Analysts flag broken compliance controls in Anchorpoint's live HKDAP stablecoin

A review published by security analyst Yajin Zhou says HKDAP runs on an Ethereum contract that is not production-ready, and has Know-Your-Customer (KYC) and revocation controls that do not work as coded.
HKDAP is a Hong Kong dollar stablecoin that Standard Chartered-backed Anchorpoint launched on August 12.
What’s wrong with HKDAP’s rules?
The security analyst Yajin Zhou and his team have published a review on HKDAP. In it, they lean on the fact that because HKDAP settles on Ethereum mainnet and its source is verified on Etherscan, the token is directly inspectable.
The analysts checked whether the code is correct and ready for real-world use, and whether its on-chain behavior follows the HKMA’s official rules for stablecoin issuers. The answer to both questions was no.
The contract, as of the time of writing, has several functional flaws, one of which is that its governance is too centralized.
A single key can carry out high-risk actions, including minting new tokens, freezing accounts, pausing the system, and forced burning. The contract also lacks a time-lock, which is a common feature that delays actions for review. The review also said the contract “clashes with specific clauses” in the HKMA regulations.
… Continue reading the full article at the original source below.



