CrossCurve bridge exploited for $3M; users urged to stop

CrossCurve lost $3M in a cross-chain bridge exploit due to a smart contract flaw. Users are advised to halt all activity while the team investigates.

CrossCurve, formerly known as EYWA, suffered a major security breach, losing approximately $3 million across multiple blockchains. The incident was traced to a vulnerability in the ReceiverAxelar smart contract, which lacked proper validation checks. This flaw enabled attackers to spoof cross-chain messages and invoke the expressExecute function, bypassing gateway verification and withdrawing tokens from the PortalV2 contract. The exploit took place between January 31 and February 1. In response, the CrossCurve team urged users to immediately cease all platform interactions while investigations are ongoing. Some addresses received stolen tokens, and the team has requested their return, offering a bounty for recovery. If the funds are not returned within 72 hours, CrossCurve may pursue legal action and collaborate with exchanges and analytics firms. The incident highlights ongoing security concerns surrounding cross-chain bridges in DeFi.

Related News