CrossCurve Bridge Exploited for $3 Million via Spoofed Multi-Chain Messages

CrossCurve Bridge Exploited for $3 Million via Spoofed Multi-Chain Messages

CrossCurve suffered a $3 million multi-network asset drain after a smart contract exploit, prompting suspension of user interactions to prevent further losses.

Fact Check
The provided sources offer strong, consistent evidence supporting all components of the statement. 1. **The Event and Amount:** The occurrence of the CrossCurve bridge exploit and the loss of approximately $3 million are overwhelmingly confirmed by a majority of the credible sources. High-authority sources like Messari and The Block, as well as several other news outlets (BlockTempo, BingX, Mena FN), all report the exploit and corroborate the $3 million figure. There is no conflicting information regarding these core facts.2. **The Exploit Method:** The most specific part of the claim, that the exploit was due to "spoofed multi-chain messages," is also well-supported. One highly relevant source, a news article from The Block, has a URL that explicitly states the exploit occurred "via-spoofed-messages." Another summary of the same article provides a more technical description of a "gateway validation bypass," which it notes is consistent with a spoofed message attack vector. This provides both a direct claim and technical corroboration for the method.Overall, the evidence is highly consistent across multiple reputable sources. The key details of the event, the financial loss, and the technical cause are all explicitly supported, with no contradictions found in the provided information.
Summary

CrossCurve has confirmed being targeted in a smart contract exploit that drained approximately $3 million worth of assets across multiple blockchain networks. The attack, disclosed via a Feb. 2 X post, prompted the protocol to advise users to pause all interactions. Earlier details revealed that attackers bypassed gateway verification in the ReceiverAxelar contract, using forged cross-chain messages to unlock tokens without authorization. The incident highlights persistent security risks in cross-chain protocols and their susceptibility to validation bypass attacks.

Terms & Concepts
  • Blockchain Bridge: A platform enabling the transfer of digital assets between different blockchain networks.
  • Gateway Verification: A security process in cross-chain systems that ensures incoming messages originate from authenticated and authorized sources.
  • Cross-Chain Messages: Data or transaction instructions sent between different blockchain networks to facilitate interoperability.