Invest1 publisher3 min readPublished
A code review just made HKMA stablecoin compliance an on-chain question
Analyst Yajin Zhou's team says the KYC and revocation controls in Anchorpoint's live HKDAP contract do not work as coded. The contract is verified on Etherscan, so anyone can check.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- A review published by security analyst Yajin Zhou says HKDAP runs on an Ethereum contract that is not production-ready and has KYC and revocation controls that do not work as coded. HKDAP is a Hong Kong dollar stablecoin launched by Standard Chartered-backed Anchorpoint.
- Anchorpoint launched HKDAP on August 12; the article's FAQ dates the first rollout phase to August 12, 2026.
- The reviewers note that because HKDAP settles on Ethereum mainnet and its source is verified on Etherscan, the token is directly inspectable.
- The analysts checked whether the code is correct and ready for real-world use, and whether its on-chain behaviour follows the HKMA's official rules for stablecoin issuers; the answer to both questions was no.
- The KYC module, which should stop users who are no longer approved, has a broken revocation function: if a KYC provider is de-registered, the wallets they approved can still transact.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
A review published by security analyst Yajin Zhou and his team says HKDAP, the Hong Kong dollar stablecoin issued by Standard Chartered-backed Anchorpoint, runs on an Ethereum contract that is not production-ready and carries KYC and revocation controls that do not work as coded [1]. That matters less as a bug report than as a precedent: the review leans on the fact that HKDAP settles on Ethereum mainnet with its source verified on Etherscan, so the token is directly inspectable [3].
Zhou's team asked two questions, whether the code is correct and ready for real-world use, and whether its on-chain behaviour follows the HKMA's official rules for stablecoin issuers. According to the review, the answer to both was no [4].
The specifics are unglamorous and consequential. The KYC module's revocation function is broken, so if a KYC provider is de-registered, the wallets it approved can still transact [5]. KYC proofs are not validated on-chain, and de-registered verifiers can still approve new users [6]. The review's summary is that these controls fail open [7]. On governance, a single key can mint new tokens, freeze accounts, pause the system and force burns, and the contract has no time-lock to delay high-risk actions for review [8]. The review says the contract "clashes with specific clauses" in the HKMA regulations [9]. It also found that the contract rebuilds basic security features rather than using well-tested code, that most of the bugs sit in that custom code, and that the "Beta Access" label does not close the gap [10].
The institutional weight behind the token is the point. Anchorpoint Financial is a subsidiary of Standard Chartered Bank (Hong Kong) and a joint venture with HKT and Animoca Brands [11]. In April it became one of the first two firms, alongside HSBC, to win a stablecoin issuer licence from the HKMA, out of 36 applications under the Stablecoins Ordinance that took effect on 1 August 2025 [12]. Anchorpoint holds licence number FRS01 [13]. Two licences from 36 applications is an approval rate of about 6 percent, which is the scarcity that gives the licence its signalling value [14].
The rollout began on 12 August, dated in the source's own FAQ to 2026, and is currently beta access for institutional distributors and professional investors, with HashKey Exchange the first authorised distributor to mint and redeem [2][15]. Chief executive Dominic Maffei has called the rollout "prudent and structured", with retail access flagged as early as end-2026 subject to market conditions [16]. The findings therefore land in beta, before any retail exposure [17].
The operator takeaway is not that a beta contract has bugs. It is that a bank-backed licensee's compliance posture is now a public artifact that a small research team can read line by line, and that the gap between a regulator's guideline and a deployed function is measurable by outsiders rather than asserted by issuers.