Cross-Chain Bridge Vulnerability Leads to $3M CrossCurve Loss

CRV-5,43%
SAGA-8,12%
SOL-4,24%

Losses at CrossCurve underline the high risk of cross-chain bridges during periods of rising crypto attacks.

CrossCurve halted user activity after an attack targeted its cross-chain bridge. The incident forced developers to investigate a smart contract flaw. Partner protocols and and security firms issued warnings as funds were traced on-chain.

User Interactions Halted as CrossCurve Examines Contract Weakness

CrossCurve confirmed on Sunday that its cross-chain bridge was targeted by attackers. The team linked the incident to a flaw in one of the bridge’s smart contracts. Users were asked to pause all activity while developers began reviewing the issue.

Because assets are held across multiple smart contracts, moving them between networks increases risk when a single component fails.

⚠️ URGENT Security Notice

Dear users,

Our bridge is currently under attack, involving the exploitation of a vulnerability in one of the smart contracts used.

Please pause all interactions with CrossCurve while the investigation is ongoing.

We appreciate your patience and… pic.twitter.com/yfo1KvWoDd

— CrossCurve (@crosscurvefi) February 1, 2026

Curve Finance addressed its community shortly after the incident. Users with exposure to CrossCurve pools were advised to reassess their positions and decide whether to withdraw voting support. The statement urged careful judgment when interacting with external protocols during unstable conditions.

Early checks found damage limited to the bridge, with no issues detected across other protocol components. Alerts went out quickly, while the team kept access paused and tracked the movement of stolen funds.

Protocol Calls for Asset Returns After On-Chain Review

After tracing on-chain activity, the team found that funds from the exploit had moved into 10 wallet addresses. CrossCurve said it could not confirm whether those wallets belonged to the attackers and saw no clear hostile behavior at that point. Even so, the protocol acknowledged that users lost funds due to the exploit.

In response, project officials appealed directly to recipients to return the assets. The team described the transfers as improper and asked for cooperation. To support recovery efforts, CrossCurve activated its SafeHarbor WhiteHat policy, offering a reward of up to 10% of recovered funds if the rest is returned.

Details included a direct contact email for coordination. An alternative option allows anonymous returns through a designated wallet address. The team said recovered funds would be returned to affected users after review.

Moreover, CrossCurve shared a contact email to help coordinate the return of funds. A separate wallet address was also provided for those who prefer to send assets back without revealing their identity. After verification, the team said it plans to distribute recovered funds to affected users.

Recent Breaches Expose Ongoing Risks in Decentralized Finance

Crypto attacks have increased across the industry, with the CrossCurve incident adding to a growing list of breaches. Security firm CertiK recorded nearly $400 million in losses in January 2026, with more than 40 major incidents reported.

_Image Source: _X/CertiK

Cross-chain systems face a higher risk because they handle large amounts of funds and rely on complex structures. Recent incidents show how fast damage can spread once an exploit begins.

Other victims during the same period included Swapnet, which lost $13 million. Saga and Makina Finance reported losses of $6.2 million and $4.2 million. Step Finance also suffered a breach that drained several treasury and fee wallets, moving more than 261,000 SOL.

Losses across 2025 passed $1 billion, marking the worst year on record for crypto theft. The CrossCurve case adds another reminder of ongoing security gaps within decentralized finance.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Gerelateerde artikelen

诺贝尔物理学奖得主警告:量子计算可能在数分钟内破解比特币私钥

前Google量子硬件负责人John Martinis警告,比特币可能成为量子计算攻击目标,量子计算机能在几分钟内推导出比特币私钥,威胁大于传统金融系统。建议社区尽早规划量子抗性升级,以应对未来5至10年的威胁。

GateNews8m geleden

国家安全部警示 Token 骗局频发,涉嫌非法金融活动或被境外间谍机构利用

国家安全部近日警示各种以"囤 Token 能暴富"为噱头的骗局,称这些行为危害国家经济安全,并提醒公众谨慎对待非法加密货币交易。

GateNews1u geleden

360 发现 OpenClaw 三大安全漏洞,涉 1 个高危、2 个中危

Gate News 消息,4 月 7 日,360 漏洞挖掘智能体近期针对 OpenClaw 新挖掘并上报 1 个高危、2 个中危共 3 个高价值漏洞,目前所有新发现漏洞均已被官方修复并公开披露。此次新发现的三大漏洞直指 AI 智能体核心运行机制,直接影响用户设备、数据与账号的核心安全。

GateNews1u geleden

Solana Foundation unveils security overhaul days after $270 million Drift exploit

The Solana Foundation announced a suite of security initiatives on Monday, just five days after decentralized finance (DeFi) platform Drift Protocol suffered a $270 million exploit carried out by a North Korean state-affiliated group following a six-month social engineering campaign. The

CoinDesk1u geleden

風險管理團隊 Chaos Labs 因預算問題出走 Aave,V4 安全性存疑?

風險管理團隊Chaos Labs宣布終止與Aave的合作,因長期虧損及無法調和的風險管理分歧。此時Aave V4剛上線,Chaos在升級後需重新構建風險工具,且預算需求高於Aave的接受範圍。此外,Aave面臨多名核心團隊出走,運營穩定性成疑。

ChainNewsAbmedia3u geleden

Savannah Guthrie 重返《今日秀》,母亲 Nancy Guthrie 加密绑架案比特币赎金仍未破

NBC主持人Savannah Guthrie今日重返《今日秀》,但其84岁母亲Nancy在亚利桑那州仍失踪,绑匪索要600万美元比特币赎金。失踪65天,案件无重大进展,Savannah表达自责,认为母亲遭绑架可能与她的知名度有关。

GateNews4u geleden
Opmerking
0/400
Geen opmerkingen