Zetachain Pauses Mainnet After GatewayZEVM Flaw Hits Team Wallets

Zetachain Pauses Mainnet After GatewayZEVM Flaw Hits Team Wallets

N
News Editor 01
2026-07-22 23:40:14
Zetachain halted cross-chain transactions on April 28 after an exploit in the GatewayZEVM contract. SlowMist said the call function lacked access control and input validation, while the protocol said only internal team wallets were affected, not user funds.
Zetachaincross-chain securitysmart contract exploitSlowMistDeFi

Zetachain halted cross-chain transactions on April 28 after an exploit targeted a vulnerability in its GatewayZEVM smart contract. SlowMist identified the issue within hours, saying the attack path came through the contract’s call function. Wu Blockchain later confirmed the same root cause independently.

The attack path centered on the call function

According to SlowMist’s preliminary analysis, the call function in GatewayZEVM had no access control and no input validation. That opened a clear route for abuse: any external address could trigger cross-chain calls without authorization and send those calls toward arbitrary targets. In a contract that handles sensitive cross-chain operations, that combination is dangerous fast.

The weakness was not limited to missing permissions. Without validation on the data passed into the function, an attacker could craft malicious payloads and have them processed as if they were legitimate cross-chain instructions. That meant assumed trust boundaries inside the contract logic could be bypassed, turning a basic design flaw into an exploitable path across chains.

Zetachain says user funds were not directly affected

Zetachain said the exploit affected internal team wallets valued at about $300,000. The protocol added that user funds were not directly impacted. While its security team reviews the full scope of the breach, cross-chain transactions remain paused, and the project said a post-mortem will be released after the investigation is complete.

So far, the project has not shared detailed remediation steps. It also has not confirmed whether the GatewayZEVM contract received a formal third-party security audit before deployment.

Another major cross-chain incident in April

The Zetachain breach is described in the source material as the second major cross-chain exploit of April 2026. Earlier in the month, the KelpDAO hack triggered broad liquidity withdrawals across DeFi protocols and led to the worst DeFi liquidity crunch since 2024. The same report notes that the Arbitrum Security Council took emergency action to freeze 30,766 ETH linked to the KelpDAO exploiter.

The incident adds to a familiar pattern in smart contract failures. Security researchers have long treated weak or missing access control as one of the most common and preventable flaws in production contracts, especially where functions handle high-value or privileged actions. In Zetachain’s case, that recurring issue appears to have sat at the center of the exploit.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.