CrossCurve has reported a critical incident on its cross-chain bridge that allowed unauthorized movement of assets. According to Odaily reports, the project confirmed the exploitation of a security flaw in its infrastructure, potentially impacting funds of multiple users. The team has urged the community to suspend all operations on the platform until the security investigation is complete.
Nature of the Flaw and Scope of the Incident
The CrossCurve team identified that certain smart contracts processed transactions incorrectly, resulting in tokens intended for specific users being redirected to unauthorized addresses. While it has been confirmed that these addresses did not demonstrate malicious intent, the project emphasizes the severity of the security breach. The cross-chain bridge, a critical component for interprotocol transfers, showed vulnerabilities that allowed this accidental redistribution of assets.
Recovery Program and Available Incentives
CrossCurve has implemented a white-hat “Safe Harbor” program to encourage voluntary asset restitution. Under this policy, owners of compromised addresses can retain up to 10% of the recovered assets as a reward for their cooperation. The project has directly appealed to those controlling these addresses to return the funds immediately, recognizing that this incentivized measure is more effective than coercive actions.
Ultimatum and Potential Legal Consequences
The CrossCurve team has set a critical deadline: if the funds are not repatriated or contact is not established before Ethereum block height 24,364,392, they will initiate more aggressive procedures. This includes civil and criminal legal actions against the controllers of the affected addresses. Additionally, the project has announced its willingness to collaborate with cryptocurrency exchanges, stablecoin issuers, and blockchain analytics firms to freeze or track the compromised assets on the bridge.
The incident underscores the critical importance of rigorous audits in cross-chain bridge solutions, especially when managing significant volumes of assets across multiple blockchain networks.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
CrossCurve Bridge Experiences Security Attack Due to Smart Contract Flaw
CrossCurve has reported a critical incident on its cross-chain bridge that allowed unauthorized movement of assets. According to Odaily reports, the project confirmed the exploitation of a security flaw in its infrastructure, potentially impacting funds of multiple users. The team has urged the community to suspend all operations on the platform until the security investigation is complete.
Nature of the Flaw and Scope of the Incident
The CrossCurve team identified that certain smart contracts processed transactions incorrectly, resulting in tokens intended for specific users being redirected to unauthorized addresses. While it has been confirmed that these addresses did not demonstrate malicious intent, the project emphasizes the severity of the security breach. The cross-chain bridge, a critical component for interprotocol transfers, showed vulnerabilities that allowed this accidental redistribution of assets.
Recovery Program and Available Incentives
CrossCurve has implemented a white-hat “Safe Harbor” program to encourage voluntary asset restitution. Under this policy, owners of compromised addresses can retain up to 10% of the recovered assets as a reward for their cooperation. The project has directly appealed to those controlling these addresses to return the funds immediately, recognizing that this incentivized measure is more effective than coercive actions.
Ultimatum and Potential Legal Consequences
The CrossCurve team has set a critical deadline: if the funds are not repatriated or contact is not established before Ethereum block height 24,364,392, they will initiate more aggressive procedures. This includes civil and criminal legal actions against the controllers of the affected addresses. Additionally, the project has announced its willingness to collaborate with cryptocurrency exchanges, stablecoin issuers, and blockchain analytics firms to freeze or track the compromised assets on the bridge.
The incident underscores the critical importance of rigorous audits in cross-chain bridge solutions, especially when managing significant volumes of assets across multiple blockchain networks.