CrossCurve Bridge Exploit Exposes $3 Million Loss in Cross-Chain Security Breach

TheNewsCryptoPublicado a 2026-02-02Actualizado a 2026-02-02

Resumen

CrossCurve, a cross-chain liquidity and bridge protocol, suffered a security breach resulting in approximately $3 million in losses. The exploit was caused by a missing security check in its smart contract, allowing attackers to send fake but valid-looking messages and drain tokens. The incident resembles the 2022 Nomad bridge hack and highlights that even protocols with multiple validation systems (like Axelar and LayerZero) remain vulnerable to single coding errors. CrossCurve and its backer, Curve Finance founder Michael Egorov, advise users to pause all interactions with the protocol, review exposures to CrossCurve-related pools, and await official updates.

CrossCurve, a cross-chain liquidity and bridge protocol, has confirmed that its bridge system was hacked, resulting in a loss of around $3 million. This affected multiple blockchains and is now under investigation. CrossCurve warns the users to pause all activity interacting with the protocol.

How Attackers Hacked the Bridge system

The missing security check from the CrossCurve smart contract was the major reason for this hack. The Smart Contract needs to verify the messages sent between the blockchains, but one of the verification steps was incommpleete which allowed the attackers to trick the system by sending fake messages that look valid to the system. This allowed the attacker to hack the token from the contract.

Security experts say that this exploit resembles the Nomad bridge hack in 2022, which drained around $190 million. They raised concerns that basic security mistakes are happening years later despite several past warnings.

CrossCurve has promoted its bridge as one of the safer and more secure bridges than others because it relies on multiple independent validation systems, such as Axelar, LayerZero, and its own oracle network. But this incident shows that despite multiple systems, a single coding mistake can still be exploited.

What must users do after this exploit?

The project, backed by Michael Egorov, the founder of Curve Finance, has reportedly raised around $7 million from investors. After the incident, Curve Finance warns users to review their positions and consider removing those who have exposure to CrossCurve-related pools.

Right now, the users should not interact with the CrossCurve until further notice and review any exposure to CrossCurve-related pools. They should look for any official updates from the team and be cautious with the cross-chain bridges.

Highlighted Crypto News:

U.S. Treasury Sanctions UK Crypto Exchanges for Iran Sanctions Evasion

TagsCross-ChainCryptocurrency

Preguntas relacionadas

QWhat was the primary cause of the CrossCurve Bridge security breach?

AThe primary cause was a missing security check in the CrossCurve smart contract, specifically an incomplete verification step for messages sent between blockchains, which allowed attackers to send fake but valid-looking messages.

QHow much was lost in the CrossCurve Bridge exploit?

AApproximately $3 million was lost in the exploit.

QWhich previous bridge hack does this incident resemble, according to security experts?

ASecurity experts stated that this exploit resembles the Nomad bridge hack in 2022, which resulted in a loss of around $190 million.

QWhat should users do in response to the CrossCurve exploit, as warned by the protocol?

AUsers should pause all activity interacting with the CrossCurve protocol, review their positions, and consider removing any exposure to CrossCurve-related pools until further official notice.

QWhat validation systems did CrossCurve promote as making its bridge secure before the incident?

ACrossCurve promoted its reliance on multiple independent validation systems, including Axelar, LayerZero, and its own oracle network, to claim it was one of the safer bridges.

Lecturas Relacionadas

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

Coldcard Hardware Wallet Hacked: Losses Mount Due to Vulnerable Seed Generation A critical vulnerability in Coldcard hardware wallets has led to a continued wave of fund thefts. According to Galaxy Research, the total stolen has reached 1,367.05 BTC (approx. $88.6 million) from 4,585 addresses, a significant increase from the initial 594.5 BTC reported on July 30, 2026. Most of the stolen funds remain on the attackers' addresses. The issue is not with the current firmware, which Coinkite has updated, but with seed phrases generated on vulnerable devices between March 2021 and the release of fixed firmware versions. Due to a programmer error, devices switched from using a hardware random number generator to the software-based Yasmarang generator, which was initialized with publicly accessible data like the chip's serial number. This made the seed phrases predictable through offline brute-force attacks, meaning wallets remain at risk until funds are moved to a new wallet generated with the patched firmware. Affected devices include Mk2/Mk3 with firmware 4.0.1–4.1.9 (and up to 5.0.3), Mk4/Mk5 up to version 5.6.0, and Q models up to 1.5.0Q. The only exceptions are seeds created with a high-entropy method like at least 50 independent dice rolls or a strong unique BIP-39 passphrase. All other owners must generate a new seed on the fixed firmware and transfer their assets. A case highlighting the human impact involves a 39-year-old long-term investor who lost 2 BTC (approx. $130,000) in minutes. He had accumulated the Bitcoin over eight years through physical labor, viewing it as a financial lifeline and a retirement plan in a country suffering from hyperinflation. His story underscores that even conservative "buy and hold in cold storage" strategies can be compromised by such underlying technical flaws. From a technical perspective, this incident echoes historical failures where weak random number generators undermined cryptographic security, challenging the assumption that offline storage is automatically foolproof.

cryptonews.ruHace 4 hora(s)

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

cryptonews.ruHace 4 hora(s)

Trading

Spot
活动图片