Cross-Chain Bridge Vulnerability Leads to $3M CrossCurve Loss

CRV-4,25%
SAGA-0,14%
SOL-5,52%

Losses at CrossCurve underline the high risk of cross-chain bridges during periods of rising crypto attacks.

CrossCurve halted user activity after an attack targeted its cross-chain bridge. The incident forced developers to investigate a smart contract flaw. Partner protocols and and security firms issued warnings as funds were traced on-chain.

User Interactions Halted as CrossCurve Examines Contract Weakness

CrossCurve confirmed on Sunday that its cross-chain bridge was targeted by attackers. The team linked the incident to a flaw in one of the bridge’s smart contracts. Users were asked to pause all activity while developers began reviewing the issue.

Because assets are held across multiple smart contracts, moving them between networks increases risk when a single component fails.

⚠️ URGENT Security Notice

Dear users,

Our bridge is currently under attack, involving the exploitation of a vulnerability in one of the smart contracts used.

Please pause all interactions with CrossCurve while the investigation is ongoing.

We appreciate your patience and… pic.twitter.com/yfo1KvWoDd

— CrossCurve (@crosscurvefi) February 1, 2026

Curve Finance addressed its community shortly after the incident. Users with exposure to CrossCurve pools were advised to reassess their positions and decide whether to withdraw voting support. The statement urged careful judgment when interacting with external protocols during unstable conditions.

Early checks found damage limited to the bridge, with no issues detected across other protocol components. Alerts went out quickly, while the team kept access paused and tracked the movement of stolen funds.

Protocol Calls for Asset Returns After On-Chain Review

After tracing on-chain activity, the team found that funds from the exploit had moved into 10 wallet addresses. CrossCurve said it could not confirm whether those wallets belonged to the attackers and saw no clear hostile behavior at that point. Even so, the protocol acknowledged that users lost funds due to the exploit.

In response, project officials appealed directly to recipients to return the assets. The team described the transfers as improper and asked for cooperation. To support recovery efforts, CrossCurve activated its SafeHarbor WhiteHat policy, offering a reward of up to 10% of recovered funds if the rest is returned.

Details included a direct contact email for coordination. An alternative option allows anonymous returns through a designated wallet address. The team said recovered funds would be returned to affected users after review.

Moreover, CrossCurve shared a contact email to help coordinate the return of funds. A separate wallet address was also provided for those who prefer to send assets back without revealing their identity. After verification, the team said it plans to distribute recovered funds to affected users.

Recent Breaches Expose Ongoing Risks in Decentralized Finance

Crypto attacks have increased across the industry, with the CrossCurve incident adding to a growing list of breaches. Security firm CertiK recorded nearly $400 million in losses in January 2026, with more than 40 major incidents reported.

_Image Source: _X/CertiK

Cross-chain systems face a higher risk because they handle large amounts of funds and rely on complex structures. Recent incidents show how fast damage can spread once an exploit begins.

Other victims during the same period included Swapnet, which lost $13 million. Saga and Makina Finance reported losses of $6.2 million and $4.2 million. Step Finance also suffered a breach that drained several treasury and fee wallets, moving more than 261,000 SOL.

Losses across 2025 passed $1 billion, marking the worst year on record for crypto theft. The CrossCurve case adds another reminder of ongoing security gaps within decentralized finance.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Gerelateerde artikelen

Drift 攻击事件波及 11 个 DeFi 协议,Ranger Finance 风险敞口约 90 万美元

4月2日,Drift攻击事件影响了多个DeFi协议,包括Reflect Money和Ranger Finance等11个项目。部分项目暂停了铸造及取款等功能,Ranger Finance损失约90万美元,占其总值的6%;Pyra因用户资金受影响也暂停了相关功能。

GateNews2m geleden

Wormhole 回应 Drift 遭攻击事件:因 Solana 安全机制部分跨链交易或有延迟

Gate News 消息,4 月 2 日,Wormhole 就 Drift 遭攻击事件发布官方回应,表示 Wormhole 用户资产暂未面临风险,跨链桥功能仍可正常使用。但由于针对 Solana 设置的内置安全机制,部分跨链转账可能出现延迟。Wormhole 核心贡献者已与 Solana 生态团队保持沟通,并将根据需要持续提供支持。

GateNews57m geleden

Loopscale:SOL Genesis 金库约 17 万美元存款存在 Drift 间接敞口,承诺全额补偿

Loopscale 声明与 Drift 无直接关联,多数资金安全,部分存在间接敞口。SOL Genesis 金库中的存款将会全额补偿用户,存取款功能暂时禁用,待恢复后重新开放。

GateNews1u geleden

鏈上交易所 Drift Protocol 遭駭損失 2.8 億美元,Solana 生態恐出現連鎖反應?

去中心化交易平台Drift Protocol於4月2日遭駭,損失高達2.8億美元,成為Solana生態中最大的DeFi安全事件之一。攻擊者利用多簽漏洞獲取管理員金鑰,迅速轉移資產。Drift已暫停存提款,並承諾持續更新事件調查。資安專家指出,此次事件凸顯DeFi協議在高權限金鑰管理上的風險,呼籲加強安全措施以保護用戶資產。

ChainNewsAbmedia1u geleden

Trust Wallet Discord 短連結遭劫持,ZachXBT 緊急警告切勿點擊

Trust Wallet 的 Discord 短連結被劫持,指向惡意釣魚伺服器,使用者應立即停止點擊相關連結,並等待官方確認安全性。新推出的地址投毒防護功能能主動篩查潛在詐騙地址。自 2025 年以來,Trust Wallet 面臨多項安全挑戰,使用者需謹慎防範。

MarketWhisper1u geleden
Opmerking
0/400
Geen opmerkingen