COINPURO - Crypto Currency Latest News logo COINPURO - Crypto Currency Latest News logo
Coinpaper 2026-04-29 12:41:34

Ignored Warning Led to ZetaChain’s $334K Crypto Exploit

The vulnerability had reportedly been submitted earlier through the project’s bug bounty program but was dismissed as intended behavior. In its post-mortem, ZetaChain said the attacker combined multiple design flaws, including unrestricted cross-chain instructions, overly broad contract execution permissions, and leftover unlimited token approvals from previous wallet interactions. The attacker also allegedly prepared in advance by funding wallets through Tornado Cash. ZetaChain Hack Raises New Questions ZetaChain recently suffered an exploit that resulted in losses of approximately $334,000. The attackers drained protocol-controlled funds across multiple blockchain networks including Ethereum, Arbitrum, Base, and BNB Smart Chain. Importantly, no user funds were impacted. The incident attracted a lot of attention because the vulnerability behind the attack had reportedly been identified earlier through ZetaChain’s bug bounty program, but was dismissed by the team as intended. After the exploit, ZetaChain released a post-mortem explaining that the breach was not caused by a single catastrophic flaw, but rather by several smaller design weaknesses that became dangerous when combined. According to the report, the protocol’s gateway contract allowed anyone to submit arbitrary cross-chain instructions without sufficient restrictions. Once those instructions reached their destination chain, the gateway could execute commands on nearly any smart contract. Although a blocklist existed, it was too limited and failed to prevent common token transfer functions. Another key issue involved wallets that previously interacted with the gateway and still had unlimited token approvals active. These approvals had not been revoked or cleaned up. By combining open cross-chain messaging, overly broad execution permissions, and lingering token approvals, the attacker was able to instruct the gateway to transfer tokens from affected wallets directly into their own addresses. ZetaChain stated that the exploit was carefully planned rather than opportunistic. Investigators found that the attacker funded their wallet through Tornado Cash several days before the breach, deployed a custom draining contract on ZetaChain, and conducted an address poisoning campaign that was designed to manipulate transaction histories and potentially confuse victims or monitoring systems. In response, the protocol started rolling out security fixes. The arbitrary call functionality was permanently disabled on mainnet nodes, and the token approval process has been redesigned so that future deposits use exact-amount approvals instead of unlimited permissions. The team also said it is reviewing how bug bounty submissions are handled, especially cases where separate low-risk issues can be chained together into a serious exploit. Part of ZetaChain’s post-mortem report

La maggior parte ha letto le notizie

coinpuro_earn
Leggi la dichiarazione di non responsabilità : Tutti i contenuti forniti nel nostro sito Web, i siti con collegamento ipertestuale, le applicazioni associate, i forum, i blog, gli account dei social media e altre piattaforme ("Sito") sono solo per le vostre informazioni generali, procurati da fonti di terze parti. Non rilasciamo alcuna garanzia di alcun tipo in relazione al nostro contenuto, incluso ma non limitato a accuratezza e aggiornamento. Nessuna parte del contenuto che forniamo costituisce consulenza finanziaria, consulenza legale o qualsiasi altra forma di consulenza intesa per la vostra specifica dipendenza per qualsiasi scopo. Qualsiasi uso o affidamento sui nostri contenuti è esclusivamente a proprio rischio e discrezione. Devi condurre la tua ricerca, rivedere, analizzare e verificare i nostri contenuti prima di fare affidamento su di essi. Il trading è un'attività altamente rischiosa che può portare a perdite importanti, pertanto si prega di consultare il proprio consulente finanziario prima di prendere qualsiasi decisione. Nessun contenuto sul nostro sito è pensato per essere una sollecitazione o un'offerta