Revoke.cash logo

402bridge Hack / Rug Pull

Check if your address is affected.

27 Oct 2025
$21k stolen
Base Logo

402bridge was a payment protocol on Base built on x402, a standard from Coinbase that lets apps and AI agents pay for online services with stablecoins. To use it, people approved the 402bridge contract to spend their USDC, and the contract gave its admin the power to move USDC from any wallet that had approved it. On 27 October 2025, about 13 hours after the contract went live, the admin private key ended up in the wrong hands. The attacker took control of the contract and started draining approved USDC.

Roughly $18k in USDC was taken within about half an hour, and smaller drains continued over the following weeks, bringing the total to about $21k. The attacker swapped the stolen USDC for ETH and moved it to Arbitrum. On 28 October 2025, 402bridge said the key had leaked because it was stored on a server so the service could call the contract, that several team wallets were also compromised, and that it had reported the incident to law enforcement. Its website then went offline.

Because the team shared very little after the incident, some in the community suspected a rug pull rather than an outside hack. SlowMist founder Yu Xian said insider involvement could not be ruled out, although he did not see it as a typical rug pull. Since the attacker took over the contract and kept draining wallets for weeks, any USDC approval to it is still dangerous. If you ever used 402bridge on Base, revoke that approval, even if your wallet holds no USDC today.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits