Skip to main content
Sign in

402bridge

avoid.net/402bridge18/100·78% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]
anchored·668xNk…TdRm

Summary

402bridge (also written x402bridge) was a short-lived cross-chain bridge protocol built on the x402 HTTP payment standard, operating at 402bridge.fun. On October 28, 2025, approximately 13 hours after deployment, an attacker exploited a leaked admin private key to drain $17,693 in USDC from 227 user wallets in under 30 minutes; the protocol ceased operations immediately afterward and no user compensation has been announced. Security firm SlowMist noted that while the incident appeared consistent with a private key leak, the possibility of insider involvement could not be ruled out.

Connected Entities

1 entities
Organizations
402bridge
Relationships
    Have evidence about 402bridge?

    Timeline(10 events)

    2025-10-26

    402bridge.fun domain registered, approximately two days before the protocol ceased service.

    2025-10-28

    402bridge protocol deployed on-chain; users began granting USDC allowances to contract 0xed1AFc4DCfb39b9ab9d67f3f7f7d02803cEA9FC5 in preparation for minting.

    2025-10-28

    Approximately 13 hours after deployment, admin private key compromised. Contract ownership transferred to attacker address 0x2b8F95560b5f1d1a439dd4d150b28FAE2B6B361F.

    2025-10-28

    Attacker calls transferUserToken function, draining 17,693 USDC from 227 user wallets within 28 minutes. Stolen USDC converted to ETH and bridged to Arbitrum.

    2025-10-28

    GoPlus Security Chinese community issues first public alert about abnormal asset transfers from x402bridge.

    2025-10-28

    PeckShield issues advisory urging users to revoke USDC allowances to the compromised contract.

    2025-10-28

    402bridge team publishes statement on X confirming private key leak, reporting to law enforcement, and acknowledging team wallets were also compromised.

    2025-10-28

    SlowMist's Yu Xian (Cosine) states the attack was caused by private key leakage and notes insider involvement cannot be ruled out; characterizes this as the first publicly known theft linked to x402 protocol services.

    2025-10-28

    402bridge.fun website taken offline. Protocol ceases operations.

    2025-11-17

    GoPlus Security publishes audit findings covering 30+ x402 ecosystem projects, finding the majority had at least one high-risk vulnerability; references 402bridge as the catalyst for the broader ecosystem security review.

    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.

    model: claude-sonnet-4-6

    generated: 5/4/2026, 2:54:20 AM

    last updated: 5/29/2026, 5:14:48 PM

    avoid.net — verified advice for a post-truth world