ZetaChain identifies cross-chain messaging loophole as root of targeted exploit
Summary
ZetaChain reported that an April 24 exploit targeting its GatewayEVM contract was caused by a loophole in its cross-chain messaging system. The attacker combined unrestricted arbitrary call requests with existing token approvals to drain $333,868 in stablecoins from internal team wallets. ZetaChain confirmed that no user funds were lost, deployed a patch, and recommended that users revoke outstanding token allowances as a precaution.
(Source:The Block)