The post CrossCurve Suffers $3M Bridge Exploit as Validation Check Fails appeared on BitcoinEthereumNews.com. Attackers bypassed gateway validation using spoofedThe post CrossCurve Suffers $3M Bridge Exploit as Validation Check Fails appeared on BitcoinEthereumNews.com. Attackers bypassed gateway validation using spoofed

CrossCurve Suffers $3M Bridge Exploit as Validation Check Fails

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
  • Attackers bypassed gateway validation using spoofed cross-chain messages to unlock funds.
  • The exploit drained roughly $3 million from CrossCurve’s PortalV2 contract across multiple networks.
  • CrossCurve identified ten recipient wallets and activated its 10% WhiteHat bounty policy.

CrossCurve, a decentralized cross-chain liquidity protocol formerly known as EYWA, has confirmed that its bridge infrastructure was exploited, leading to losses of about $3 million.

The attack adds to a substantial rise in crypto thefts. Nearly $400 million was stolen across the industry in January 2026 alone. More than 40 major security incidents were recorded during the month, according to CertiK. 

Spoofed Messages Bypassed Validation

The exploit targeted a missing validation check in one of CrossCurve’s smart contracts. According to Defimon Alerts, anyone could call the expressExecute function on the ReceiverAxelar contract using a spoofed cross-chain message.

This bypassed gateway validation and triggered unauthorized token unlocks on the protocol’s PortalV2 contract. Arkham data showed the PortalV2 balance dropping from roughly $3 million to near zero around January 31, with funds drained across multiple networks.

BlockSec later estimated total losses at about $2.76 million. Roughly $1.3 million was lost on Ethereum and around $1.28 million on Arbitrum. Additional losses were recorded on Optimism, Base, Mantle, Kava, Frax, Celo, and Blast.

The exploit mechanism resembled the Nomad bridge failure in 2022, where a flawed verification check led to a rapid drain of funds by hundreds of wallets.

Emergency Response and Wallet Identification

Following the attack, CrossCurve issued an urgent notice asking users to stop all interactions while the issue was investigated. The team later confirmed it had identified ten Ethereum addresses that received tokens originating from the exploit. 

CrossCurve stated that the funds were taken due to a smart contract flaw and said it did not assume malicious intent at this stage. The protocol invoked its SafeHarbor WhiteHat policy, offering a bounty of up to 10% to any party that returns the remaining funds. 

It also invited direct coordination through email or anonymous repayment to a designated wallet. But warned that if no contact is made and funds are not returned within 72 hours from block 24364392, the incident will be treated as malicious.

Escalation measures include criminal referrals, civil litigation, cooperation with centralized exchanges and stablecoin issuers to freeze assets, public disclosure of wallet data, and coordination with blockchain analytics firms and law enforcement.

Related: Truebit Protocol Hack Triggers Record Uniswap Fees Amid a 100% TRU Dump

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source: https://coinedition.com/crosscurve-bridge-exploited-for-3m-after-spoofed-cross-chain-messages/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

The post How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings appeared on BitcoinEthereumNews.com. contributor Posted: September 17, 2025 As digital assets continue to reshape global finance, cloud mining has become one of the most effective ways for investors to generate stable passive income. Addressing the growing demand for simplicity, security, and profitability, IeByte has officially upgraded its fully automated cloud mining platform, empowering both beginners and experienced investors to earn Bitcoin, Dogecoin, and other mainstream cryptocurrencies without the need for hardware or technical expertise. Why cloud mining in 2025? Traditional crypto mining requires expensive hardware, high electricity costs, and constant maintenance. In 2025, with blockchain networks becoming more competitive, these barriers have grown even higher. Cloud mining solves this by allowing users to lease professional mining power remotely, eliminating the upfront costs and complexity. IeByte stands at the forefront of this transformation, offering investors a transparent and seamless path to daily earnings. IeByte’s upgraded auto-cloud mining platform With its latest upgrade, IeByte introduces: Full Automation: Mining contracts can be activated in just one click, with all processes handled by IeByte’s servers. Enhanced Security: Bank-grade encryption, cold wallets, and real-time monitoring protect every transaction. Scalable Options: From starter packages to high-level investment contracts, investors can choose the plan that matches their goals. Global Reach: Already trusted by users in over 100 countries. Mining contracts for 2025 IeByte offers a wide range of contracts tailored for every investor level. From entry-level plans with daily returns to premium high-yield packages, the platform ensures maximum accessibility. Contract Type Duration Price Daily Reward Total Earnings (Principal + Profit) Starter Contract 1 Day $200 $6 $200 + $6 + $10 bonus Bronze Basic Contract 2 Days $500 $13.5 $500 + $27 Bronze Basic Contract 3 Days $1,200 $36 $1,200 + $108 Silver Advanced Contract 1 Day $5,000 $175 $5,000 + $175 Silver Advanced Contract 2 Days $8,000 $320 $8,000 + $640 Silver…
Share
BitcoinEthereumNews2025/09/17 23:48
Veterans losing their homes in droves after Trump ignored major warning: report

Veterans losing their homes in droves after Trump ignored major warning: report

The Trump administration ignored warnings from policy experts when they changed a major policy at the Department of Veterans Affairs — and the result is a wave
Share
Rawstory2026/04/02 19:30
Teradyne (TER) Stock Surges 271% Ahead of Q1 Earnings: What Investors Should Watch

Teradyne (TER) Stock Surges 271% Ahead of Q1 Earnings: What Investors Should Watch

Teradyne (TER) stock analysis ahead of Q1 2026 earnings. Analysts forecast 177% EPS growth with a $311 price target after a 271% annual rally. The post Teradyne
Share
Blockonomi2026/04/03 21:53

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!