CrossCurve Bridge Exploit Exposes $3 Million Loss in Cross-Chain Security Breach

TheNewsCrypto發佈於 2026-02-02更新於 2026-02-02

文章摘要

CrossCurve, a cross-chain liquidity and bridge protocol, suffered a security breach resulting in approximately $3 million in losses. The exploit was caused by a missing security check in its smart contract, allowing attackers to send fake but valid-looking messages and drain tokens. The incident resembles the 2022 Nomad bridge hack and highlights that even protocols with multiple validation systems (like Axelar and LayerZero) remain vulnerable to single coding errors. CrossCurve and its backer, Curve Finance founder Michael Egorov, advise users to pause all interactions with the protocol, review exposures to CrossCurve-related pools, and await official updates.

CrossCurve, a cross-chain liquidity and bridge protocol, has confirmed that its bridge system was hacked, resulting in a loss of around $3 million. This affected multiple blockchains and is now under investigation. CrossCurve warns the users to pause all activity interacting with the protocol.

How Attackers Hacked the Bridge system

The missing security check from the CrossCurve smart contract was the major reason for this hack. The Smart Contract needs to verify the messages sent between the blockchains, but one of the verification steps was incommpleete which allowed the attackers to trick the system by sending fake messages that look valid to the system. This allowed the attacker to hack the token from the contract.

Security experts say that this exploit resembles the Nomad bridge hack in 2022, which drained around $190 million. They raised concerns that basic security mistakes are happening years later despite several past warnings.

CrossCurve has promoted its bridge as one of the safer and more secure bridges than others because it relies on multiple independent validation systems, such as Axelar, LayerZero, and its own oracle network. But this incident shows that despite multiple systems, a single coding mistake can still be exploited.

What must users do after this exploit?

The project, backed by Michael Egorov, the founder of Curve Finance, has reportedly raised around $7 million from investors. After the incident, Curve Finance warns users to review their positions and consider removing those who have exposure to CrossCurve-related pools.

Right now, the users should not interact with the CrossCurve until further notice and review any exposure to CrossCurve-related pools. They should look for any official updates from the team and be cautious with the cross-chain bridges.

Highlighted Crypto News:

U.S. Treasury Sanctions UK Crypto Exchanges for Iran Sanctions Evasion

TagsCross-ChainCryptocurrency

相關問答

QWhat was the primary cause of the CrossCurve Bridge security breach?

AThe primary cause was a missing security check in the CrossCurve smart contract, specifically an incomplete verification step for messages sent between blockchains, which allowed attackers to send fake but valid-looking messages.

QHow much was lost in the CrossCurve Bridge exploit?

AApproximately $3 million was lost in the exploit.

QWhich previous bridge hack does this incident resemble, according to security experts?

ASecurity experts stated that this exploit resembles the Nomad bridge hack in 2022, which resulted in a loss of around $190 million.

QWhat should users do in response to the CrossCurve exploit, as warned by the protocol?

AUsers should pause all activity interacting with the CrossCurve protocol, review their positions, and consider removing any exposure to CrossCurve-related pools until further official notice.

QWhat validation systems did CrossCurve promote as making its bridge secure before the incident?

ACrossCurve promoted its reliance on multiple independent validation systems, including Axelar, LayerZero, and its own oracle network, to claim it was one of the safer bridges.

你可能也喜歡

全球股市的风暴点:韩国股市的去杠杆已基本完成

近期韩国股市出现剧烈波动,KOSPI指数自6月高点最大回撤达32%,成为全球AI行情调整的“风暴中心”。文章指出,市场下跌的深层原因并非基本面恶化,而是由高度集中的杠杆资金结构所驱动。 具体来看,核心风险来源于两方面: 1. **杠杆ETF大规模去化**:前期规模一度接近500亿美元的杠杆ETF,其“每日再平衡”机制在下跌中引发了“股价下跌→强制平仓”的负向循环。目前其规模已从高点收缩约240亿美元,去化进度已达约75%,剩余压力显著收敛。监管层也已出台新规,从8月起严格限制此类产品,从源头降低风险。 2. **对冲基金快速降杠杆**:通过互换交易放大敞口的对冲基金,其多空持仓比率已从峰值显著回落,净多头水平显示杠杆已下降超过50%,最剧烈的被动去杠杆阶段基本完成。 相比之下,韩国居民融资余额占股市市值比重很小(约0.5%),且不具备强制平仓机制,难以成为系统性风险的核心来源。 综合而言,最容易引发“连锁抛售”的高杠杆结构已大部分出清,市场正从“流动性驱动的下跌”过渡到“基本面驱动的定价”。只要AI产业趋势未发生根本逆转,本轮调整更接近一次拥挤交易的集中出清,而非行情的终结。 文章最后强调,AI代表的硅基革命趋势不可逆,波动是参与趋势的成本而非风险。每一次调整都是在进行筹码结构的优化,并为认清趋势的投资者提供新的参与机会。

链捕手24 分鐘前

全球股市的风暴点:韩国股市的去杠杆已基本完成

链捕手24 分鐘前

自2024年以来推出的加密货币代币中,92.9%跌破发行价:CryptoRank

加密货币数据平台CryptoRank的最新研究显示,自2024年以来发行的加密货币代币中,有高达92.9%目前正低于其代币生成事件(TGE)时的初始价格。 该分析聚焦于市值超过1亿美元的项目,在2024年至2026年间发行的113个项目中,仅有8个仍保持在发行价之上,其余105个均已跌破。这意味着只有约7.1%的项目为投资者带来了正回报,而整体样本的中位数回报率低至-95.7%。 表现最突出的项目是Hyperliquid (HYPE),自TGE以来上涨了1,519%。其次是Ondo Finance (ONDO)、EverValue Coin (EVA)和Midnight Network (NIGHT),涨幅分别为101.4%、20.32%和16.50%。 数据表明,与过去市场周期中新股常持续上涨不同,当前投资者变得更加挑剔。资本正越来越集中于少数已证明其产品采用度、生态增长或强劲市场需求的项目。许多新代币难以维持初始估值。 这一趋势反映了市场关注点的转变:投资者愈发看重代币经济学、流通供应量、解锁时间表和长期实用性,而非仅关注上市初期的价格动能。 研究结果可能影响未来项目的发行策略。项目因过高的完全稀释估值(FDV)、上市初期流通量不足以及大量未来代币解锁计划而备受审视,这些因素都可能在新供应进入市场时对价格构成下行压力。因此,开发者和投资者未来或将更重视可持续的代币分发模式和长期的生态增长,而非激进的初始估值。

ambcrypto25 分鐘前

自2024年以来推出的加密货币代币中,92.9%跌破发行价:CryptoRank

ambcrypto25 分鐘前

交易

現貨
活动图片