Invest1 distinct publisher3 min readUpdated
Analyst Yajin Zhou's team says the KYC and revocation controls in Anchorpoint's live HKDAP contract do not work as coded. The contract is verified on Etherscan, so anyone can check.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Analyst Yajin Zhou's team says the KYC and revocation controls in Anchorpoint's live HKDAP contract do not work as coded. The contract is verified on Etherscan, so anyone can check.
A review published by security analyst Yajin Zhou and his team says HKDAP, the Hong Kong dollar stablecoin issued by Standard Chartered-backed Anchorpoint, runs on an Ethereum contract that is not production-ready and carries KYC and revocation controls that do not work as coded [1]. That matters less as a bug report than as a precedent: the review leans on the fact that HKDAP settles on Ethereum mainnet with its source verified on Etherscan, so the token is directly inspectable [3].
Zhou's team asked two questions, whether the code is correct and ready for real-world use, and whether its on-chain behaviour follows the HKMA's official rules for stablecoin issuers. According to the review, the answer to both was no [4].
The specifics are unglamorous and consequential. The KYC module's revocation function is broken, so if a KYC provider is de-registered, the wallets it approved can still transact [5]. KYC proofs are not validated on-chain, and de-registered verifiers can still approve new users [6]. The review's summary is that these controls fail open [7]. On governance, a single key can mint new tokens, freeze accounts, pause the system and force burns, and the contract has no time-lock to delay high-risk actions for review [8]. The review says the contract "clashes with specific clauses" in the HKMA regulations [9]. It also found that the contract rebuilds basic security features rather than using well-tested code, that most of the bugs sit in that custom code, and that the "Beta Access" label does not close the gap [10].
The institutional weight behind the token is the point. Anchorpoint Financial is a subsidiary of Standard Chartered Bank (Hong Kong) and a joint venture with HKT and Animoca Brands [11]. In April it became one of the first two firms, alongside HSBC, to win a stablecoin issuer licence from the HKMA, out of 36 applications under the Stablecoins Ordinance that took effect on 1 August 2025 [12]. Anchorpoint holds licence number FRS01 [13]. Two licences from 36 applications is an approval rate of about 6 percent, which is the scarcity that gives the licence its signalling value [14].
The rollout began on 12 August, dated in the source's own FAQ to 2026, and is currently beta access for institutional distributors and professional investors, with HashKey Exchange the first authorised distributor to mint and redeem [2][15]. Chief executive Dominic Maffei has called the rollout "prudent and structured", with retail access flagged as early as end-2026 subject to market conditions [16]. The findings therefore land in beta, before any retail exposure [17].
The operator takeaway is not that a beta contract has bugs. It is that a bank-backed licensee's compliance posture is now a public artifact that a small research team can read line by line, and that the gap between a regulator's guideline and a deployed function is measurable by outsiders rather than asserted by issuers.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
A review published by security analyst Yajin Zhou says HKDAP runs on an Ethereum contract that is not production-ready and has KYC and revocation controls that do not work as coded. HKDAP is a Hong Kong dollar stablecoin launched by Standard Chartered-backed Anchorpoint.
Anchorpoint launched HKDAP on August 12; the article's FAQ dates the first rollout phase to August 12, 2026.
The reviewers note that because HKDAP settles on Ethereum mainnet and its source is verified on Etherscan, the token is directly inspectable.
The analysts checked whether the code is correct and ready for real-world use, and whether its on-chain behaviour follows the HKMA's official rules for stablecoin issuers; the answer to both questions was no.
The KYC module, which should stop users who are no longer approved, has a broken revocation function: if a KYC provider is de-registered, the wallets they approved can still transact.
Analysts found that KYC proofs are not validated on-chain and that deregistered verifiers can still approve new users.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet relaying one unlinked review
The technical findings are attributed and specific, and the artefact they concern is publicly verifiable on Etherscan, which raises the ceiling on checkability. But the cluster contains a single publisher, the review itself is not supplied or linked, no methodology, severity ranking or disclosure timeline is given, and no issuer, distributor or regulator response appears. The named regulatory-conflict claim cites no clause.
Live but gated institutional beta
HKDAP is genuinely deployed on Ethereum mainnet under HKMA licence FRS01 and has at least one authorised distributor minting and redeeming, which is more than a pilot announcement. Usage remains capped at institutional distributors and professional investors with retail only targeted for end-2026, and no supply, reserve or transaction figures are disclosed, so measurable uptake is thin.
Severity framing ahead of verification
Framing such as 'broken compliance controls', 'not production-ready' and conflict with HKMA rules is strong relative to the evidence base: one outlet, one unlinked review, no exploit, loss or enforcement reported, and no issuer or regulator rebuttal. The gap is modest rather than large because the defects described are concrete, the contract is publicly inspectable, and the article correctly notes the product is still in beta with no retail exposure.
Reputational and promotional pulls on both sides
Sourcing sits with a named security researcher whose visibility benefits from publishing findings against a high-profile bank-backed issuer, while the only issuer voice in the piece is a CEO quote framing the rollout as 'prudent and structured' ahead of a retail launch. The publisher is a crypto-trade outlet that closes with a newsletter solicitation and an investment disclaimer. None of these are disqualifying, but no disclosure of the reviewer's commercial relationships, audit engagements or positions is supplied.
Plausible and specific, but unconfirmed
Confidence is limited by single-publisher sourcing, an absent primary document, and no response from issuer, distributor or regulator. It is not lower because the claims are falsifiable against a verified public contract, the corporate, licensing and distribution facts are internally consistent, and the derived approval-rate figure checks out against the article's own numbers.
invest
Tokenized stocks hit $2.7 billion, and the venue with the users is winning1 distinct publisher
invest
Solana added $378M in tokenized Treasuries while the whole market grew about $289M1 distinct publisher
invest
Robinhood Chain's first month: a stock-token network that traded cats1 distinct publisher
build
The $559M-versus-$12.3B quarter matters more than the $65B run rate4 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 14, 2026