Crosscurve hack highlights a $3 million cross-chain breach, underscoring DeFi security risks, white-hat incentives, and legal responses.Crosscurve hack highlights a $3 million cross-chain breach, underscoring DeFi security risks, white-hat incentives, and legal responses.

CrossCurve hack exposes $3 million cross-chain bridge exploit as crypto thefts accelerate

crosscurve hack

A fresh security incident has hit the DeFi sector, with the crosscurve hack underscoring growing concerns around cross-chain protocols and on-chain infrastructure.

CrossCurve bridge hit by $3 million exploit

CrossCurve, a decentralized cross-chain liquidity protocol, confirmed that its bridge infrastructure was attacked, with estimated losses of around $3 million. The team disclosed the incident after detecting suspicious activity affecting one of its deployed smart contracts.

The exploit comes amid a broader rise in crypto attacks. Moreover, it lands in a period when security firms are warning that sophisticated threats are increasingly targeting cross-chain bridges and liquidity routing systems.

The protocol said the attack affected its cross-chain bridge component, which relies on multiple smart contracts to move assets across different networks. However, the team moved quickly to issue public warnings and pause user interactions while it investigated.

Technical details of the cross-chain bridge exploit

The attack focused on a specific smart contract vulnerability within CrossCurve’s architecture. In an urgent notice posted on its official X account on 2026, the team urged users to immediately stop interacting with the protocol while the situation was assessed.

CrossCurve wrote that its bridge was “currently under attack” and that a flaw in one of the contracts used by the system was being exploited. That said, the project emphasized that users should “pause all interactions” with CrossCurve until further updates were available.

According to Defimon Alerts, an automated monitoring account operated by security company Decurity, the exploit allowed attackers to abuse the ReceiverAxelar contract. Moreover, the issue reportedly enabled calls to the expressExecute function using spoofed cross-chain messages.

The post from Defimon Alerts explained that the malicious calls bypassed gateway validation and triggered unauthorized unlocks on the PortalV2 contract. On-chain data later showed that roughly $3M had been drained from PortalV2 across several networks through this mechanism.

CrossCurve response and SafeHarbor policy

In a follow-up update, CrossCurve said it had traced funds from the exploit to 10 wallet addresses that received tokens originating from the incident. The team stressed that those addresses might not belong to malicious actors and that there was “no indication of malicious intent” from the holders at that stage.

However, CrossCurve noted that the tokens had been “wrongfully taken from users” as a result of the smart contract exploit. The project appealed for cooperation from recipients and asked them to return the digital assets that had been transferred to their wallets.

As part of its mitigation strategy, the protocol activated its SafeHarbor WhiteHat policy, offering a bounty of up to 10% to those who help rescue funds. The team clarified that anyone acting in good faith would be eligible to keep as much as 10% of the recovered amount if the remaining funds were returned.

The announcement also provided a dedicated contact email for coordination. Moreover, CrossCurve said that individuals preferring to remain anonymous could send the compromised assets directly to a specified wallet address under the SafeHarbor framework.

The crosscurve hack was accompanied by a strict timeline. CrossCurve warned that if no contact was made and the funds were not returned within 72 hours from block 24364392, the team would treat the incident as a malicious attack.

In that scenario, the project said it would escalate the matter through several channels. These include filing criminal referrals, initiating potential civil litigation, and working with centralized exchanges and stablecoin issuers to freeze associated assets where possible.

Furthermore, CrossCurve pledged to collaborate with blockchain analytics firms and law enforcement agencies. The team also indicated that, absent cooperation, it would proceed with public disclosure of the wallet data linked to the exploit.

Rising wave of crypto hacks in 2025 and 2026

The CrossCurve incident adds to a growing list of high-profile attacks on decentralized finance platforms. In January 2026, hackers stole nearly $400 million in digital assets across the industry, according to data cited in the report.

Security firm CertiK recorded more than 40 major security incidents during that month alone, highlighting the scale of the current threat environment. Moreover, cross-chain protocols and complex liquidity systems have increasingly been targeted because of the large volumes of assets they secure.

The surge in attacks follows an already damaging year for the sector. In 2025, total losses from crypto-related thefts exceeded $1 billion, making it the worst year on record for such incidents and underscoring persistent structural vulnerabilities.

Against this backdrop, the CrossCurve case illustrates how a single smart contract flaw can cascade across multiple networks and user wallets. It also shows why projects are leaning on whitehat incentives and coordinated responses to limit damage when exploits occur.

In summary, the CrossCurve exploit, the SafeHarbor response, and the broader statistics from 2025 and January 2026 reinforce the need for stronger security practices, more rigorous code audits, and faster cross-industry collaboration when bridge vulnerabilities are exposed.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Share
BitcoinEthereumNews2025/09/18 00:09
Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058

Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058

Ethereum price predictions are turning heads, with analysts suggesting ETH could climb to $10,000 by 2026 as institutional demand and network upgrades drive growth. While Ethereum remains a blue-chip asset, investors looking for sharper multiples are eyeing Layer Brett (LBRETT). Currently in presale at just $0.0058, the Ethereum Layer 2 meme coin is drawing huge [...] The post Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058 appeared first on Blockonomi.
Share
Blockonomi2025/09/17 23:45
IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

The post IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge! appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 18:00 Discover why BlockDAG’s upcoming Awakening Testnet launch makes it the best crypto to buy today as Story (IP) price jumps to $11.75 and Hyperliquid hits new highs. Recent crypto market numbers show strength but also some limits. The Story (IP) price jump has been sharp, fueled by big buybacks and speculation, yet critics point out that revenue still lags far behind its valuation. The Hyperliquid (HYPE) price looks solid around the mid-$50s after a new all-time high, but questions remain about sustainability once the hype around USDH proposals cools down. So the obvious question is: why chase coins that are either stretched thin or at risk of retracing when you could back a network that’s already proving itself on the ground? That’s where BlockDAG comes in. While other chains are stuck dealing with validator congestion or outages, BlockDAG’s upcoming Awakening Testnet will be stress-testing its EVM-compatible smart chain with real miners before listing. For anyone looking for the best crypto coin to buy, the choice between waiting on fixes or joining live progress feels like an easy one. BlockDAG: Smart Chain Running Before Launch Ethereum continues to wrestle with gas congestion, and Solana is still known for network freezes, yet BlockDAG is already showing a different picture. Its upcoming Awakening Testnet, set to launch on September 25, isn’t just a demo; it’s a live rollout where the chain’s base protocols are being stress-tested with miners connected globally. EVM compatibility is active, account abstraction is built in, and tools like updated vesting contracts and Stratum integration are already functional. Instead of waiting for fixes like other networks, BlockDAG is proving its infrastructure in real time. What makes this even more important is that the technology is operational before the coin even hits exchanges. That…
Share
BitcoinEthereumNews2025/09/18 00:32