CrossCurve exploited for $3 million in multi-network bridge attack

by shayaan

Cross-chain liquidity protocol CrossCurve has been the target of a smart contract exploit, with attackers taking approximately $3 million dollars across multiple networks.

Summary

  • CrossCurve has confirmed a $3 million exploit involving forged cross-chain messages that bypassed bridge validation.
  • The protocol offers a 10% cash return premium.

CrossCurve confirmed the exploit via an X after and has asked all users to “pause all interactions with the protocol” until the vulnerability is fixed.

In a sequel afterthe protocol said it had identified ten addresses that received tokens from the exploit and urged the attackers to return the money in exchange for a reward.

“We do not believe this was intentional on your part, and there is no evidence of malicious intent. We hope for your cooperation in returning the money,” CrossCurve wrote.

The protocol has offered 10% of the stolen funds as a bounty, similar to what it offers under its SafeHarbor WhiteHat policy.

If the money is not returned within 72 hours, the Protocol has pledged to pursue legal options, including civil lawsuits to recover damages and coordinate with law enforcement and other projects to freeze the assets.

At the time of publication, CrossCurve has not released an official post-mortem report on the extent of the losses and how many users may have been affected.

According to blockchain security account Defimon Alerts, total losses could reach nearly $3 million.

“Anyone could call expressExecute on the ReceiverAxelar contract with a forged cross-chain message, bypassing gateway validation and triggering unlocking on PortalV2,” Defimon said.

See also  Dogwifhat Rally Imminent? Whale Buys 9.50 Million WIF

Arkham Intelligence data cited by Defimon showed that the PortalV2 contract balance fell to almost zero around January 31.

Wallet address linked to CrossCruve. | Source: Defimon Alerts on X//DefimonAlerts

CrossCurve, formerly known as EYWA Protocol, operates a cross-chain DEX and consensus bridge built in partnership with Curve Finance. It uses a consensus mechanism that routes transactions through multiple independent validation protocols to reduce single points of failure.

“Users who have votes assigned to Eywa-related pools may wish to reconsider their positions and consider removing those votes. We continue to encourage all participants to remain vigilant and make risk-conscious decisions when interacting with third-party projects,” the official Curve Finance posted after the incident was confirmed.

SagaEVM chain was operated several weeks earlier

The CrossCurve incident is the second major exploit in recent weeks, as it closely follows the smart contract breach in the SagaEVM chain, which resulted in the loss of approximately $7 million in bridged assets.

As previously reported by crypto.news, Saga had to pause the SagaEVM chain and work with bridge operators to blacklist the address and restrict further money flows.

Source link

You may also like

Latest News

Copyright © Sovereign Wealth Signals