CrossCurve Hack
What happened
On February 1, 2026, CrossCurve’s PortalV2 bridge contracts were exploited through spoofed cross-chain messages, with initial reporting estimating about $3 million extracted across multiple networks.
CrossCurve exposed an unprotected Axelar expressExecute path that bypassed gateway message validation while relying on externally supplied source metadata for authorization.
Case & protocol details
Attack Timeline
The attacker called ReceiverAxelar expressExecute with a forged payload, bypassed Axelar Gateway validation, and caused PortalV2 contracts to unlock assets on Ethereum and then Arbitrum.
Evidence & learning
Sources and on-chain records
- report Report x.com
- report CrossCurve incident reporting theblock.co
- analysis Website reference x.com
- analysis Website reference x.com
- analysis Cantina CrossCurve incident analysis cantina.xyz
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.