Skip to content
Crypto News Today

Analysts Flag Security Gaps in Standard Chartered-Backed Stablecoin

Analysts Flag Security Gaps in Standard Chartered-Backed Stablecoin
  • Security researcher Yajin Zhou published a review finding that HKDAP, a Hong Kong dollar stablecoin backed by Standard Chartered, runs on a contract that is not production-ready.
  • The review found the token’s KYC revocation controls fail open, meaning deregistered verifiers and their approved wallets can keep transacting.
  • HKDAP remains in a beta phase limited to institutional distributors, with retail access planned as early as the end of 2026.

A security review published by researcher Yajin Zhou has flagged multiple issues in the smart contract behind HKDAP, a Hong Kong dollar-backed stablecoin that Standard Chartered-backed Anchorpoint Financial launched on August 12. 

Contents

Ethereum trades near $1,891 as of this writing, as HKDAP settles on the Ethereum mainnet, which lets Zhou’s team inspect its verified source code directly on Etherscan.

Ethereum price performance

A Contract That Is Not Production Ready

Zhou’s team checked two things. First, whether the code was correctly written for real-world use and second, whether its on-chain behavior matched the Hong Kong Monetary Authority’s rules for licensed stablecoin issuers. The review, published on X, concluded no on both counts.

The most serious finding centers on governance. A single key can mint new tokens, freeze accounts, pause the entire system, and force a burn, with no time lock delaying any of those actions for review. The review said this concentration of control clashes with specific clauses in the HKMA’s own guidelines for how licensed issuers are supposed to operate.

This isn’t a story about one flawed stablecoin launch. It’s about whether a beta label is enough cover for a contract that regulators expect to meet production standards before real users touch it.

Compliance Controls That Do Not Work As Written

The review’s second major finding concerns HKDAP’s Know Your Customer system. The token’s revocation function, meant to cut off wallets once a KYC provider is deregistered, does not work as coded. 

In practice, if a verifier loses its approval, the wallets it previously cleared can keep transacting anyway. Zhou’s team also found that KYC proofs are never validated on chain, meaning a deregistered verifier could still approve new users after the fact. The review attributed most of the flaws to custom code built instead of relying on well-tested, widely audited standards, and said the beta access label does not close that gap.

HKDAP carries significant institutional weight behind it. Anchorpoint is a joint venture between Standard Chartered Bank Hong Kong, telecom operator HKT, and Web3 firm Animoca Brands. It was one of two firms, alongside HSBC, to win a stablecoin issuer license from the HKMA in April, chosen from 36 applicants under Hong Kong’s Stablecoins Ordinance. 

Anchorpoint CEO Dominic Maffei has described the current rollout as prudent and structured, with HashKey Exchange serving as the first authorized distributor able to mint and redeem the token. Retail access is planned as early as the end of 2026, subject to market conditions, though the current phase remains limited to institutional distributors and professional investors.

Coinscipher covered a related security failure in our reporting on the Coinsbuy wallet hack earlier this month, and this review adds to a pattern of security researchers catching design flaws in new financial products before they reach a wider user base rather than after.

Sources: