CrossCurve, a cross-chain bridge protocol, suffered a hack on Sunday, with approximately $3 million stolen across multiple blockchains. The protocol urgently asked users to pause all interactions and launched a full investigation.
Attack Vector: Fake Cross-Chain Messages Bypass Axelar Gateway
Security firm Decurity's Defimon Alerts analyzed that the attacker exploited a vulnerability in CrossCurve's ReceiverAxelar contract by calling the expressExecute function with forged cross-chain messages, bypassing Axelar gateway validation and directly triggering the PortalV2 contract's unlock operation. The attacker didn't need to complete real cross-chain transfers — fake messages tricked the contract into releasing locked funds. This highlights a typical flaw in cross-chain bridge message verification.
CEO Issues 72-Hour Ultimatum
CrossCurve CEO Boris Povar responded quickly, releasing 10 wallet addresses holding the stolen tokens and offering the attacker 10% as a bug bounty if funds are returned within 72 hours. "These tokens were taken illegally from users due to a smart contract vulnerability," Povar said. He warned that if the deadline passes, CrossCurve will pursue legal action, asset freezes, and cooperate with law enforcement.
Curve Finance Warns Users to Withdraw Voting
Partner protocol Curve Finance issued a warning, urging users to review and consider withdrawing votes for CrossCurve-related liquidity pools. This suggests the incident's impact may extend beyond CrossCurve itself, forcing the broader DeFi ecosystem to reassess exposure.
Cross-Chain Bridges: Achilles' Heel of DeFi
Cross-chain bridges remain one of the most vulnerable DeFi infrastructures. From the $320 million Wormhole hack and $625 million Ronin Bridge exploit in 2022 to this CrossCurve incident, security issues persist. The core reason: bridges must relay and verify messages across different blockchains, creating far more attack surface than single-chain apps. This incident reminds users to verify a protocol's security audits before using cross-chain services and avoid locking large amounts in bridge contracts long-term.

