CrossChain Bridge CrossCurve Hacked for $3M, CEO Issues 72-Hour Ultimatum

CrossChain Bridge CrossCurve Hacked for $3M, CEO Issues 72-Hour Ultimatum

N
News Editor 01
2026-07-23 01:55:15
CrossCurve, a cross-chain bridge protocol, was hacked for approximately $3 million via a smart contract vulnerability. CEO Boris Povar published 10 recipient addresses and offered a 10% bug bounty for return within 72 hours. Curve Finance warns users to reconsider voting.
cross-chain bridgehackDeFi securityCurve Financebug bounty

CrossCurve, a cross-chain bridge protocol, suffered a hack on Sunday, with approximately $3 million stolen across multiple blockchains. The protocol urgently asked users to pause all interactions and launched a full investigation.

Attack Vector: Fake Cross-Chain Messages Bypass Axelar Gateway

Security firm Decurity's Defimon Alerts analyzed that the attacker exploited a vulnerability in CrossCurve's ReceiverAxelar contract by calling the expressExecute function with forged cross-chain messages, bypassing Axelar gateway validation and directly triggering the PortalV2 contract's unlock operation. The attacker didn't need to complete real cross-chain transfers — fake messages tricked the contract into releasing locked funds. This highlights a typical flaw in cross-chain bridge message verification.

CEO Issues 72-Hour Ultimatum

CrossCurve CEO Boris Povar responded quickly, releasing 10 wallet addresses holding the stolen tokens and offering the attacker 10% as a bug bounty if funds are returned within 72 hours. "These tokens were taken illegally from users due to a smart contract vulnerability," Povar said. He warned that if the deadline passes, CrossCurve will pursue legal action, asset freezes, and cooperate with law enforcement.

Curve Finance Warns Users to Withdraw Voting

Partner protocol Curve Finance issued a warning, urging users to review and consider withdrawing votes for CrossCurve-related liquidity pools. This suggests the incident's impact may extend beyond CrossCurve itself, forcing the broader DeFi ecosystem to reassess exposure.

Cross-Chain Bridges: Achilles' Heel of DeFi

Cross-chain bridges remain one of the most vulnerable DeFi infrastructures. From the $320 million Wormhole hack and $625 million Ronin Bridge exploit in 2022 to this CrossCurve incident, security issues persist. The core reason: bridges must relay and verify messages across different blockchains, creating far more attack surface than single-chain apps. This incident reminds users to verify a protocol's security audits before using cross-chain services and avoid locking large amounts in bridge contracts long-term.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.