The cross-chain bridge CrossCurve, formerly known as EYWA, confirmed it was actively under attack after a security exploit drained roughly $3 million in user assetsThe cross-chain bridge CrossCurve, formerly known as EYWA, confirmed it was actively under attack after a security exploit drained roughly $3 million in user assets

CrossCurve Bridge Hit by $3M Exploit as Message Spoofing Strikes Again

2026/02/02 10:47
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

The cross-chain bridge CrossCurve, formerly known as EYWA, confirmed it was actively under attack after a security exploit drained roughly $3 million in user assets.

The incident quickly drew comparisons to earlier bridge failures, underscoring how long-standing vulnerabilities in cross-chain messaging continue to resurface across the ecosystem.

The exploit unfolded over January 31 and February 1, triggering immediate concern among users and security researchers as funds were siphoned from the protocol’s core contracts across multiple connected networks.

How the Exploit Worked

According to early technical breakdowns, the attack relied on a message spoofing flaw similar in structure to the 2022 Nomad bridge incident.

At the center of the issue was a missing validation check in CrossCurve’s smart contracts, which left a critical execution path insufficiently protected.

Attackers were able to invoke the expressExecute function using spoofed cross-chain messages. By doing so, they effectively bypassed the protocol’s intended gateway verification logic and triggered unauthorized executions directly within the PortalV2 contract. This flaw allowed token unlocks to occur without legitimate cross-chain authorization, giving attackers direct access to protocol-held assets.

The mechanism did not require sophisticated key compromises or oracle manipulation. Instead, it exploited a logic gap in message verification, a category of vulnerability that has repeatedly plagued cross-chain infrastructure.

Impact Across the Protocol

On-chain data from Arkham Intelligence showed the PortalV2 contract balance falling from approximately $3 million to near zero during the attack window. The rapid depletion suggested a largely unimpeded exploit path once the vulnerability was discovered.

The impact was not confined to a single chain. Because CrossCurve connects multiple networks, the exploit appeared to affect assets spanning several ecosystems, amplifying the overall damage and complicating containment efforts.

CrossCurve is backed by Michael Egorov, founder of Curve Finance, and had previously raised $7 million to develop its consensus-based bridging mechanism. The incident therefore carries broader reputational implications beyond the immediate financial loss.

Which Crypto Exchanges Dominated Spot Trading in 2025?

Security Community Reaction

The exploit prompted renewed frustration among security researchers. Taylor Monahan highlighted that message spoofing vulnerabilities remain a recurring failure mode in cross-chain systems, despite years of high-profile lessons from earlier bridge hacks.

The underlying issue, as experts note, is structural. Cross-chain protocols rely heavily on correct message validation across heterogeneous environments, making even small logic oversights potentially catastrophic. The CrossCurve incident reinforces how unforgiving this design space remains.

Takeaway

The CrossCurve exploit is less about a novel attack vector and more about a familiar one reappearing under a new name. Missing validation checks and spoofed messages continue to represent systemic risks for cross-chain bridges, regardless of funding, backing, or architectural ambition. Until message verification is treated as a zero-tolerance surface, similar incidents are likely to remain a recurring feature of cross-chain infrastructure rather than a solved problem.

The post CrossCurve Bridge Hit by $3M Exploit as Message Spoofing Strikes Again appeared first on ETHNews.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

USDH Power Struggle Ignites Stablecoin “Bidding Wars” Across DeFi: Bloomberg

USDH Power Struggle Ignites Stablecoin “Bidding Wars” Across DeFi: Bloomberg

A heated contest for control over a new dollar-pegged token has set the stage for what analysts say could define the next phase of the stablecoin industry. According to Bloomberg, a bidding war unfolded on Hyperliquid, one of crypto’s fastest-growing trading platforms, with the prize being the right to issue USDH, its native stablecoin. The competition drew some of the sector’s most prominent names, including Paxos, Sky, and Ethena, who later withdrew their bid, alongside the lesser-known Native Markets, a startup backed by Stripe stablecoin subsidiary Bridge. Hyperliquid Stablecoin Race Shows Branding and Partnerships Matter as Much as Tech Over the weekend, Hyperliquid’s validators, the contributors who secure the network and vote on key decisions, awarded the USDH contract to Native Markets over the weekend. Despite its relatively new status, the firm’s connection with Stripe helped it outpace more established rivals. Stablecoins underpin decentralized finance by providing a dollar-backed medium for collateral, settlement, and payments across applications. What began as a grassroots, community-led sector has evolved into a battleground for institutions and payment companies seeking revenue from interest on reserves. Circle, for example, shares proceeds from its USDC with Coinbase under a partnership designed to stabilize earnings during market swings. The Hyperliquid contest offered a rare glimpse into just how intense competition has become. Paxos pledged to take no revenue until USDH surpassed $1 billion in circulation. Agora offered to share 100% of net revenue with Hyperliquid, while Ethena put forward 95%. All were outbid by Native Markets, whose ties to Stripe’s $1.1 billion acquisition of Bridge and subsequent rollout of the Tempo blockchain positioned it as a strong contender. “Every stablecoin issuer is extremely desperate for supply,” said Zaheer Ebtikar, co-founder of Split Capital. “They are willing to publicly announce how much they are willing to offer. It just shows it’s a very tough business for stablecoin issuers.” While USDC remains dominant on Hyperliquid with more than $5.6 billion in deposits, the arrival of USDH could shift flows and revenue dynamics. Paxos co-founder Bhau Kotecha said the firm sees the exchange’s growth as an important opportunity, while Agora’s co-founder Nick van Eck warned that awarding the contract to a vertically integrated issuer risked undermining decentralization. Regulatory positioning also factored into the debate. Paxos operates under a New York trust charter and is seeking a federal license, while Bridge holds money transmitter approvals in 30 states. Native Markets, in a blog post, cited regulatory flexibility and deployment speed as reasons for its selection. Hyperliquid said the strong engagement from its community validated the process. Circle CEO Jeremy Allaire dismissed concerns over USDC’s status, noting on X that competition benefits the ecosystem. Analysts suggested that fears of centralization may be exaggerated, noting that Hyperliquid is likely to remain neutral and support multiple stablecoins. Still, the contest over USDH highlighted a new reality for stablecoins: branding, partnerships, and business strategy are becoming as decisive as technology. Native Markets Secures USDH Stablecoin Mandate on Hyperliquid Hyperliquid has concluded its governance vote for the USDH stablecoin, awarding the mandate to Native Markets after a closely watched process that drew weeks of community debate and rival proposals. USDH, described by Hyperliquid as a “Hyperliquid-first, compliant, and natively minted” dollar-backed token, is intended to reduce the platform’s dependence on USDC and strengthen its spot markets. Validators on the decentralized exchange voted in favor of Native Markets, a relatively new player backed by Stripe’s Bridge subsidiary, over established contenders including Paxos and Ethena. The outcome followed a string of proposals offering aggressive revenue-sharing terms to win validator support, underscoring the scale of incentives attached to controlling USDH. Hyperliquid’s exchange has become a critical hub for stablecoin liquidity, with $5.7 billion in USDC, around 8% of its total supply, currently held on the network. At prevailing treasury yields, that translates to an estimated $200 million to $220 million in annual revenue for Circle, underlining why a native alternative could be transformative. Hyperliquid’s validators, who secure the network and vote on key decisions, selected Native Markets following an on-chain governance process that concluded September 15. Native Markets has laid out a phased rollout for USDH, beginning with capped minting and redemption trials before expanding into spot markets. Its reserves will be managed in cash and treasuries by BlackRock, with on-chain tokenization through Superstate and Bridge. Yield from those reserves will be split between Hyperliquid’s Assistance Fund and ecosystem development. The launch of USDH comes as Hyperliquid records record profits from perpetual futures trading, with $106 million in revenue in August alone, and prepares to slash spot trading fees by 80% to bolster liquidity. Analysts say the move positions Hyperliquid to capture more of the stablecoin economics internally, marking a significant step in its bid to rival the largest players in decentralized finance
Share
CryptoNews2025/09/18 00:48
XRP Price Prediction: Could XRP Hit $10 or Will a 150x Presale Get There First

XRP Price Prediction: Could XRP Hit $10 or Will a 150x Presale Get There First

A sudden BTC bounce from $66,800 just jolted the entire market, dragging altcoins up and forcing late sellers to cover in a move that instantly changed short term
Share
Techbullion2026/03/29 03:34
How a Dutch IPTV Provider Is Rethinking the Trial-First Model for European Cord-Cutters

How a Dutch IPTV Provider Is Rethinking the Trial-First Model for European Cord-Cutters

The European IPTV market has grown aggressively over the past three years. According to IMARC Group, the global IPTV market reached $94.1 billion in 2024 and is
Share
Techbullion2026/03/29 03:25