YFarmX

Tools Crypto Exploit Tracker exploit-0067

Exploit record

CrossCurve

Loss
$3M
Attack vector
Other
Chain
Multichain
Sector
Bridge

What happened

On February 1, 2026, CrossCurve lost roughly $2.9M after an attacker exploited an authorisation bypass in ReceiverAxelar's express execution flow.

Axelar's model is supposed to bind execution to validated cross-chain messages. The weak point here was a path that skipped that validation and relied too heavily on attacker-controlled metadata. The result was spoofed messages that looked close enough to pass local checks, letting the attacker trigger unlocks they had no right to trigger. CrossCurve responded with a white-hat ultimatum and threat of legal follow-through, which is usually what teams say when the chain has already spoken.

On-chain references

  • Funds Holder 10xAc8f44ceCa92b2a4b30360E5bd3043850a0FFcbE
  • Funds Holder 20x8c259f1e53e79408095d0ba805554d4cdda15285
  • Funds Holder 30x851c01d014b1ad2b1266ca48a4b5578b67194834

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026