The post $3M cross-chain breach shakes DeFi appeared on BitcoinEthereumNews.com. A fresh security incident has hit the DeFi sector, with the crosscurve hack underscoringThe post $3M cross-chain breach shakes DeFi appeared on BitcoinEthereumNews.com. A fresh security incident has hit the DeFi sector, with the crosscurve hack underscoring

$3M cross-chain breach shakes DeFi

5 min read

A fresh security incident has hit the DeFi sector, with the crosscurve hack underscoring growing concerns around cross-chain protocols and on-chain infrastructure.

CrossCurve bridge hit by $3 million exploit

CrossCurve, a decentralized cross-chain liquidity protocol, confirmed that its bridge infrastructure was attacked, with estimated losses of around $3 million. The team disclosed the incident after detecting suspicious activity affecting one of its deployed smart contracts.

The exploit comes amid a broader rise in crypto attacks. Moreover, it lands in a period when security firms are warning that sophisticated threats are increasingly targeting cross-chain bridges and liquidity routing systems.

The protocol said the attack affected its cross-chain bridge component, which relies on multiple smart contracts to move assets across different networks. However, the team moved quickly to issue public warnings and pause user interactions while it investigated.

Technical details of the cross-chain bridge exploit

The attack focused on a specific smart contract vulnerability within CrossCurve’s architecture. In an urgent notice posted on its official X account on 2026, the team urged users to immediately stop interacting with the protocol while the situation was assessed.

CrossCurve wrote that its bridge was “currently under attack” and that a flaw in one of the contracts used by the system was being exploited. That said, the project emphasized that users should “pause all interactions” with CrossCurve until further updates were available.

According to Defimon Alerts, an automated monitoring account operated by security company Decurity, the exploit allowed attackers to abuse the ReceiverAxelar contract. Moreover, the issue reportedly enabled calls to the expressExecute function using spoofed cross-chain messages.

The post from Defimon Alerts explained that the malicious calls bypassed gateway validation and triggered unauthorized unlocks on the PortalV2 contract. On-chain data later showed that roughly $3M had been drained from PortalV2 across several networks through this mechanism.

CrossCurve response and SafeHarbor policy

In a follow-up update, CrossCurve said it had traced funds from the exploit to 10 wallet addresses that received tokens originating from the incident. The team stressed that those addresses might not belong to malicious actors and that there was “no indication of malicious intent” from the holders at that stage.

However, CrossCurve noted that the tokens had been “wrongfully taken from users” as a result of the smart contract exploit. The project appealed for cooperation from recipients and asked them to return the digital assets that had been transferred to their wallets.

As part of its mitigation strategy, the protocol activated its SafeHarbor WhiteHat policy, offering a bounty of up to 10% to those who help rescue funds. The team clarified that anyone acting in good faith would be eligible to keep as much as 10% of the recovered amount if the remaining funds were returned.

The announcement also provided a dedicated contact email for coordination. Moreover, CrossCurve said that individuals preferring to remain anonymous could send the compromised assets directly to a specified wallet address under the SafeHarbor framework.

The crosscurve hack was accompanied by a strict timeline. CrossCurve warned that if no contact was made and the funds were not returned within 72 hours from block 24364392, the team would treat the incident as a malicious attack.

In that scenario, the project said it would escalate the matter through several channels. These include filing criminal referrals, initiating potential civil litigation, and working with centralized exchanges and stablecoin issuers to freeze associated assets where possible.

Furthermore, CrossCurve pledged to collaborate with blockchain analytics firms and law enforcement agencies. The team also indicated that, absent cooperation, it would proceed with public disclosure of the wallet data linked to the exploit.

Rising wave of crypto hacks in 2025 and 2026

The CrossCurve incident adds to a growing list of high-profile attacks on decentralized finance platforms. In January 2026, hackers stole nearly $400 million in digital assets across the industry, according to data cited in the report.

Security firm CertiK recorded more than 40 major security incidents during that month alone, highlighting the scale of the current threat environment. Moreover, cross-chain protocols and complex liquidity systems have increasingly been targeted because of the large volumes of assets they secure.

The surge in attacks follows an already damaging year for the sector. In 2025, total losses from crypto-related thefts exceeded $1 billion, making it the worst year on record for such incidents and underscoring persistent structural vulnerabilities.

Against this backdrop, the CrossCurve case illustrates how a single smart contract flaw can cascade across multiple networks and user wallets. It also shows why projects are leaning on whitehat incentives and coordinated responses to limit damage when exploits occur.

In summary, the CrossCurve exploit, the SafeHarbor response, and the broader statistics from 2025 and January 2026 reinforce the need for stronger security practices, more rigorous code audits, and faster cross-industry collaboration when bridge vulnerabilities are exposed.

Source: https://en.cryptonomist.ch/2026/02/02/crosscurve-hack-bridge-exploit/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Woman shot 5 times by DHS to stare down Trump at State of the Union address

Woman shot 5 times by DHS to stare down Trump at State of the Union address

A House Democrat has invited Marimar Martinez to attend President Donald Trump's State of the Union address in Washington, D.C., after she was shot by Customs and
Share
Rawstory2026/02/06 03:36
CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

The post CEO Sandeep Nailwal Shared Highlights About RWA on Polygon appeared on BitcoinEthereumNews.com. Polygon CEO Sandeep Nailwal highlighted Polygon’s lead in global bonds, Spiko US T-Bill, and Spiko Euro T-Bill. Polygon published an X post to share that its roadmap to GigaGas was still scaling. Sentiments around POL price were last seen to be bearish. Polygon CEO Sandeep Nailwal shared key pointers from the Dune and RWA.xyz report. These pertain to highlights about RWA on Polygon. Simultaneously, Polygon underlined its roadmap towards GigaGas. Sentiments around POL price were last seen fumbling under bearish emotions. Polygon CEO Sandeep Nailwal on Polygon RWA CEO Sandeep Nailwal highlighted three key points from the Dune and RWA.xyz report. The Chief Executive of Polygon maintained that Polygon PoS was hosting RWA TVL worth $1.13 billion across 269 assets plus 2,900 holders. Nailwal confirmed from the report that RWA was happening on Polygon. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 The X post published by Polygon CEO Sandeep Nailwal underlined that the ecosystem was leading in global bonds by holding a 62% share of tokenized global bonds. He further highlighted that Polygon was leading with Spiko US T-Bill at approximately 29% share of TVL along with Ethereum, adding that the ecosystem had more than 50% share in the number of holders. Finally, Sandeep highlighted from the report that there was a strong adoption for Spiko Euro T-Bill with 38% share of TVL. He added that 68% of returns were on Polygon across all the chains. Polygon Roadmap to GigaGas In a different update from Polygon, the community…
Share
BitcoinEthereumNews2025/09/18 01:10
WLFI Drops 20% Weekly as Price Tests the Crucial $0.113 Support

WLFI Drops 20% Weekly as Price Tests the Crucial $0.113 Support

On Thursday, February 5, World Liberty Financial (WLFI) is continuing its decline and is trading at $0.1281, decreased by 5.89% in the past day. The token has lost
Share
Tronweekly2026/02/06 03:00