Tools Crypto Exploit Tracker exploit-0067
Exploit record
CrossCurve
- Loss
- $3M
- Attack vector
- Other
- Chain
- Multichain
- Sector
- Bridge
What happened
On February 1, 2026, CrossCurve lost roughly $2.9M after an attacker exploited an authorisation bypass in ReceiverAxelar's express execution flow.
Axelar's model is supposed to bind execution to validated cross-chain messages. The weak point here was a path that skipped that validation and relied too heavily on attacker-controlled metadata. The result was spoofed messages that looked close enough to pass local checks, letting the attacker trigger unlocks they had no right to trigger. CrossCurve responded with a white-hat ultimatum and threat of legal follow-through, which is usually what teams say when the chain has already spoken.
On-chain references
- Funds Holder 1
0xAc8f44ceCa92b2a4b30360E5bd3043850a0FFcbE - Funds Holder 2
0x8c259f1e53e79408095d0ba805554d4cdda15285 - Funds Holder 3
0x851c01d014b1ad2b1266ca48a4b5578b67194834
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
