HomeCoinsLitecoinDeFi Protocol CrossCurve Smart Contract Exploited, Suffers $3M Loss Across Multiple Chains

DeFi Protocol CrossCurve Smart Contract Exploited, Suffers $3M Loss Across Multiple Chains

Cross-chain bridge CrossCurve announced Monday that it has suffered a major attack, losing $3 million across multiple networks.

The DeFi protocol noted that a vulnerability in its smart contracts had been exploited, raising security concerns about cross-chain infrastructure.

“Our bridge is currently under attack,” it wrote on X, warning users to suspend all interactions with CrossCurve.

Smart Contract Flaw: Attackers Used Spoof Messages

Per CrossCurve post, some user addresses received token funds due to the smart contract vulnerability that were “wrongfully taken” from other users.

Read More:  Solana Price Prediction: $30M Hack Sends SOL Below $100 – Can Bulls Recover?

“We do not believe this was intentional on your part, and there is no indication of malicious intent. We hope for your cooperation in returning the funds,” the platform wrote, identifying a total of 10 addresses.

According to blockchain security account Defimon Alerts, a vulnerable CrossCurve’s smart contracts ReceiverAxelar, allowed anyone to spoof cross-chain message, bypassing the gateway validation. This has triggered unauthorized token unlocks on PortalV2 contract.

Besides, Curve Finance wrote that users who have allocated votes to the platform-related pools “may wish to review their positions and consider removing those votes.”

Read More:  Bitcoin Price Prediction: Major Miner Just Expanded in Texas: Is a Massive BTC Production Surge Coming?

The protocol is backed by Curve Finance founder Michael Egorov and raised $7 million from VCs in 2023.

CrossCurve Offers 10% White Hat Bounty, Sets 72-Hour Limit

Per the Safe Harbor Responsible Disclosure Policy, which details the steps to implement responsible reporting of security vulnerabilities, if a white-hat hacker assists in fund recovery, a 10% bounty will be provided.

Read More:  Solana Price Prediction: SOL Just Flipped Ethereum in Critical $600 Billion Metric — Is Solana About to Explode?

“This makes you eligible to keep up to 10% if the remainder is returned,” the project team noted.

Besides, CrossCurve has set a 72-hour limit for hackers to return the funds. If no effective communication is established, the project team will take immediate escalation.

This includes formal criminal and civil proceedings, collaborating with exchanges such as Coinbase and Binance, stablecoin issuers, law enforcements and on-chain analytics firms, including Chainalysis, TRM Labs and Elliptic.

CrossCurve hack is similar to Nomad’s $190 million bridge exploit in 2022, which saw an estimated 8000 Solana wallets compromised.

“In terms of prevention, an industry set of standard smart contract templates that are known to be secure, smart contract auditing and secure software development lifecycles would be steps in the right direction,” Andrew Morfill, Chief Information Security Officer at Komainu, told Cryptonews. “As the market matures, securely developed and updated protocols with real utility will provide the credibility and security assurance investors are looking for.”

The post DeFi Protocol CrossCurve Smart Contract Exploited, Suffers $3M Loss Across Multiple Chains appeared first on Cryptonews.

Facebook Comments Box

LATEST POSTS

Bitcoin At Key Support Levels — Why Jack Mallers Says Turn On DCA Now

Few people are as close to the center of the Bitcoin industry as Jack Maller. A young, tech-savvy CEO of a major Bitcoin...

Bitcoin’s power-law model faces its biggest test yet as ETF flows challenge the curve

Bitcoin’s power law enters a 2026 stress test as Giovanni’s new chart shifts the debate from price targets to regime signalsBitcoin Power Law chart creator...

Most Popular