CrossCurve Bridge Exploit Exposes $3 Million Loss in Cross-Chain Security Breach

TheNewsCrypto发布于2026-02-02更新于2026-02-02

文章摘要

CrossCurve, a cross-chain liquidity and bridge protocol, suffered a security breach resulting in approximately $3 million in losses. The exploit was caused by a missing security check in its smart contract, allowing attackers to send fake but valid-looking messages and drain tokens. The incident resembles the 2022 Nomad bridge hack and highlights that even protocols with multiple validation systems (like Axelar and LayerZero) remain vulnerable to single coding errors. CrossCurve and its backer, Curve Finance founder Michael Egorov, advise users to pause all interactions with the protocol, review exposures to CrossCurve-related pools, and await official updates.

CrossCurve, a cross-chain liquidity and bridge protocol, has confirmed that its bridge system was hacked, resulting in a loss of around $3 million. This affected multiple blockchains and is now under investigation. CrossCurve warns the users to pause all activity interacting with the protocol.

How Attackers Hacked the Bridge system

The missing security check from the CrossCurve smart contract was the major reason for this hack. The Smart Contract needs to verify the messages sent between the blockchains, but one of the verification steps was incommpleete which allowed the attackers to trick the system by sending fake messages that look valid to the system. This allowed the attacker to hack the token from the contract.

Security experts say that this exploit resembles the Nomad bridge hack in 2022, which drained around $190 million. They raised concerns that basic security mistakes are happening years later despite several past warnings.

CrossCurve has promoted its bridge as one of the safer and more secure bridges than others because it relies on multiple independent validation systems, such as Axelar, LayerZero, and its own oracle network. But this incident shows that despite multiple systems, a single coding mistake can still be exploited.

What must users do after this exploit?

The project, backed by Michael Egorov, the founder of Curve Finance, has reportedly raised around $7 million from investors. After the incident, Curve Finance warns users to review their positions and consider removing those who have exposure to CrossCurve-related pools.

Right now, the users should not interact with the CrossCurve until further notice and review any exposure to CrossCurve-related pools. They should look for any official updates from the team and be cautious with the cross-chain bridges.

Highlighted Crypto News:

U.S. Treasury Sanctions UK Crypto Exchanges for Iran Sanctions Evasion

TagsCross-ChainCryptocurrency

相关问答

QWhat was the primary cause of the CrossCurve Bridge security breach?

AThe primary cause was a missing security check in the CrossCurve smart contract, specifically an incomplete verification step for messages sent between blockchains, which allowed attackers to send fake but valid-looking messages.

QHow much was lost in the CrossCurve Bridge exploit?

AApproximately $3 million was lost in the exploit.

QWhich previous bridge hack does this incident resemble, according to security experts?

ASecurity experts stated that this exploit resembles the Nomad bridge hack in 2022, which resulted in a loss of around $190 million.

QWhat should users do in response to the CrossCurve exploit, as warned by the protocol?

AUsers should pause all activity interacting with the CrossCurve protocol, review their positions, and consider removing any exposure to CrossCurve-related pools until further official notice.

QWhat validation systems did CrossCurve promote as making its bridge secure before the incident?

ACrossCurve promoted its reliance on multiple independent validation systems, including Axelar, LayerZero, and its own oracle network, to claim it was one of the safer bridges.

你可能也喜欢

Coinbase在最新扩张中为英国用户推出加密支持的USDC贷款

基于其在美国的成功经验,加密货币交易所Coinbase已为英国居民推出以加密货币为抵押的USDC贷款服务,接受比特币(BTC)和以太坊(ETH)作为抵押品。此举进一步扩展了该交易所在该地区不断增长的金融服务范围。 英国用户现可通过链上协议Morpho(基于Base网络)使用比特币、以太坊及Coinbase包装质押以太坊(cbETH)作为抵押,即时借入USDC。根据抵押的BTC数量,用户最高可借入500万美元的USDC。抵押品将锁定在Morpho智能合约中,直至贷款全额偿还,且无固定还款计划,但若贷款价值比超过特定阈值,抵押品将被清算并收取罚金。 自2025年1月在美国推出以来,该贷款服务需求强劲,截至2026年4月14日,通过Morpho的贷款发放总额已超过21.7亿USDC。Coinbase计划近期在更多国家推广此项服务。 此外,Coinbase于2025年2月成功获得英国金融行为监管局(FCA)注册为加密服务提供商,随后在2025年11月和2026年4月分别推出了英国储蓄账户和去中心化交易所(DEX)交易服务。近期还与Better Home & Finance合作推出抵押贷款产品,允许用户使用加密货币作为购房首付抵押,并获得了美国货币监理署(OCC)的条件批准,成立Coinbase国家信托公司,迈向联邦监管加密托管机构的重要一步。

bitcoinist4小时前

Coinbase在最新扩张中为英国用户推出加密支持的USDC贷款

bitcoinist4小时前

交易

现货
合约
活动图片