CrossCurve hack — January 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | February 1, 2026 |
| Target type | Cross-chain bridge |
| Loss | $3,000,000Published estimates range $2,760,000 to $3,000,000Price at time of incident |
| Method | Access control flawThe ReceiverAxelar contract's expressExecute function was callable by any address and did not verify the supplied cross-chain message against the Axelar gateway. A forged message therefore passed straight through and triggered token unlocks from the PortalV2 contract that held bridged assets. |
| Chains | Ethereum, Arbitrum, Optimism, Base, Blast, Other |
| Outcome | Unresolved |
What happened
CrossCurve, the cross-chain routing and bridging protocol built by the EYWA team and counting Curve Finance founder Michael Egorov among its investors, was drained of roughly $3 million on 31 January 2026. The team confirmed the attack publicly in posts on 1 and 2 February.
The flaw was a missing authorisation check in CrossCurve's ReceiverAxelar contract. Its expressExecute function could be called by any address carrying a fabricated cross-chain message, and because the contract did not validate that message against the Axelar gateway, the forged call triggered releases from the PortalV2 contract holding bridged assets. Defimon Alerts flagged the drain as the PortalV2 balance fell from about $3 million to near zero. Losses were spread across networks, with the largest amounts on Ethereum, around $1.3 million, and Arbitrum, around $1.28 million, and smaller amounts on Optimism, Base, Mantle, Kava, Frax, Celo and Blast. BlockSec put the total slightly lower, at about $2.76 million, against the roughly $3 million figure used in most reporting.
CrossCurve told users to pause all interactions while it investigated, then identified ten receiving addresses and invoked its SafeHarbor white-hat policy, offering a 10 percent bounty and a 72-hour window for voluntary return. It said at first that it did not believe the taking was intentional, and warned that failure to return the funds would be followed by criminal referrals, civil litigation, coordination with exchanges and stablecoin issuers to freeze assets, and publication of the wallets. Curve Finance advised holders with votes allocated to EYWA-related pools to review their positions. No return, recovery or full post-mortem was publicly confirmed afterwards.
Law enforcement
CrossCurve threatened criminal complaints and civil litigation and said it would coordinate with exchanges and stablecoin issuers on asset freezes; no agency involvement has been confirmed.
Sources
- The BlockSecondary · retrieved 2026-08-01
- crypto.newsSecondary · retrieved 2026-08-01
- Coin EditionSecondary · retrieved 2026-08-01
- BlockonomiSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "CrossCurve hack — January 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/crosscurvehttps://itokenly.com/hacks/crosscurvePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.