On April 24, Layer 1 blockchain ZetaChain reported a security breach in which attackers exploited vulnerabilities in its cross-chain messaging system to steal approximately $333,868 in USDC and USDT. The attack consisted of nine transactions spanning Ethereum, Arbitrum, Base, and BSC, targeting three internal team wallets without affecting user funds.
Details of the Vulnerabilities
According to ZetaChain's post-mortem, the attackers leveraged three key flaws: first, insufficient arbitrary call restrictions allowed unapproved cross-chain messages; second, the GatewayEVM contract accepted most commands including the dangerous transferFrom function; third, users' unlimited token approvals granted via GatewayEVM.deposit() were never revoked, enabling attackers to drain approved tokens.
The attackers orchestrated transactions across multiple chains simultaneously, combining these vulnerabilities to extract $334,000 worth of stablecoins from internal wallets. ZetaChain emphasized that the exploit was premeditated, with significant preparation by the perpetrators.
Response and Recommendations
In response, ZetaChain deployed patches on its mainnet and paused all cross-chain transactions pending further upgrades and security reviews. The team reassured users that their funds remain safe. They strongly advised all users who have interacted with ZetaChain’s gateway contracts to revoke related ERC-20 approvals immediately to prevent potential secondary attacks.
This incident highlights the ongoing security risks associated with cross-chain bridges and messaging protocols. As the multi-chain ecosystem expands, similar exploits remain a threat. ZetaChain is collaborating with security experts for a comprehensive audit and plans to implement stricter permission controls.

