The ZetaChain vulnerability was reported in advance by white hats but was ignored, ultimately leading to a $334,000 attack incident

By: rootdata|2026/04/29 19:42:02
0
Share
copy

The cross-chain protocol ZetaChain disclosed that the security issues involved in its recent approximately $334,000 vulnerability attack event had been reported in advance by researchers in the bug bounty program but were deemed "expected behavior" by the project team at that time and were not addressed.

According to the official incident review, this attack originated from a combination of three design flaws that initially seemed independent and low-risk: the Gateway contract allowed anyone to send any cross-chain instructions; the receiving end could execute calls on almost any contract, and the blacklist restrictions were too narrow; some wallets retained unlimited approval for an extended period without being cleared. The attacker ultimately combined these flaws to instruct the Gateway to transfer tokens directly to their controlled address, thereby completing the asset transfer.

ZetaChain stated that this attack involved 9 transactions across four chains: Ethereum, Arbitrum, Base, and BSC, with the stolen funds all coming from wallets controlled by ZetaChain, and user funds were not affected. The official noted that the attack showed clear premeditation. The attacker funded their wallet through Tornado Cash three days before the attack and deployed a dedicated Drainer contract in advance, while also implementing an address poisoning attack. Currently, ZetaChain has begun pushing repair patches to the mainnet nodes, permanently disabling the arbitrary call function and changing the unlimited approval mechanism in the deposit process to "precise amount authorization."

-- Price

--

You may also like

The Rise of Composable RWA

27 billion RWA funds are undergoing a major reshuffle: U.S. Treasury bonds are "cooling off," while high-yield credit assets are quietly dominating the DeFi lending market with permissionless designs. This article reveals the explosive logic behind composable RWA.

MAGA Up 350% in 24 Hours, PEPE Up 46% in One Day: Which Memecoins Are Next in 2026?

MAGA +350% in 24hrs. PEPE +46% in one day. RAVE +4,500% then -90%. In 2026's memecoin market, the gains are real. So are the traps? Here's how to tell the difference before you buy.

RCD Espanyol vs Real Madrid: Can the Pericos Delay the Inevitable?

RCD Espanyol vs Real Madrid lineups, standings, and stats for May 3, 2026. Real Madrid visits RCDE Stadium as Barcelona closes in on the LALIGA title. Full preview inside.

MegaETH goes live with an FDV exceeding 2 billion USD. Which ecological projects are worth paying attention to?

The financing and team backgrounds of many projects in the MegaETH ecosystem are rich, making it the most prosperous ecosystem among unlaunched public chains, and it is currently the focus of attention for profit-seekers.

Dialogue with "Wood Sister" Cathie Wood: The next bull market is about to arrive

The correlation coefficient between gold and Bitcoin is only 0.14. In the past two cycles, gold started before Bitcoin, and this time is no different.

Can prediction markets win the competition for perpetual contracts?

Polymarket and Kalshi have entered the perpetual contract arena. In the face of Hyperliquid's "cross-margin" dimensional reduction attack, can the prediction market break the curse of loss and turn the tide?

Contents

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com