The ZetaChain vulnerability was reported in advance by white hats but was ignored, ultimately leading to a $334,000 attack incident

By: rootdata|2026/04/29 19:42:02
0
Share
copy

The cross-chain protocol ZetaChain disclosed that the security issues involved in its recent approximately $334,000 vulnerability attack event had been reported in advance by researchers in the bug bounty program but were deemed "expected behavior" by the project team at that time and were not addressed.

According to the official incident review, this attack originated from a combination of three design flaws that initially seemed independent and low-risk: the Gateway contract allowed anyone to send any cross-chain instructions; the receiving end could execute calls on almost any contract, and the blacklist restrictions were too narrow; some wallets retained unlimited approval for an extended period without being cleared. The attacker ultimately combined these flaws to instruct the Gateway to transfer tokens directly to their controlled address, thereby completing the asset transfer.

ZetaChain stated that this attack involved 9 transactions across four chains: Ethereum, Arbitrum, Base, and BSC, with the stolen funds all coming from wallets controlled by ZetaChain, and user funds were not affected. The official noted that the attack showed clear premeditation. The attacker funded their wallet through Tornado Cash three days before the attack and deployed a dedicated Drainer contract in advance, while also implementing an address poisoning attack. Currently, ZetaChain has begun pushing repair patches to the mainnet nodes, permanently disabling the arbitrary call function and changing the unlimited approval mechanism in the deposit process to "precise amount authorization."

-- Price

--

You may also like

Track Markets At a Glance: New WEEX Price Widgets for iOS & Android

To streamline your market data access, WEEX has officially launched "Market Watchlist" desktop widgets

The billion-dollar lesson: The focus of DeFi security is shifting from code to operational governance

Warning of nearly $1 billion loss in DeFi: Security pain points have shifted from code vulnerabilities to permissions and operations. Introducing TradFi bank-level risk control and AI defenses is the way to balance openness and security.

A Brief Analysis of Stablecoin Licenses and On-Chain Funding

Hong Kong accelerates the layout of digital finance, providing a panoramic analysis of the evolution of three major on-chain financial forms: central bank digital currency, deposit tokens, and stablecoins, along with future opportunities.

BVNK Founder: Three Stages of Stablecoin Development

Once payments become faster, cheaper, and globally interconnected, stablecoins will not just open up a new market, but a new realm with boundaries that are not yet visible today.

The truth about Trump's son's Bitcoin game: he made a staggering $100 million while retail investors lost $500 million

The Trump family has a family skill: to exaggerate and make something sound bigger than it actually is.

What Is Futures Trading? Hours, Platforms, and How to Start Trade Futures(2026 Guide)

Learn how to start futures trading, understand trading hours, and choose the best futures trading platform. Includes real data, strategies, and ways to maximize returns with rebates.

Contents

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com