ZetaChain Reports Cross-Chain Messaging Vulnerability, $333,868 Loss from April 24 Attack

ZETA0.03%
ETH0.46%
ARB1.01%

Gate News message, April 29 — ZetaChain released a post-mortem report confirming that the April 24 attack exploited vulnerabilities in its cross-chain messaging pipeline. The incident resulted in a total loss of $333,868 (primarily USDC and USDT) across nine transactions on Ethereum, Arbitrum, Base, and BSC. The attack affected only three internal team wallets, with no user funds impacted.

The attack leveraged three interconnected vulnerabilities: the cross-chain system permitted "arbitrary calls" with minimal restrictions; the GatewayEVM contract on the receiving end accepted most commands, including "transferFrom"; and users who had deposited tokens via "GatewayEVM.deposit()" had granted unlimited, unrevoked approvals that the attacker exploited to extract tokens from wallets.

ZetaChain noted the attacker was not opportunistic but had invested significant time and resources in preparation, including funding a wallet via Tornado Cash three days before the attack and conducting brute-force attacks to impersonate victim addresses. The protocol has deployed patches, and cross-chain transaction functionality will remain disabled until upgrades and audits are completed.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments