The post $3M cross-chain breach shakes DeFi appeared on BitcoinEthereumNews.com. A fresh security incident has hit the DeFi sector, with the crosscurve hack underscoringThe post $3M cross-chain breach shakes DeFi appeared on BitcoinEthereumNews.com. A fresh security incident has hit the DeFi sector, with the crosscurve hack underscoring

$3M cross-chain breach shakes DeFi

5 min read

A fresh security incident has hit the DeFi sector, with the crosscurve hack underscoring growing concerns around cross-chain protocols and on-chain infrastructure.

CrossCurve bridge hit by $3 million exploit

CrossCurve, a decentralized cross-chain liquidity protocol, confirmed that its bridge infrastructure was attacked, with estimated losses of around $3 million. The team disclosed the incident after detecting suspicious activity affecting one of its deployed smart contracts.

The exploit comes amid a broader rise in crypto attacks. Moreover, it lands in a period when security firms are warning that sophisticated threats are increasingly targeting cross-chain bridges and liquidity routing systems.

The protocol said the attack affected its cross-chain bridge component, which relies on multiple smart contracts to move assets across different networks. However, the team moved quickly to issue public warnings and pause user interactions while it investigated.

Technical details of the cross-chain bridge exploit

The attack focused on a specific smart contract vulnerability within CrossCurve’s architecture. In an urgent notice posted on its official X account on 2026, the team urged users to immediately stop interacting with the protocol while the situation was assessed.

CrossCurve wrote that its bridge was “currently under attack” and that a flaw in one of the contracts used by the system was being exploited. That said, the project emphasized that users should “pause all interactions” with CrossCurve until further updates were available.

According to Defimon Alerts, an automated monitoring account operated by security company Decurity, the exploit allowed attackers to abuse the ReceiverAxelar contract. Moreover, the issue reportedly enabled calls to the expressExecute function using spoofed cross-chain messages.

The post from Defimon Alerts explained that the malicious calls bypassed gateway validation and triggered unauthorized unlocks on the PortalV2 contract. On-chain data later showed that roughly $3M had been drained from PortalV2 across several networks through this mechanism.

CrossCurve response and SafeHarbor policy

In a follow-up update, CrossCurve said it had traced funds from the exploit to 10 wallet addresses that received tokens originating from the incident. The team stressed that those addresses might not belong to malicious actors and that there was “no indication of malicious intent” from the holders at that stage.

However, CrossCurve noted that the tokens had been “wrongfully taken from users” as a result of the smart contract exploit. The project appealed for cooperation from recipients and asked them to return the digital assets that had been transferred to their wallets.

As part of its mitigation strategy, the protocol activated its SafeHarbor WhiteHat policy, offering a bounty of up to 10% to those who help rescue funds. The team clarified that anyone acting in good faith would be eligible to keep as much as 10% of the recovered amount if the remaining funds were returned.

The announcement also provided a dedicated contact email for coordination. Moreover, CrossCurve said that individuals preferring to remain anonymous could send the compromised assets directly to a specified wallet address under the SafeHarbor framework.

The crosscurve hack was accompanied by a strict timeline. CrossCurve warned that if no contact was made and the funds were not returned within 72 hours from block 24364392, the team would treat the incident as a malicious attack.

In that scenario, the project said it would escalate the matter through several channels. These include filing criminal referrals, initiating potential civil litigation, and working with centralized exchanges and stablecoin issuers to freeze associated assets where possible.

Furthermore, CrossCurve pledged to collaborate with blockchain analytics firms and law enforcement agencies. The team also indicated that, absent cooperation, it would proceed with public disclosure of the wallet data linked to the exploit.

Rising wave of crypto hacks in 2025 and 2026

The CrossCurve incident adds to a growing list of high-profile attacks on decentralized finance platforms. In January 2026, hackers stole nearly $400 million in digital assets across the industry, according to data cited in the report.

Security firm CertiK recorded more than 40 major security incidents during that month alone, highlighting the scale of the current threat environment. Moreover, cross-chain protocols and complex liquidity systems have increasingly been targeted because of the large volumes of assets they secure.

The surge in attacks follows an already damaging year for the sector. In 2025, total losses from crypto-related thefts exceeded $1 billion, making it the worst year on record for such incidents and underscoring persistent structural vulnerabilities.

Against this backdrop, the CrossCurve case illustrates how a single smart contract flaw can cascade across multiple networks and user wallets. It also shows why projects are leaning on whitehat incentives and coordinated responses to limit damage when exploits occur.

In summary, the CrossCurve exploit, the SafeHarbor response, and the broader statistics from 2025 and January 2026 reinforce the need for stronger security practices, more rigorous code audits, and faster cross-industry collaboration when bridge vulnerabilities are exposed.

Source: https://en.cryptonomist.ch/2026/02/02/crosscurve-hack-bridge-exploit/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Trump roasts Mike Johnson for saying grace at prayer event: 'Excuse me, it's lunch!'

Trump roasts Mike Johnson for saying grace at prayer event: 'Excuse me, it's lunch!'

President Donald Trump in a speech at this year's National Prayer Breakfast roasted House Speaker Mike Johnson (R-LA) for saying grace at meals.The 79-year-old
Share
Rawstory2026/02/05 23:11
Where Can You Turn $1,000 Into $5,000 This Week? Experts Point Towards Remittix As The Best Option

Where Can You Turn $1,000 Into $5,000 This Week? Experts Point Towards Remittix As The Best Option

Cryptocurrency markets are again showing that opportunities can emerge when fundamentals, timing and demand intersect. Amid sideways price action in many major
Share
Techbullion2026/02/05 23:13
UK Looks to US to Adopt More Crypto-Friendly Approach

UK Looks to US to Adopt More Crypto-Friendly Approach

The post UK Looks to US to Adopt More Crypto-Friendly Approach appeared on BitcoinEthereumNews.com. The UK and US are reportedly preparing to deepen cooperation on digital assets, with Britain looking to copy the Trump administration’s crypto-friendly stance in a bid to boost innovation.  UK Chancellor Rachel Reeves and US Treasury Secretary Scott Bessent discussed on Tuesday how the two nations could strengthen their coordination on crypto, the Financial Times reported on Tuesday, citing people familiar with the matter.  The discussions also involved representatives from crypto companies, including Coinbase, Circle Internet Group and Ripple, with executives from the Bank of America, Barclays and Citi also attending, according to the report. The agreement was made “last-minute” after crypto advocacy groups urged the UK government on Thursday to adopt a more open stance toward the industry, claiming its cautious approach to the sector has left the country lagging in innovation and policy.  Source: Rachel Reeves Deal to include stablecoins, look to unlock adoption Any deal between the countries is likely to include stablecoins, the Financial Times reported, an area of crypto that US President Donald Trump made a policy priority and in which his family has significant business interests. The Financial Times reported on Monday that UK crypto advocacy groups also slammed the Bank of England’s proposal to limit individual stablecoin holdings to between 10,000 British pounds ($13,650) and 20,000 pounds ($27,300), claiming it would be difficult and expensive to implement. UK banks appear to have slowed adoption too, with around 40% of 2,000 recently surveyed crypto investors saying that their banks had either blocked or delayed a payment to a crypto provider.  Many of these actions have been linked to concerns over volatility, fraud and scams. The UK has made some progress on crypto regulation recently, proposing a framework in May that would see crypto exchanges, dealers, and agents treated similarly to traditional finance firms, with…
Share
BitcoinEthereumNews2025/09/18 02:21