Skip to main content
AVOID.NET

402bridge

avoid.net/402bridge18/100·78% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·668xNk…TdRm

Summary

402bridge (also written x402bridge) was a short-lived cross-chain bridge protocol built on the x402 HTTP payment standard, operating at 402bridge.fun. On October 28, 2025, approximately 13 hours after deployment, an attacker exploited a leaked admin private key to drain $17,693 in USDC from 227 user wallets in under 30 minutes; the protocol ceased operations immediately afterward and no user compensation has been announced. Security firm SlowMist noted that while the incident appeared consistent with a private key leak, the possibility of insider involvement could not be ruled out.

Connected Entities

3 entities · 60 linked investigations
Organizations
402bridgeArbitrum52
Tokens
Relationships
  • 402bridgementioned withCoinbase(65%)
  • 402bridgementioned withArbitrum(70%)
  • Arbitrummentioned withCoinbase(65%)

Connected Through

2 shared actors · 418 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about 402bridge?

Timeline(10 events)

26 October 2025

402bridge.fun domain registered, approximately two days before the protocol ceased service.

28 October 2025

402bridge protocol deployed on-chain; users began granting USDC allowances to contract 0xed1AFc4DCfb39b9ab9d67f3f7f7d02803cEA9FC5 in preparation for minting.

28 October 2025

Approximately 13 hours after deployment, admin private key compromised. Contract ownership transferred to attacker address 0x2b8F95560b5f1d1a439dd4d150b28FAE2B6B361F.

28 October 2025

Attacker calls transferUserToken function, draining 17,693 USDC from 227 user wallets within 28 minutes. Stolen USDC converted to ETH and bridged to Arbitrum.

28 October 2025

GoPlus Security Chinese community issues first public alert about abnormal asset transfers from x402bridge.

28 October 2025

PeckShield issues advisory urging users to revoke USDC allowances to the compromised contract.

28 October 2025

402bridge team publishes statement on X confirming private key leak, reporting to law enforcement, and acknowledging team wallets were also compromised.

28 October 2025

SlowMist's Yu Xian (Cosine) states the attack was caused by private key leakage and notes insider involvement cannot be ruled out; characterizes this as the first publicly known theft linked to x402 protocol services.

28 October 2025

402bridge.fun website taken offline. Protocol ceases operations.

17 November 2025

GoPlus Security publishes audit findings covering 30+ x402 ecosystem projects, finding the majority had at least one high-risk vulnerability; references 402bridge as the catalyst for the broader ecosystem security review.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 14 of 16 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/4/2026, 2:54:20 AM

last updated: 8/29/2026, 6:16:46 PM

6 views

avoid.net — verified advice for a post-truth world