logo

CrossCurve Bridge Hacked for $3M After Smart Contract Validation Vulnerability Exploited

ID: b6fdc34f-c709-5356-a15d-6eb779b13d70

STIX ID: report--b6fdc34f-c709-5356-a15d-6eb779b13d70

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2026-02-02

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

CrossCurve (formerly EYWA) suffered an active exploit after attackers abused a missing validation check in its ReceiverAxelar smart contract to submit spoofed cross-chain messages and call expressExecute, enabling unauthorized token unlocks and draining about $3 million from the PortalV2 contract across multiple blockchains; the incident raises broader concerns about bridge validation designs and cross-chain messaging risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.