CrossCurve bridge exploited for approximately $3 million across multiple chains via spoofed messages

EcosystemsFebruary 1, 2026, 4:31PM EST
UPDATED: February 1, 2026, 4:42PM EST
CrossCurve bridge exploited for approximately $3 million across multiple chains via spoofed messages
Partner offers

Quick Take

  • CrossCurve, formerly known as EYWA, has confirmed its bridge is “currently under attack” following an exploit that has so far drained approximately $3 million.
  • A missing validation check allowed attackers to spoof cross-chain messages and drain the protocol’s PortalV2 contract. 
  • The protocol is backed by Curve Finance founder Michael Egorov and had raised $7 million. 

We'd love your feedback.

Advertisement

Cross-chain liquidity protocol CrossCurve has confirmed that its bridge infrastructure is under active attack after a vulnerability in its smart contracts was exploited for approximately $3 million across multiple networks, according to an announcement from the project on Sunday.

"Our bridge is currently under attack, involving the exploitation of a vulnerability in one of the smart contracts used," CrossCurve said on X. "Please pause all interactions with CrossCurve while the investigation is ongoing."

Blockchain security account Defimon Alerts identified the attack vector as a gateway validation bypass in CrossCurve's ReceiverAxelar contract. According to the analysis, anyone could call the expressExecute function on the contract with a spoofed cross-chain message, bypassing the intended gateway validation and triggering unauthorized token unlocks on the protocol's PortalV2 contract.

The vulnerability is reminiscent of Nomad's $190 million bridge exploit in 2022, which saw more than 300 wallet addresses attempt to drain funds from the protocol in a feeding frenzy. "I cannot believe nothing has changed in four years," security expert Taylor Monahan told The Block in reference to the exploit. 

Data from Arkham Intelligence shared by Defimon Alerts shows the PortalV2 contract's balance dropping from approximately $3 million to near zero around January 31, with the exploit appearing to span multiple networks.

CrossCurve, formerly known as EYWA Protocol, operates a cross-chain DEX and consensus bridge built in partnership with Curve Finance. The protocol uses what it calls a "Consensus Bridge" mechanism that routes transactions through multiple independent validation protocols, including Axelar, LayerZero, and its own EYWA Oracle Network, to reduce single points of failure.

The project had previously emphasized its security architecture as a key differentiator, noting in documentation that "the probability of several crosschain protocols getting hacked at the same time is near zero." Curve Finance founder Michael Egorov became an investor in the protocol in September 2023, and the project later said it had raised $7 million from VCs. 

"Users who have allocated votes to Eywa-related pools may wish to review their positions and consider removing those votes," Curve Finance wrote on X. We continue to encourage all participants to remain vigilant and make risk-aware decisions when interacting with third-party projects."

Updated at 4:42 ET with Curve Finance's X post. 


Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.