PANews丨APP全面升级|Nov 17, 2025 10:33
GoPlus: Discovered multiple risks in x402 ecosystem projects, including over-authorization, signature replay, and more.
According to official reports, the GoPlus Security Research Institute conducted a detailed security risk scan on over 30 x402 projects in Binance Wallet and OKX Wallet, as well as community-reported risk projects. The following projects were found to have risks such as over-authorization, signature replay, HonyPot (Pi Xiu tokens), and unlimited minting:
FLOCK (0x5ab3): The transferERC20 function allows the owner to withdraw any amount of any token from the contract.
x420 (0x68e2): The crosschainMint function allows unlimited token minting.
U402 (0xd2b3): The mintByBond function allows unlimited token minting via bond.
MRDN (0xe57e): The withdrawToken function allows the owner to withdraw any amount of any token from the contract.
PENG (0x4444ee, 0x444450, 0x444428): The manualSwap function allows the owner to withdraw ETH from the contract, and the transferFrom function bypasses allowance checks for specific accounts.
x402Token (0x40ff): The transferFrom function bypasses allowance checks for specific accounts.
x402b (0xd8af5f): The manualSwap function allows the owner to withdraw ETH from the contract, and the transferFrom function bypasses allowance checks for specific accounts.
x402MO (0x3c47df): The manualSwap function allows the owner to withdraw ETH from the contract, and the transferFrom function bypasses allowance checks for specific accounts.
Share To
HotFlash
APP
X
Telegram
CopyLink