUPPLY` total, effectively creating a backdoor for unlimited minting. - The `redeemTokenCredits` function enables users to mint H402 tokens based on their allocated shares. - The `WithdrawDevToken` function permits the administrator address to mint all unallocated shares at once, posing a high risk of centralized manipulation. 2. The project team stated on X that the `WithdrawDevToken` function is intended solely for purposes such as "token replenishment," "ecosystem incentives," and "profit margins" after the private sale ends. However, none of these promises have been specifically implemented at the contract level, leading to a high risk of centralized breach of trust. In related news yesterday, OKX announced that it has launched an investigation into the abnormal behavior of Hello 402 and will continue to track on-chain evidence while reserving the right to take legal action.
+4
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads