GoPlus Security identified abnormal authorizations in 402bridge, resulting in over 200 users losing USDC, highlighting ongoing risks in cross-chain protocol operations.
GoPlus Security reported that unusual authorizations in the 402bridge cross-chain protocol led to losses of USDC from more than 200 user wallets. This incident followed a transfer of contract ownership to address 0x2b8F, after which 17,693 USDC was withdrawn, converted to ETH, and moved to Arbitrum. The web3 security firm has urged users to revoke excessive token approvals to mitigate potential exploitation risks.