CrossCurve Hack

TOTAL LOST $3.0M
Medium Spoofed Cross-Chain Messages ethereum arbitrum

What happened

On February 1, 2026, CrossCurve’s PortalV2 bridge contracts were exploited through spoofed cross-chain messages, with initial reporting estimating about $3 million extracted across multiple networks.

Technical Root Cause

CrossCurve exposed an unprotected Axelar expressExecute path that bypassed gateway message validation while relying on externally supplied source metadata for authorization.

Case & protocol details

Classification Protocol Logic / Bridge / Bridge & Cross-Chain
Protocol Type Cross Chain Bridge
Official Website crosscurve.fi/
Protocol Twitter/X @crosscurvefi

Attack Timeline

The attacker called ReceiverAxelar expressExecute with a forged payload, bypassed Axelar Gateway validation, and caused PortalV2 contracts to unlock assets on Ethereum and then Arbitrum.

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.