CrossCurve Bridge Exploit Drains About $3M, Rekindling Cross-Chain Risk

ccn.comDipublikasikan tanggal 2026-02-02Terakhir diperbarui pada 2026-02-02

Abstrak

Cross-chain liquidity protocol CrossCurve suffered an exploit on February 2, with estimated losses around $3 million across multiple networks. The attack involved a spoofed cross-chain message that bypassed validation, allowing the attacker to trigger unauthorized token unlocks on the destination chain. The protocol urged users to pause interactions and launched an investigation. CEO Boris Povar later published ten Ethereum addresses linked to the stolen funds, offering a 10% bounty for their return within 72 hours and threatening legal action. The incident highlights persistent vulnerabilities in cross-chain bridges, where security often conflicts with user demand for speed. Verification failures and assumptions in smart contract logic remain critical risks, as a single flaw can lead to multi-network exploits.

Key Takeaways
  • CrossCurve said its bridge was “under attack” on Feb. 2 and told users to pause interactions.
  • Defimon Alerts, linked to Decurity, estimated losses around $3 million across “several networks.”
  • Early reporting and security posts described a spoofed cross-chain message that bypassed validation and triggered token unlocks on the destination chain.

Cross-chain liquidity protocol CrossCurve said its bridge was exploited on Feb. 2, with security monitors estimating roughly $3 million in losses across multiple networks.

The protocol urged users to pause interactions while it investigated.

Later, CEO Boris Povar published ten Ethereum addresses he said received funds and offered a bounty of up to 10% if the assets were returned within 72 hours, warning the project would pursue legal action if no contact was made.

Try Our Recommended Crypto Exchanges
Sponsored
Disclosure
We sometimes use affiliate links in our content, when clicking on those we might receive a commission at no extra cost to you. By using this website you agree to our terms and conditions and privacy policy.

Bitget

promotions
New user rewards up to 6,200 USDT.
Coins
88
Claim Offer

Bitunix

promotions
Receive up to $100,000 worth of exclusive gifts for newcomers upon registration.
Coins
151
Claim Offer

BTCC

promotions
Get up to 10,055 USDT when you register, verify, and make the first deposit and the first trades.
Coins
162
Claim Offer
Explore All Offers

CrossCurve Attack Timeline

CrossCurve said on Feb. 2 that its bridge was “under attack,” involving exploitation of a vulnerability in one of the smart contracts used in its cross-chain system.

The exploit allowed an attacker to spoof a message to bypass validation and unlock tokens.

One quoted description said an attacker could call an “express” execution path on a receiver contract using a forged cross-chain message, then trigger an unlock on a portal contract.

CrossCurve has not published a full post-mortem or confirmed a final loss figure. Separate estimates clustered around $3 million.

In a follow-up post, Povar said the team identified ten Ethereum addresses tied to received funds and set a 72-hour window to return assets or make contact before escalation.

He said the project was prepared to pursue civil and criminal remedies and coordinate with industry partners to freeze assets.

CrossCurve did not immediately respond to a request for comment on the specific bug, the final loss amount, or a timeline for reopening.

A separate warning came from Curve Finance, which said users allocated to CrossCurve pools “may wish to review their positions” and consider removing votes, urging “risk-aware decisions” when interacting with third parties.

Why Spoofed Messages and Validation Assumptions Keep Winning

Bridge exploits often look like “just a smart contract bug.” The deeper pattern is verification failure.

A bridge is a promise: release assets on Chain B because something real happened on Chain A. The hard part is proving that “something real” without trusting an attacker’s message.

In general message passing, the destination contract is supposed to verify that a call was approved by the validator set by checking with the gateway (for example, via a validation function) before executing.

If a receiver contract accepts an alternate path that skips or weakens that check, a forged message can become a payout.

That’s why the “receiver side” matters as much as the messaging layer.

A protocol can route messages through reputable infrastructure and still lose funds if its own destination contract implements permissive logic, unsafe fast paths, or incorrect assumptions about upstream guarantees.

CrossCurve’s own documentation frames cross-chain risk as a “black swan” category and describes a design goal of routing through multiple independent validation protocols (“Consensus Bridge”) to reduce single points of failure.

But even multi-path designs can be undermined by a weak integration contract at the edge.

The Uncomfortable Truth: Bridge UX Wants Speed, Security Wants Paranoia

Users want bridging to feel instant: fewer clicks, less waiting, faster finality.

Security wants the opposite: more confirmations, tighter limits, and “do nothing unless you’re sure.”

Some cross-chain stacks explicitly offer speed features like “express” execution, where off-chain actors can accelerate delivery of an intended outcome.

The trade-off is that fast paths demand extra care in how authenticity is enforced, because the system is trying to move before the slowest proofs arrive.

This tension is why bridge hacks stay evergreen. Bridges concentrate liquidity, and a single verification bypass can unlock assets across multiple networks in one run.

What To Watch Next

CrossCurve has not yet released a full incident report. In most bridge incidents, the next signals that matter are:

  • Whether contracts remain paused and what code changes ship before any restart.
  • Whether the attacker returns funds, often in exchange for a bounty.
  • Whether stablecoin issuers, exchanges, or analytics firms flag and freeze related addresses.
  • Whether independent security teams publish a corroborated root-cause analysis.

For now, the takeaway is familiar and still useful: cross-chain bridges remain one of crypto’s most repeatable failure points, because “truth across chains” is a hard engineering problem with real money behind every assumption.

This is a developing story and will be updated.

Recommended Secure Partners
  • Safest Exchanges Best Safest (Most Secure) Crypto Exchanges? Check Out These Exchanges
  • Secure Crypto Wallets Crypto Wallets Reviews and Ranked
  • Bet Anonymously Check Out Our Recommended No KYC Casinos

Pertanyaan Terkait

QWhat was the estimated financial loss from the CrossCurve bridge exploit?

AThe estimated financial loss from the CrossCurve bridge exploit was approximately $3 million across several networks.

QWhat was the technical cause of the CrossCurve exploit as described in early reports?

AThe exploit was caused by a spoofed cross-chain message that bypassed validation, which then triggered unauthorized token unlocks on the destination chain.

QWhat action did CrossCurve's CEO take in response to the attack?

ACrossCurve's CEO, Boris Povar, published ten Ethereum addresses that received the funds and offered a bounty of up to 10% if the assets were returned within 72 hours, warning of legal action if no contact was made.

QAccording to the article, what is the fundamental tension that makes bridge exploits a recurring problem?

AThe fundamental tension is that users want bridging to be fast and instant, while security requires more confirmations, tighter limits, and cautious verification, creating a conflict between user experience and security paranoia.

QWhat general warning did Curve Finance issue in relation to this incident?

ACurve Finance warned users allocated to CrossCurve pools to review their positions and consider removing votes, urging them to make 'risk-aware decisions' when interacting with third parties.

Bacaan Terkait

Dari Blokir Doubao hingga Sambut Glory, Mengapa WeChat Tiba-tiba "Berganti Wajah"?

Dari memblokir "Doubao" hingga berkolaborasi dengan "Honor": Mengapa WeChat tiba-tiba berubah sikap? WeChat, yang dimiliki Tencent, kini bekerja sama dengan produsen ponsel seperti Honor, Huawei, Xiaomi, OPPO, dan vivo untuk meluncurkan kemampuan A2A, memungkinkan asisten AI sistem ponsel (seperti YOYO Honor) memanggil fungsi WeChat melalui perintah suara, seperti mengirim pesan atau menelepon. Ini adalah perubahan besar mengingat sebelumnya WeChat dengan ketat memblokir upaya pihak ketiga (termasuk ponsel "Doubao" ByteDance) yang mengontrol aplikasinya melalui simulasi klik (GUI Agent). Perubahan ini didorong oleh tekanan kompetisi AI Tencent. Meskipun memiliki WeChat dengan 1,4 miliar pengguna bulanan, aplikasi AI-nya sendiri tertinggal dari pesaing seperti "Doubao" dan "Tongyi Qianwen". WeChat kini memprioritaskan pengembangan "agen AI" internal yang memanfaatkan ekosistem mini-programnya. Namun, untuk menjangkau pengguna, WeChat perlu terhubung dengan asisten AI tingkat sistem di ponsel, yang merupakan pintu masuk AI pertama bagi banyak pengguna. Kolaborasi A2A memungkinkan hal ini: asisten ponsel bertindak sebagai "operator" yang meneruskan perintah ke WeChat, yang kemudian mengeksekusinya di dalam lingkungannya sendiri. Skema ini menjaga kendali dan keamanan data WeChat, tidak seperti pendekatan GUI yang dianggap sebagai "perampasan". Bagi produsen ponsel, kolaborasi ini menarik karena jalur GUI terbukti tidak dapat diandalkan dan mudah diblokir. Meskipun mereka juga memiliki ambisi membangun ekosistem AI sendiri (seperti konsep AHI Honor), kerja sama A2A membuka akses yang sah dan terkontrol ke fungsi WeChat, sekaligus memungkinkan mereka fokus pada pengembangan kemampuan AI lainnya di luar WeChat. Kerja sama ini menggunakan mekanisme otorisasi ganda (pengguna dan aplikasi) untuk keamanan. Pada akhirnya, kolaborasi ini adalah bentuk "jabat tangan" strategis: Tencent mendapatkan pintu masuk AI di tingkat sistem ponsel, sementara produsen ponsel mendapatkan akses yang sah ke fungsi WeChat untuk meningkatkan kegunaan asisten AI mereka. Ini menandai babak baru dalam perebutan pintu masuk di era AI, di mana WeChat berusaha menjadi "sistem operasi layanan", sementara produsen ponsel beralih menjadi penyedia ekosistem AI. Pertarungan untuk menguasai interaksi utama pengguna dengan AI di perangkat mereka baru saja dimulai.

marsbit54m yang lalu

Dari Blokir Doubao hingga Sambut Glory, Mengapa WeChat Tiba-tiba "Berganti Wajah"?

marsbit54m yang lalu

Angka di On-Chain pada Malam Sebelum Kick-off: Piala Dunia Belum Dimulai, Sudah Terjual Rp 16 Miliar

Tujuh edisi sebelumnya membedah cara crypto masuk ke sepak bola. Kini, 6 hari sebelum kick-off Piala Dunia 2026, fokusnya adalah skala pasar on-chain. Hanya satu kontrak "Juara Piala Dunia" di platform Polymarket telah mencapai volume perdagangan kumulatif sekitar **$1,6 miliar** per 5 Juni, padahal pertandingan belum dimulai. Angka ini melonjak dari $368 juta pada Maret menjadi lebih dari $1,2 miliar di Mei. Volume industri pasar prediksi global melonjak 4x dari $16B (2024) menjadi ~$64B (2025). Platform seperti Polymarket dan Kalshi menawarkan ~100 kontrak yang mencakup semua 104 pertandingan, dari juara, top scorer, hingga hasil tiap laga. Harga kontrak (misal $0,53) mencerminkan probabilitas tersirat pasar (53%). Penyelesaian menggunakan stablecoin native USDC yang diatur dan oracle seperti Chainlink untuk hasil real-time. Perubahan infrastruktur kunci: (1) Settlement layer beralih ke stablecoin teratur (USDC). (2) Oracle terdesentralisasi (Chainlink) dipakai untuk resolusi otomatis. (3) FIFA menunjuk mitra resmi pertama di kategori "pasar prediksi" (ADI Predictstreet). Ini menandai pergeseran crypto dari sponsor pinggir lapangan menjadi bagian dari infrastruktur inti acara. Aset terkait sepak bola seperti Chiliz (CHZ) dan fan token negara (ARG, POR) juga aktif diperdagangkan mendekati turnamen. Penting dicatat: "pasar prediksi" (di bawah CFTC) berbeda secara hukum dari "taruhan olahraga" (lisensi negara bagian). Legalitasnya bervariasi di setiap yurisdiksi. Intinya: Meski bukan sponsor utama FIFA, teknologi crypto telah meresap ke dalam lapisan penyelesaian, prediksi, dan kemitraan resmi Piala Dunia ini. Pasar on-chain sudah "bermain" setahun sebelum kick-off pertama.

marsbit1j yang lalu

Angka di On-Chain pada Malam Sebelum Kick-off: Piala Dunia Belum Dimulai, Sudah Terjual Rp 16 Miliar

marsbit1j yang lalu

Dari IPO SpaceX Melihat Masa Depan Crypto: Sektor Crypto Mana yang Akan Menjadi Narasi Triliunan Dolar?

Penulis: Climber, CryptoPulse Labs Berdasarkan dokumen SEC terbaru, SpaceX berencana mengumpulkan $750 miliar dengan valuasi sekitar $1,77 triliun, mengintegrasikan roket, Starlink, AI, pusat data orbital, dan ekonomi luar angkasa ke dalam satu narasi besar. Peristiwa ini mengisyaratkan perubahan logika penilaian modal, yang dapat berdampak pada pasar crypto. Tiga sektor crypto yang mungkin mendapat aliran dana: 1. **AI Beralih ke Infrastruktur**: Modal mulai mencari "penjual sekop". Narasi bergeser dari aplikasi AI ke protokol lapisan dasar seperti jaringan komputasi (contoh: TAO, RENDER, AKT, IO) yang menyediakan sumber daya inti seperti daya komputasi GPU. 2. **RWA untuk Aset Masa Depan**: RWA (Real World Assets) dapat melampaui obligasi pemerintah, membuka akses ke aset ekuitas pra-IPO seperti SpaceX melalui tokenisasi. Ini berpotensi merekonstruksi pasar modal global, menguntungkan infrastruktur seperti ONDO dan LINK. 3. **Stablecoin, Pembayaran & DePIN sebagai Dasar Baru**: Seiring pertumbuhan ekonomi on-chain, stablecoin (sebagai infrastruktur keuangan global) dan jaringan pembayaran akan menjadi penting. DePIN (Jaringan Infrastruktur Fisik Terdesentralisasi) juga dapat dinilai ulang, mencerminkan nilai jaringan fisik seperti yang ditunjukkan Starlink. Kesimpulannya, IPO SpaceX mencerminkan pergeseran modal dari sekadar mengejar cerita (aplikasi) ke pengejaran infrastruktur dan arus kas. Sektor-sektor crypto yang membangun sistem dasar ini mungkin menjadi logika inti siklus pasar berikutnya.

marsbit2j yang lalu

Dari IPO SpaceX Melihat Masa Depan Crypto: Sektor Crypto Mana yang Akan Menjadi Narasi Triliunan Dolar?

marsbit2j yang lalu

Trading

Spot
Futures
活动图片