CrossCurve Bridge Exploit Exposes $3 Million Loss in Cross-Chain Security Breach

TheNewsCryptoPublicado em 2026-02-02Última atualização em 2026-02-02

Resumo

CrossCurve, a cross-chain liquidity and bridge protocol, suffered a security breach resulting in approximately $3 million in losses. The exploit was caused by a missing security check in its smart contract, allowing attackers to send fake but valid-looking messages and drain tokens. The incident resembles the 2022 Nomad bridge hack and highlights that even protocols with multiple validation systems (like Axelar and LayerZero) remain vulnerable to single coding errors. CrossCurve and its backer, Curve Finance founder Michael Egorov, advise users to pause all interactions with the protocol, review exposures to CrossCurve-related pools, and await official updates.

CrossCurve, a cross-chain liquidity and bridge protocol, has confirmed that its bridge system was hacked, resulting in a loss of around $3 million. This affected multiple blockchains and is now under investigation. CrossCurve warns the users to pause all activity interacting with the protocol.

How Attackers Hacked the Bridge system

The missing security check from the CrossCurve smart contract was the major reason for this hack. The Smart Contract needs to verify the messages sent between the blockchains, but one of the verification steps was incommpleete which allowed the attackers to trick the system by sending fake messages that look valid to the system. This allowed the attacker to hack the token from the contract.

Security experts say that this exploit resembles the Nomad bridge hack in 2022, which drained around $190 million. They raised concerns that basic security mistakes are happening years later despite several past warnings.

CrossCurve has promoted its bridge as one of the safer and more secure bridges than others because it relies on multiple independent validation systems, such as Axelar, LayerZero, and its own oracle network. But this incident shows that despite multiple systems, a single coding mistake can still be exploited.

What must users do after this exploit?

The project, backed by Michael Egorov, the founder of Curve Finance, has reportedly raised around $7 million from investors. After the incident, Curve Finance warns users to review their positions and consider removing those who have exposure to CrossCurve-related pools.

Right now, the users should not interact with the CrossCurve until further notice and review any exposure to CrossCurve-related pools. They should look for any official updates from the team and be cautious with the cross-chain bridges.

Highlighted Crypto News:

U.S. Treasury Sanctions UK Crypto Exchanges for Iran Sanctions Evasion

TagsCross-ChainCryptocurrency

Perguntas relacionadas

QWhat was the primary cause of the CrossCurve Bridge security breach?

AThe primary cause was a missing security check in the CrossCurve smart contract, specifically an incomplete verification step for messages sent between blockchains, which allowed attackers to send fake but valid-looking messages.

QHow much was lost in the CrossCurve Bridge exploit?

AApproximately $3 million was lost in the exploit.

QWhich previous bridge hack does this incident resemble, according to security experts?

ASecurity experts stated that this exploit resembles the Nomad bridge hack in 2022, which resulted in a loss of around $190 million.

QWhat should users do in response to the CrossCurve exploit, as warned by the protocol?

AUsers should pause all activity interacting with the CrossCurve protocol, review their positions, and consider removing any exposure to CrossCurve-related pools until further official notice.

QWhat validation systems did CrossCurve promote as making its bridge secure before the incident?

ACrossCurve promoted its reliance on multiple independent validation systems, including Axelar, LayerZero, and its own oracle network, to claim it was one of the safer bridges.

Leituras Relacionadas

The Encryption Bill Clarity's Challenge: A Thorny Path of Bipartisan Compromise in the U.S.

U.S. lawmakers are attempting to advance the Clarity Act, a significant crypto market structure bill, but its path is fraught with partisan hurdles. The process has been rocky since January, when a prior bipartisan deal in the Senate Banking Committee was upended. A key compromise in May on "yield" issues allowed the bill to move forward in committee, but only with the conditional support of two Democratic senators, Angela Alsobrooks and Ruben Gallego. They emphasized that their final vote depends on reaching an agreement on ethics provisions for elected officials. Ultimately, the Senate Agriculture Committee passed its version along party lines without Democratic support. As Republicans push for a full Senate vote in July, the demand for strong ethics language has expanded beyond Democrats. Additional controversies surround provisions related to yields (aligning some Republicans with large banks) and developer protections (opposed by enforcement agencies). Core concerns about illicit finance and consumer protection remain central to the debate. Despite consensus on the need for legislation, achieving the necessary bipartisan compromise is proving difficult. While momentum exists—including recent meetings between senators and White House officials—a reconciled bill text faces skepticism. Senator Gallego has stated that without ethics terms acceptable to Democrats, they will not provide the needed votes. The immediate goals for the crypto community in Congress are unclear: a symbolic Senate vote before the August recess, eventual passage into law by 2026, or forging a final compromise framework. The arduous, vote-by-vote effort to build bipartisan support continues, mirroring the traditional legislative grind the industry must now navigate.

Foresight NewsHá 50m

The Encryption Bill Clarity's Challenge: A Thorny Path of Bipartisan Compromise in the U.S.

Foresight NewsHá 50m

Kalshi and Polymarket Founders at Odds? This Business War Is Far More Brutal Than You Imagine

The New York Times details the fierce, personal rivalry between Kalshi CEO Tarek Mansour and Polymarket founder Shayne Coplan, which has escalated beyond typical business competition into a conflict marked by legal complaints, regulatory battles, and public hostilities. The feud intensified in late 2024 when FBI agents raided Coplan's New York apartment. While Coplan publicly blamed political motives, sources indicate his team privately suspected Mansour, noting that Kalshi's lawyers had previously reported Polymarket's operational model to federal prosecutors, highlighting that U.S. users could still access its offshore platform despite a ban. The animosity extends through their companies' operations. Kalshi positions itself as a compliance-focused, fully licensed U.S. operator, while Polymarket has historically operated its core platform offshore without a U.S. license, offering more anonymity and controversial betting markets. Mansour has publicly called Polymarket's model "illegal and immoral," while Coplan privately dismisses Kalshi as a copycat. Their competition has played out in Washington lobbying, attempts to sabotage each other's major deals (such as Kalshi's efforts to dissuade Intercontinental Exchange from investing in Polymarket), competing sponsorships, and poaching staff. The rivalry continues as both platforms experience massive growth, with Kalshi currently holding a valuation and trading volume edge, but facing ongoing regulatory scrutiny alongside Polymarket.

Foresight NewsHá 1h

Kalshi and Polymarket Founders at Odds? This Business War Is Far More Brutal Than You Imagine

Foresight NewsHá 1h

Trading

Spot
活动图片