CrossCurve Bridge Exploit Exposes $3 Million Loss in Cross-Chain Security Breach

TheNewsCrypto發佈於 2026-02-02更新於 2026-02-02

文章摘要

CrossCurve, a cross-chain liquidity and bridge protocol, suffered a security breach resulting in approximately $3 million in losses. The exploit was caused by a missing security check in its smart contract, allowing attackers to send fake but valid-looking messages and drain tokens. The incident resembles the 2022 Nomad bridge hack and highlights that even protocols with multiple validation systems (like Axelar and LayerZero) remain vulnerable to single coding errors. CrossCurve and its backer, Curve Finance founder Michael Egorov, advise users to pause all interactions with the protocol, review exposures to CrossCurve-related pools, and await official updates.

CrossCurve, a cross-chain liquidity and bridge protocol, has confirmed that its bridge system was hacked, resulting in a loss of around $3 million. This affected multiple blockchains and is now under investigation. CrossCurve warns the users to pause all activity interacting with the protocol.

How Attackers Hacked the Bridge system

The missing security check from the CrossCurve smart contract was the major reason for this hack. The Smart Contract needs to verify the messages sent between the blockchains, but one of the verification steps was incommpleete which allowed the attackers to trick the system by sending fake messages that look valid to the system. This allowed the attacker to hack the token from the contract.

Security experts say that this exploit resembles the Nomad bridge hack in 2022, which drained around $190 million. They raised concerns that basic security mistakes are happening years later despite several past warnings.

CrossCurve has promoted its bridge as one of the safer and more secure bridges than others because it relies on multiple independent validation systems, such as Axelar, LayerZero, and its own oracle network. But this incident shows that despite multiple systems, a single coding mistake can still be exploited.

What must users do after this exploit?

The project, backed by Michael Egorov, the founder of Curve Finance, has reportedly raised around $7 million from investors. After the incident, Curve Finance warns users to review their positions and consider removing those who have exposure to CrossCurve-related pools.

Right now, the users should not interact with the CrossCurve until further notice and review any exposure to CrossCurve-related pools. They should look for any official updates from the team and be cautious with the cross-chain bridges.

Highlighted Crypto News:

U.S. Treasury Sanctions UK Crypto Exchanges for Iran Sanctions Evasion

TagsCross-ChainCryptocurrency

相關問答

QWhat was the primary cause of the CrossCurve Bridge security breach?

AThe primary cause was a missing security check in the CrossCurve smart contract, specifically an incomplete verification step for messages sent between blockchains, which allowed attackers to send fake but valid-looking messages.

QHow much was lost in the CrossCurve Bridge exploit?

AApproximately $3 million was lost in the exploit.

QWhich previous bridge hack does this incident resemble, according to security experts?

ASecurity experts stated that this exploit resembles the Nomad bridge hack in 2022, which resulted in a loss of around $190 million.

QWhat should users do in response to the CrossCurve exploit, as warned by the protocol?

AUsers should pause all activity interacting with the CrossCurve protocol, review their positions, and consider removing any exposure to CrossCurve-related pools until further official notice.

QWhat validation systems did CrossCurve promote as making its bridge secure before the incident?

ACrossCurve promoted its reliance on multiple independent validation systems, including Axelar, LayerZero, and its own oracle network, to claim it was one of the safer bridges.

你可能也喜歡

WEEX API Fast Connect:10秒内将每次登录转化为实盘交易者

WEEX宣布推出API快速连接(API Fast Connect),一种一键式OAuth授权系统。该系统允许用户无需手动处理API密钥即可关联其WEEX账户。该解决方案专为WEEX经纪商合作伙伴设计,旨在通过无缝的一键体验取代传统复杂的技术接入流程,从而在合作伙伴平台上实现更快的用户转化和更强的长期留存。 **核心要点:** * **功能:** 类似“使用Google登录”的一键授权系统,让用户无需创建或管理API密钥即可将其WEEX账户连接到第三方平台。 * **解决问题:** 手动API密钥设置是阻碍潜在用户成为活跃交易者的最大障碍。快速连接彻底消除了这一步骤。 * **获益:** 实现无摩擦转化,降低用户流失,提高留存率,使用户能在数秒内(而非数分钟)从登录进入实盘交易。 * **目标用户:** AI信号平台、量化策略工具、交易机器人以及任何目前需要用户手动配置API访问的WEEX经纪商合作伙伴。 **运作流程:** 1. 用户在合作平台点击“使用WEEX登录”。 2. 系统重定向至官方WEEX授权页面进行验证。 3. 用户确认API密钥的授权范围(默认为交易和读取权限)。 4. 确认后,系统在后台生成API密钥并通过加密通道直接绑定至合作平台。 **优势对比:** 与传统手动API密钥方式相比,快速连接在用户体验(一键操作 vs 手动碎片化流程)、权限管理(预设防错 vs 易出错)、密钥安全(后端加密,用户不接触密钥 vs 前端暴露高风险)和连接速度(即时绑定 vs 手动复制粘贴)方面均有显著提升。 API快速连接是WEEX经纪商工具包的核心组件之一,旨在帮助合作伙伴将感兴趣的用户迅速转化为实际交易者。

TheNewsCrypto9 分鐘前

WEEX API Fast Connect:10秒内将每次登录转化为实盘交易者

TheNewsCrypto9 分鐘前

Rubin Ultra大减配,英伟达也扛不住内存涨价了?

知名投研机构SemiAnalysis近日报告指出,英伟达已向主要客户预览了其顶级AI芯片Rubin Ultra的最新规格,但相比此前预期出现显著降配。核心变化包括:算力峰值保持与普通版Rubin相同的35 PFLOPs;显存容量降至8层堆叠的192GB,甚至低于普通版的288GB;显存带宽仅微升1TB/s;芯片功耗反而略有提高。Rubin Ultra的主要升级方向转向“扩展互联规模”,支持通过NVLink将最多576张GPU互联成统一计算域,远高于普通版的72张。 报告分析认为,此次调整主要源于HBM(高带宽内存)价格持续快速上涨。以HBM3为例,其价格已从2025年二季度的低点180-220美元,飙升至目前约700-850美元。HBM成本飙升使得Rubin Ultra单机架的物料成本一度从约660万美元升至800万美元。英伟达因此重新评估设计,通过减少昂贵的HBM配置(成本占比从近40%降至28%),将资源更多投入互联能力等方向,优化整体成本结构。 此消息引发市场对HBM需求见顶的担忧。受冲击影响,韩国存储股开盘大跌,SK海力士、三星股价均下挫约8%。市场解读认为,若英伟达此举成为趋势,意味着AI芯片厂商可能开始通过优化设计来降低对高容量HBM的依赖,这或将限制存储厂商未来的提价空间,标志着AI基础设施的“堆料涨价”时代可能接近尾声。

Odaily星球日报1 小時前

Rubin Ultra大减配,英伟达也扛不住内存涨价了?

Odaily星球日报1 小時前

交易

現貨
活动图片