Skip to content

ZetaChain Dismisses $334K Exploit Bug Report

ZetaChain’s $334K Exploit Linked to Ignored Bug Report

  • ZetaChain lost approximately $334,000 due to an exploit targeting its cross-chain gateway contract.
  • The attack exploited three design flaws, allowing arbitrary cross-chain instructions and executing commands on any contract.
  • The attacker funded their wallet via Tornado Cash three days prior and executed a planned drainer contract.
  • No user funds were affected during the exploit, which involved draining funds across nine transactions on four chains including Ethereum and Arbitrum.
  • ZetaChain is rolling out a patch to disable the arbitrary call functionality permanently.

The vulnerability was previously reported through ZetaChain’s bug bounty program but was dismissed as intended behavior, prompting a review of their submission handling process. This incident highlights the importance of addressing potential security issues proactively in blockchain protocols.

Following this exploit, ZetaChain aims to enhance its security measures by implementing stricter controls on token approvals and addressing identified vulnerabilities.(Source)

Share