# PIR-2026-0037 - 402Bridge private-key leak drains USDC approvals from 227 wallets in the x402 agent-payment ecosystem

- `id`: PIR-2026-0037
- `title`: Leaked admin key lets attacker seize the 402Bridge contract and drain $17,693 in USDC from 227 approving wallets in ~28 minutes
- `date_occurred`: 2025-10-27/28 (sources split between Oct 27 UTC and "early morning Oct 28" in UTC+8 community alerts; drain window ~28 minutes - see Verification notes)
- `date_detected`: same night (GoPlus community alert on abnormal transfers)
- `date_disclosed`: 2025-10-28 (team confirmation + security-firm analyses)
- `status`: corroborated (on-chain record + team confirmation + independent analyses)

### The agent
- `agent_description`: 402Bridge, a third-party cross-chain bridge serving Coinbase's x402 agentic-payment ecosystem; users and agents had granted the bridge contract USDC spending approvals. Boundary case: no LLM in the failure path - the failure sits in payment infrastructure that agent workflows depend on.
- `operator_type`: startup (small third-party team)
- `autonomy_level`: n/a (no agent autonomy in the failure path)
- `model_stack`: none
- `harness`: n/a (smart contract + admin key custody)

### Authority
- `authority_scope`: funds (USDC approvals from every wallet that had authorized the contract; the admin key controlled contract ownership)
- `funds_at_risk_usd`: all outstanding user approvals (unquantified; realized subset was $17,693)
- `blast_radius`: customers/third parties (227 user wallets)

### The failure
- `root_cause`: credential-exposure (primary; admin private key); contributing operator-error (key custody + permission design that let an ownership transfer unlock `transferUserToken` against user approvals)
- `failure_locus`: dependency (third-party infrastructure in the agent-payment stack, not agent reasoning)
- `mechanism`: The project's private keys leaked - the team confirmed more than a dozen test and main wallets were compromised. The attacker used the leak to transfer ownership of the bridge contract to their own address, then called `transferUserToken` against every wallet with an active approval, draining $17,693 in USDC from 227 wallets in ~28 minutes before swapping to ETH and bridging to Arbitrum. SlowMist attributed the breach to key leakage plus permission mismanagement and explicitly could not rule out an insider.
- `adversary_present`: yes
- `exploitation_status`: in-wild-exploited

### Impact
- `severity`: loss
- `direct_loss_usd`: 17,693 (on-chain, consistent across sources)
- `indirect_loss_usd`: unknown (project defunct; user approval-revocation effort)
- `downtime`: total - project halted all operations; website went offline
- `data_exposure`: none (funds only)

### Detection and recovery
- `detected_by`: automated-monitor / third-party (GoPlus community alert; SlowMist post-incident analysis)
- `time_to_detect`: hours at most (alert the same night as the drain)
- `time_to_recover`: no recovery - funds not returned; team reported to authorities
- `remediation`: operations halted; users urged to revoke approvals
- `structural_fix`: none from the project (defunct); ecosystem takeaway is approval hygiene for agent-payment contracts
- `controls_that_worked`: third-party on-chain monitoring surfaced the drain fast; nothing bounded the loss by design - the ceiling was the small scale of outstanding approvals, which is luck, not a control

### Legal
- `liability_holder`: 402Bridge team (self-acknowledged key-custody failure; insider question open); no known proceedings beyond the team's report to authorities
- `precedent_set`: none
- `sealed_material`: no

### Evidence
- `telemetry_grade`: append-only (on-chain record of the drain and fund movement; team/firm narratives layered on top)
- `sources`:
  - https://crypto.news/402bridge-hack-leads-to-over-200-users-drained-of-usdc/ (independent)
  - https://protos.com/402bridge-private-key-leaks-227-wallets-drained-in-minutes/ (independent)
  - https://forklog.com/en/402bridge-loses-over-17000-usdc/ (independent)
  - https://www.panewslab.com/en/articles/17ffaa3c-2beb-4cd3-b95c-33e26af7567c (SlowMist statement)
  - https://superex.medium.com/the-explosion-of-the-x402-protocol-and-the-402bridge-security-incident-an-in-depth-analysis-of-12c909bed5f1 (analysis)
  - `independence`: good - multiple outlets plus two security firms; team statements corroborate.
- `confidence`: high on figures and mechanism (on-chain); medium on attribution (external leak vs insider unresolved)

### Verification notes
1. Date corrected from a flat 2025-10-28 to 2025-10-27/28: ForkLog and others date the attack Oct 27, while first alerts are timestamped "early morning Oct 28" in UTC+8 community channels - a timezone artifact the candidate record flattened. Stated as a range with the conflict named.
2. The candidate's claim that the incident preceded a ~77% collapse in x402 volume from a Nov 2025 peak was not independently verified here and is omitted.
3. Added SlowMist's explicit refusal to rule out an insider; the candidate carried only "private-key-leak attribution is from post-incident analyses."
