HKDAP Stablecoin Review Exposes Compliance Control Flaws
A review of Anchorpoint's HKDAP stablecoin has flagged several broken compliance controls. The security analysis, led by Yajin Zhou, found that the Ethereum contract powering HKDAP is not production-ready and contains Know-Your-Customer (KYC) and revocation controls that do not function as coded.
The review discovered that a single key can perform high-risk actions, including minting new tokens, freezing accounts, pausing the system, and forced burning. The contract also lacks a time-lock, which is a common feature that delays actions for review. Additionally, the compliance controls meant to block unauthorized users do not work as intended.
The KYC module, designed to stop users who are no longer approved, has a broken revocation function. Analysts found that if a KYC provider is de-registered, the wallets they approved can still transact. Furthermore, KYC proofs are not validated on-chain, and deregistered verifiers can still approve new users.