CrossCurve, previously known as EYWA, confirmed a hack on its cross-chain liquidity protocol, draining nearly $3 million from the PortalV2 contract across multiple blockchain networks. The attack exploited a missing gateway validation that allowed attackers to forge cross-chain messages and unlock tokens without authorization.
How the Exploit Worked
Blockchain security firm Defimon Alerts identified the vulnerability in the ReceiverAxelar contract. The expressExecute function could be called directly using spoofed messages, bypassing built-in gateway verification checks. This exploit echoes the 2022 Nomad bridge attack, underscoring that protocols remain susceptible to similar flaws.
Bounty, Refund Demand, and Legal Threats
The stolen funds were sent to 10 addresses. CrossCurve offered non-malicious holders a 10% bounty if they return the remaining 90% to a designated address (0x624E) within 72 hours. Failure to comply will trigger criminal and civil litigation, as well as collaboration with exchanges and Circle to freeze assets. The project also plans to publicly disclose malicious addresses and analysis results.
Background and Risks
CrossCurve is a cross-chain DEX and consensus bridge that integrates verification protocols like Axelar, LayerZero, and the EYWA Oracle Network, in partnership with Curve Finance. Curve founder Michael Egorov invested in the project in September 2023, which raised $7 million from venture capitalists. The protocol had previously touted a “security-first” design, claiming near-zero probability of simultaneous multi-protocol compromise. The incident highlights ongoing risks in cross-chain bridges, which security experts consider one of the most attack-prone areas in DeFi. Curve Finance advised users to review holdings in Eywa-related pools and consider withdrawing votes, while CrossCurve urged all communications to cease during the investigation.

