Charts
DataOn-chain
VIP
Market Cap
API
Rankings
CoinOSNew
CoinClaw🦞
Language
  • 简体中文
  • 繁体中文
  • English
Leader in global market data applications, committed to providing valuable information more efficiently.

Features

  • Real-time Data
  • Special Features
  • AI Grid

Services

  • News
  • Open Data(API)
  • Institutional Services

Downloads

  • Desktop
  • Android
  • iOS

Contact Us

  • Chat Room
  • Business Email
  • Official Email
  • Official Verification

Join Community

  • Telegram
  • Twitter
  • Discord

© Copyright 2013-2026. All rights reserved.

简体繁體English
|Legacy

CrossCurve Threatens Legal Action After $3M Cross-Chain Bridge Exploit

CN
Decrypt
Follow
2 months ago
AI summarizes in 5 seconds.

Decentralized finance protocol CrossCurve, formerly known as EYWA, says it has publicly identified ten Ethereum addresses linked to a hack of its token transfer system on Sunday.


CrossCurve disclosed Sunday afternoon that an attacker exploited a flaw “involving the exploitation of a vulnerability in one of the smart contracts” used for its cross-chain bridge, a system that lets users move tokens between different blockchains.


Hours later, CrossCurve CEO Boris Povar said the team had identified ten Ethereum addresses that received the funds in question.


“These tokens were wrongfully taken from users due to a smart contract exploit,” Povar said. “We do not believe this was intentional on your part, and there is no indication of malicious intent.”





Povar warned that if the funds are not returned or no contact is established within 72 hours, their team would “assume malicious intent and treat the matter as a judicial issue.”


Failure to return the funds would trigger immediate escalation, including criminal referrals, civil litigation, coordination with exchanges and issuers to freeze assets, public disclosure of wallet and transaction data, and cooperation with law enforcement and blockchain analytics firms, Povar added.


A smart contract is a program that runs on a blockchain and automatically executes transactions according to predefined rules.


Defimon Alerts, a social account run by blockchain security firm Decurity, provided an initial estimate that the exploit resulted in losses of around $3 million across “several networks,” adding that the flaw let an attacker send a fake cross-chain message on CrossCurve’s smart contract that bypassed checks and caused the bridge to release funds.


Blockchain security firm BlockSec, meanwhile, estimated total losses at about $2.76 million, including roughly $1.3 million on Ethereum and about $1.28 million on Arbitrum, as well as several chains, including Optimism, Base, Mantle, Kava, Frax, Celo, and Blast.


CrossCurve has not publicly confirmed the loss estimate cited by security firms, and has not shared its own figure for the funds affected. Decrypt has reached out to CrossCurve for comment.


The exploit stemmed from a “lack of validation,” the team at BlockSec told Decrypt.


“The cross‑chain messages that should have been validated were not verified, causing the destination‑chain contract to believe the message reflected a genuine transaction initiated on the source chain and to release the corresponding assets based on attacker‑forged payload data,” BlockSec said.


The incident shows that “cross-chain security still leans too heavily on a single validation pathway,” BlockSec added. “If any alternate execution path bypasses that check, the entire trust model collapses.”


“This exploit wasn’t a failure of Axelar’s core protocol; it was a receiver-side failure,” Dan Dadybayo, research and strategy lead at Unstoppable Wallet, told Decrypt. “CrossCurve’s custom ReceiverAxelar contract executed cross-chain messages without sufficiently authenticating them first.”  


Dadybayo said this pattern has been seen before in cases like Nomad’s 2022 hack.


“The hard part of bridge security isn’t the messaging layer, it’s making sure nothing happens until authenticity is fully proven,” he added. “Custom receivers remain the weakest link. As long as bridges concentrate liquidity and rely on bespoke validation logic, they will continue to be the highest-risk surface in DeFi.”


免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

复活节狂欢,瓜分1万USDT!
广告
|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Selected Articles by Decrypt

40 minutes ago
Where Next for Bitcoin After Worst Quarter Since 2018?
1 hour ago
Bitcoin Miner Riot Platforms Sells Over $250 Million Worth of BTC
1 hour ago
Ethereum Foundation Stakes $93M Worth of ETH, Nears Strategic Target
View More

Table of Contents

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Related Articles

avatar
avatarcoindesk
16 seconds ago
What next as XRP rises to $1.33 but fails to break out
avatar
avatarbitcoin.com
2 minutes ago
Bitcoin ETFs Add $9 Million While Ether Sees $71 Million Exit
avatar
avatarDecrypt
40 minutes ago
Where Next for Bitcoin After Worst Quarter Since 2018?
avatar
avatarbitcoin.com
56 minutes ago
Beyond the Hashrate: Why MARA Just Laid Off 15% of Its Staff
avatar
avatarDecrypt
1 hour ago
Bitcoin Miner Riot Platforms Sells Over $250 Million Worth of BTC
APP
Windows
Mac

X

Telegram

Facebook

Reddit

CopyLink