todayonchain.com

ZetaChain identifies cross-chain messaging loophole as root of targeted exploit

The Block
ZetaChain patched a cross-chain messaging vulnerability that allowed attackers to drain approximately $333,868 from specific internal team wallets.

Summary

ZetaChain reported that an April 24 exploit targeting its GatewayEVM contract was caused by a loophole in its cross-chain messaging system. The attacker combined unrestricted arbitrary call requests with existing token approvals to drain $333,868 in stablecoins from internal team wallets. ZetaChain confirmed that no user funds were lost, deployed a patch, and recommended that users revoke outstanding token allowances as a precaution.

(Source:The Block)