Security Audit Flags High-Risk Reentrancy and Access Control Flaws in Paxos Gold
A security audit of Paxos Gold (PGX), a regulated gold-backed token protocol with roughly $1.91 billion in total value locked, identified critical vulnerabilities across its smart contracts as of August 30, 2026. The most serious flaw lies in the PGXBridge withdrawal function, where an external call is made to a user-supplied address before the withdrawal nonce is updated, enabling a classic reentrancy attack that could allow double-spending of gold-backed tokens. On the access control side, the PGXController contract allows any address to nominate a pending owner without restriction, and the proxy upgrade function is guarded by a multisig key that has not been rotated since launch. Additionally, the PAUSER_ROLE is delegated to a single external contract, PGXStaking, which itself carries upgrade-path risks that could allow an attacker to seize pause privileges. Auditors rated the combined risk at 8 out of 10, warning that a coordinated exploit could break the protocol's 1:1 gold peg, freeze user funds, or enable a rug-pull scenario.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in