According to PANews, a security alert has been issued by the GoPlus Chinese community regarding a potential theft involving the x402 cross-chain protocol, known as @402bridge. The creator of the contract, starting with 0xed1A, transferred ownership to the address 0x2b8F. The new owner then used the transferUserToken method within the contract to move the remaining USDC from all authorized user wallets. Before minting, users were required to authorize USDC to the @402bridge contract, which led to over 200 users losing their remaining USDC due to excessive authorization. A total of 17,693 USDC was transferred to the 0x2b8F address, which was then converted to ETH and moved through multiple cross-chain transactions to Arbitrum.
Users who participated in this project are advised to promptly revoke related authorizations. It is recommended that users verify the authorization address to ensure it is the official project address before granting permissions, authorize only the necessary amount, and avoid unlimited authorizations. Regular checks on authorizations and the cancellation of unnecessary ones are also advised.