Gate News message, April 29 — ZetaChain released a post-mortem report confirming that the April 24 attack exploited vulnerabilities in its cross-chain messaging pipeline. The incident resulted in a total loss of $333,868 (primarily USDC and USDT) across nine transactions on Ethereum, Arbitrum, Base, and BSC. The attack affected only three internal team wallets, with no user funds impacted.
The attack leveraged three interconnected vulnerabilities: the cross-chain system permitted "arbitrary calls" with minimal restrictions; the GatewayEVM contract on the receiving end accepted most commands, including "transferFrom"; and users who had deposited tokens via "GatewayEVM.deposit()" had granted unlimited, unrevoked approvals that the attacker exploited to extract tokens from wallets.
ZetaChain noted the attacker was not opportunistic but had invested significant time and resources in preparation, including funding a wallet via Tornado Cash three days before the attack and conducting brute-force attacks to impersonate victim addresses. The protocol has deployed patches, and cross-chain transaction functionality will remain disabled until upgrades and audits are completed.