Cross-Chain Bridge Vulnerability Leads to $3M CrossCurve Loss

CRV6,1%
SAGA1,13%
SOL1,98%

Losses at CrossCurve underline the high risk of cross-chain bridges during periods of rising crypto attacks.

CrossCurve halted user activity after an attack targeted its cross-chain bridge. The incident forced developers to investigate a smart contract flaw. Partner protocols and and security firms issued warnings as funds were traced on-chain.

User Interactions Halted as CrossCurve Examines Contract Weakness

CrossCurve confirmed on Sunday that its cross-chain bridge was targeted by attackers. The team linked the incident to a flaw in one of the bridge’s smart contracts. Users were asked to pause all activity while developers began reviewing the issue.

Because assets are held across multiple smart contracts, moving them between networks increases risk when a single component fails.

⚠️ URGENT Security Notice

Dear users,

Our bridge is currently under attack, involving the exploitation of a vulnerability in one of the smart contracts used.

Please pause all interactions with CrossCurve while the investigation is ongoing.

We appreciate your patience and… pic.twitter.com/yfo1KvWoDd

— CrossCurve (@crosscurvefi) February 1, 2026

Curve Finance addressed its community shortly after the incident. Users with exposure to CrossCurve pools were advised to reassess their positions and decide whether to withdraw voting support. The statement urged careful judgment when interacting with external protocols during unstable conditions.

Early checks found damage limited to the bridge, with no issues detected across other protocol components. Alerts went out quickly, while the team kept access paused and tracked the movement of stolen funds.

Protocol Calls for Asset Returns After On-Chain Review

After tracing on-chain activity, the team found that funds from the exploit had moved into 10 wallet addresses. CrossCurve said it could not confirm whether those wallets belonged to the attackers and saw no clear hostile behavior at that point. Even so, the protocol acknowledged that users lost funds due to the exploit.

In response, project officials appealed directly to recipients to return the assets. The team described the transfers as improper and asked for cooperation. To support recovery efforts, CrossCurve activated its SafeHarbor WhiteHat policy, offering a reward of up to 10% of recovered funds if the rest is returned.

Details included a direct contact email for coordination. An alternative option allows anonymous returns through a designated wallet address. The team said recovered funds would be returned to affected users after review.

Moreover, CrossCurve shared a contact email to help coordinate the return of funds. A separate wallet address was also provided for those who prefer to send assets back without revealing their identity. After verification, the team said it plans to distribute recovered funds to affected users.

Recent Breaches Expose Ongoing Risks in Decentralized Finance

Crypto attacks have increased across the industry, with the CrossCurve incident adding to a growing list of breaches. Security firm CertiK recorded nearly $400 million in losses in January 2026, with more than 40 major incidents reported.

_Image Source: _X/CertiK

Cross-chain systems face a higher risk because they handle large amounts of funds and rely on complex structures. Recent incidents show how fast damage can spread once an exploit begins.

Other victims during the same period included Swapnet, which lost $13 million. Saga and Makina Finance reported losses of $6.2 million and $4.2 million. Step Finance also suffered a breach that drained several treasury and fee wallets, moving more than 261,000 SOL.

Losses across 2025 passed $1 billion, marking the worst year on record for crypto theft. The CrossCurve case adds another reminder of ongoing security gaps within decentralized finance.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Articoli correlati

Ledger Donjon Finds MediaTek Flaw Exposing Android Wallet Seeds

_Ledger Donjon exposed a MediaTek vulnerability that extracts Android wallet seed phrases in under 45 seconds, affecting millions of devices. CVE-2025-20435._ Ledger Donjon has uncovered a serious MediaTek vulnerability. It lets attackers pull wallet seed phrases from Android phones in seconds.

LiveBTCNews2h fa

疑似黑客地址主导 CAKE 和 THE 清算事件,Venus 产生 215 万美元亏空

3月15日,一个疑似黑客地址从Tornado收到7400枚ETH,主导CAKE和THE抵押清算事件,导致Venus产生约215万美元亏空。该地址通过复杂操作拉升THE价格,最终其在Venus的抵押品被清算,但仍有大量借款未偿还。分析认为此事件可能是其用于在某CEX获利的策略。

GateNews5h fa

Venus Protocol 暂停 THE 代币借款与提取操作,其他市场正常运行

Gate News 消息,3 月 15 日,Venus Protocol 发布安全公告称,在调查 THE 资金池中的异常活动期间,为防止进一步被滥用,已采取预防性措施,即刻暂停所有 THE 代币的借款与提取操作。该措施将在调查结束前持续生效。Venus Protocol 表示,其他市场未受影响,仍将正常运行。

GateNews5h fa

Venus Protocol 疑似遭闪电贷攻击,THE 出现大规模清算

BNB Chain 借贷协议 Venus Protocol 疑似遭遇闪电贷攻击,导致代币 THE 大规模清算。攻击者已获得约 360 万美元的资产,清算仍在进行中,目前还有约 4200 万枚 THE 等待清算。

GateNews7h fa

央视315晚会曝光AI大模型数据投毒产业链,付费可操控AI回答内容

央视315晚会曝光AI大模型数据「投毒」产业链,涉及名为GEO的业务,服务商通过收费让客户产品在AI模型中突出,催生发稿公司,成为数据操控的重要环节。

GateNews8h fa

Tether 冻结 Tron 链上地址约 1196 万枚 USDT

3月15日,Tether冻结了一个Tron链上地址的11,960,680枚USDT,利用智能合约的黑名单功能进行操作。此举通常源于洗钱和诈骗等执法要求。过去几年,Tether已累计冻结超过42亿美元的USDT。

GateNews8h fa
Commento
0/400
Nessun commento