CrossCurve Bridge Exploit Exposes $3 Million Loss in Cross-Chain Security Breach

TheNewsCrypto發佈於 2026-02-02更新於 2026-02-02

文章摘要

CrossCurve, a cross-chain liquidity and bridge protocol, suffered a security breach resulting in approximately $3 million in losses. The exploit was caused by a missing security check in its smart contract, allowing attackers to send fake but valid-looking messages and drain tokens. The incident resembles the 2022 Nomad bridge hack and highlights that even protocols with multiple validation systems (like Axelar and LayerZero) remain vulnerable to single coding errors. CrossCurve and its backer, Curve Finance founder Michael Egorov, advise users to pause all interactions with the protocol, review exposures to CrossCurve-related pools, and await official updates.

CrossCurve, a cross-chain liquidity and bridge protocol, has confirmed that its bridge system was hacked, resulting in a loss of around $3 million. This affected multiple blockchains and is now under investigation. CrossCurve warns the users to pause all activity interacting with the protocol.

How Attackers Hacked the Bridge system

The missing security check from the CrossCurve smart contract was the major reason for this hack. The Smart Contract needs to verify the messages sent between the blockchains, but one of the verification steps was incommpleete which allowed the attackers to trick the system by sending fake messages that look valid to the system. This allowed the attacker to hack the token from the contract.

Security experts say that this exploit resembles the Nomad bridge hack in 2022, which drained around $190 million. They raised concerns that basic security mistakes are happening years later despite several past warnings.

CrossCurve has promoted its bridge as one of the safer and more secure bridges than others because it relies on multiple independent validation systems, such as Axelar, LayerZero, and its own oracle network. But this incident shows that despite multiple systems, a single coding mistake can still be exploited.

What must users do after this exploit?

The project, backed by Michael Egorov, the founder of Curve Finance, has reportedly raised around $7 million from investors. After the incident, Curve Finance warns users to review their positions and consider removing those who have exposure to CrossCurve-related pools.

Right now, the users should not interact with the CrossCurve until further notice and review any exposure to CrossCurve-related pools. They should look for any official updates from the team and be cautious with the cross-chain bridges.

Highlighted Crypto News:

U.S. Treasury Sanctions UK Crypto Exchanges for Iran Sanctions Evasion

TagsCross-ChainCryptocurrency

相關問答

QWhat was the primary cause of the CrossCurve Bridge security breach?

AThe primary cause was a missing security check in the CrossCurve smart contract, specifically an incomplete verification step for messages sent between blockchains, which allowed attackers to send fake but valid-looking messages.

QHow much was lost in the CrossCurve Bridge exploit?

AApproximately $3 million was lost in the exploit.

QWhich previous bridge hack does this incident resemble, according to security experts?

ASecurity experts stated that this exploit resembles the Nomad bridge hack in 2022, which resulted in a loss of around $190 million.

QWhat should users do in response to the CrossCurve exploit, as warned by the protocol?

AUsers should pause all activity interacting with the CrossCurve protocol, review their positions, and consider removing any exposure to CrossCurve-related pools until further official notice.

QWhat validation systems did CrossCurve promote as making its bridge secure before the incident?

ACrossCurve promoted its reliance on multiple independent validation systems, including Axelar, LayerZero, and its own oracle network, to claim it was one of the safer bridges.

你可能也喜歡

越过“内存墙”,AI推理时代的晶圆级革命与算力路线

2026年,AI产业进入新拐点:全球主要云厂商的推理资本支出首次超过训练。这意味着算力需求核心从“炼模型”转向“用模型”,瓶颈也从计算规模变为“内存墙”——即数据在GPU与片外存储间搬运带来的高能耗与延迟。 为突破内存墙,Cerebras公司选择了“晶圆级计算”的激进路线。其核心产品WSE-3不切割晶圆,直接制成超大芯片,集成90万个AI核心和44GB片上SRAM,带来远超传统GPU(如英伟达B200)的片上内存带宽。其架构将模型权重存储于片外MemoryX,按需流式传输至芯片计算,从而在LLM推理,尤其是首token延迟和长上下文任务中展现出显著优势,token生成速率可达GPU的1.5-5倍。同时,其芯片内互联功耗也远低于当前GPU。 但这种极致物理优化也带来挑战:通过先进制程提升SRAM容量的路径已近天花板;整片晶圆发热量大,需专用液冷;片外I/O带宽有限,难以高速扩展形成大规模集群;软件生态也与主流CUDA不兼容。 与此同时,行业巨头正通过多条路径围剿:1)自研ASIC推理芯片(如谷歌TPU、微软Maia);2)利用台积电SoW等先进封装技术将“晶圆级”能力通用化、平民化;3)探索光互联/光计算作为终极解决方案。 Cerebras还面临商业转型的挑战,巨额订单迫使其从芯片商转向云服务商,需快速建设专用数据中心,交付压力巨大。 最终,AI推理时代的算力架构呈现路线分野:Cerebras向左,追求单任务下的极致低延迟;英伟达向右,以通用性应对多变负载。技术变革仍在继续,谁将主导未来,尚无定论。

marsbit14 分鐘前

越过“内存墙”,AI推理时代的晶圆级革命与算力路线

marsbit14 分鐘前

TechFlow 情报局:Anthropic 呼吁全球暂停 AI 开发却正筹备万亿美元 IPO,SpaceX IPO 路演火爆但 S&P 500 拒绝快速纳入

本期科技资讯围绕“信任危机”展开。Anthropic公开呼吁暂停全球AI开发,称其Claude模型存在“递归自我改进”风险,但该公司自身正筹备估值近万亿美元的IPO,引发外界质疑其动机。同时,大量用户抱怨Claude近期体验质量大幅下滑。 在加密领域,比特币价格跌破6.1万美元,导致超11亿美元多单爆仓,市场情绪转向悲观。与此同时,AI在生物医药领域取得突破,全球首款AI设计疫苗完成首阶段人体试验。 芯片方面,英伟达CEO黄仁勋访韩,宣布三星、SK海力士和美光的HBM4内存均已通过认证。但有经济学家警告,英伟达可能面临类似2000年互联网泡沫时期思科的风险。 科技公司动态中,Cloudflare收购前端工具链公司VoidZero,其CEO称互联网上机器人流量已超过真人。字节跳动的AI应用“豆包”推出付费订阅后,月活用户锐减超600万,凸显商业化困境。 美股市场焦点在SpaceX,其IPO路演备受追捧,高盛预测其2030年收入将增长百倍。然而,标普道琼斯指数公司明确表示不会为SpaceX等巨型IPO修改快速纳入规则,为其上市后表现增添不确定性。 总体而言,当前科技领域呈现“言行不一”的割裂现象,无论是AI公司、加密货币还是应用商业化,都面临信任拷问,市场狂热叙事与冷静规则之间形成鲜明对比。

marsbit30 分鐘前

TechFlow 情报局:Anthropic 呼吁全球暂停 AI 开发却正筹备万亿美元 IPO,SpaceX IPO 路演火爆但 S&P 500 拒绝快速纳入

marsbit30 分鐘前

交易

現貨
合約
活动图片