ZetaChain has acknowledged that a vulnerability behind its recent exploit had already been reported through its bug bounty program, but was treated as expectedZetaChain has acknowledged that a vulnerability behind its recent exploit had already been reported through its bug bounty program, but was treated as expected

ZetaChain admits overlooking bug bounty report before $334K exploit

2026/04/29 20:09
3 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

ZetaChain has acknowledged that a vulnerability behind its recent exploit had already been reported through its bug bounty program, but was treated as expected behavior.

According to ZetaChain’s post-mortem published Wednesday, the incident has triggered an internal review of how the protocol evaluates bug bounty submissions, especially those involving multi-step attack paths that may appear harmless when viewed separately.

The disclosure follows an attack on Sunday that targeted the project’s cross-chain gateway contract, draining about $334,000 across nine transactions on Ethereum, Arbitrum, Base, and BSC, all from wallets controlled by the team. 

ZetaChain stated that no user funds were impacted, a point it had also emphasized a day earlier when it paused cross-chain transactions on its mainnet to contain the breach.

DefiLlama data had earlier estimated the losses at roughly $300,000, while ZetaChain said at the time that it would release a full breakdown after completing its investigation.

Flaws combined to enable full drain

ZetaChain said the attacker chained together three separate design weaknesses that, on their own, did not appear critical but together enabled the exploit. The gateway contract allowed unrestricted cross-chain instructions to be sent, while the receiving side executed nearly any command on any contract, with a limited blocklist that failed to cover basic token transfer functions.

Existing wallets that had interacted with the gateway retained unlimited token approvals, which were not revoked. By combining these conditions, the attacker instructed the gateway to move tokens from those wallets, and the system executed the transfers without resistance.

“This was not an opportunistic attack,” ZetaChain said, outlining how the attacker prepared in advance by funding a wallet through Tornado Cash three days before the exploit, deploying a custom drainer contract on ZetaChain, and running an address poisoning campaign before initiating the transactions.

Bug report dismissed before exploit

In its post-mortem, ZetaChain confirmed that the core issue had been raised earlier through its bug bounty program but was not treated as a threat at the time. The team said this has prompted a reassessment of how it handles reports that describe complex attack combinations rather than isolated bugs.

“This bug was reported and they simply ignored it,” one user wrote on X, adding that current bug bounty structures often fail to reward researchers for identifying vulnerabilities before they are exploited.

Following the incident, ZetaChain said it has disabled the gateway’s arbitrary call functionality through a patch being rolled out to mainnet nodes. The platform has also removed unlimited token approvals from its deposit process, replacing them with exact-amount approvals to reduce risk from similar attack patterns.

Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

Potrebbe anche piacerti

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

The post One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight appeared on BitcoinEthereumNews.com. Frank Sinatra’s The World We Knew returns to the Jazz Albums and Traditional Jazz Albums charts, showing continued demand for his timeless music. Frank Sinatra performs on his TV special Frank Sinatra: A Man and his Music Bettmann Archive These days on the Billboard charts, Frank Sinatra’s music can always be found on the jazz-specific rankings. While the art he created when he was still working was pop at the time, and later classified as traditional pop, there is no such list for the latter format in America, and so his throwback projects and cuts appear on jazz lists instead. It’s on those charts where Sinatra rebounds this week, and one of his popular projects returns not to one, but two tallies at the same time, helping him increase the total amount of real estate he owns at the moment. Frank Sinatra’s The World We Knew Returns Sinatra’s The World We Knew is a top performer again, if only on the jazz lists. That set rebounds to No. 15 on the Traditional Jazz Albums chart and comes in at No. 20 on the all-encompassing Jazz Albums ranking after not appearing on either roster just last frame. The World We Knew’s All-Time Highs The World We Knew returns close to its all-time peak on both of those rosters. Sinatra’s classic has peaked at No. 11 on the Traditional Jazz Albums chart, just missing out on becoming another top 10 for the crooner. The set climbed all the way to No. 15 on the Jazz Albums tally and has now spent just under two months on the rosters. Frank Sinatra’s Album With Classic Hits Sinatra released The World We Knew in the summer of 1967. The title track, which on the album is actually known as “The World We Knew (Over and…
Condividi
BitcoinEthereumNews2025/09/18 00:02
Data focus shifts to payrolls – Societe Generale

Data focus shifts to payrolls – Societe Generale

The post Data focus shifts to payrolls – Societe Generale appeared on BitcoinEthereumNews.com. Societe Generale analysts note a quiet data calendar ahead of key
Condividi
BitcoinEthereumNews2026/04/02 17:52
MEXC Chain Observation Daily Day 1

MEXC Chain Observation Daily Day 1

On May 15, 2026, the US Senate Banking Committee passed the CLARITY bill, Winklevoss Twins invested 100 million USD in Gemini via Bitcoin, Coinbase became the official USDC treasury deployer on Hyperliquid, CME planned Nasdaq crypto index futures, and Tether froze over 450 million USD of illicit assets. Industry trends include Consensys delaying its IPO, Kraken switching to Chainlink CCIP, Strive launching a daily dividend security with 13.88 percent yield, and major funding rounds for Onramp, Turnkey, Fasset, and Stitch. MEXC platform data shows top gainers ENM, PEAQ, TROLLSOL and high volume in BTC, ETH, XRP. Upcoming token unlocks for PYTH, Humanity, TON, and MemeCore pose selling pressure. Users are warned against phishing scams and advised to use only official channels.
Condividi
MEXC NEWS2026/05/15 10:16

KAIO Global Debut

KAIO Global DebutKAIO Global Debut

Enjoy 0-fee KAIO trading and tap into the RWA boom