The cross-chain bridge of CrossCurve has reportedly been compromised, leading to the theft of approximately $3 million across various networks. The incident was disclosed on Sunday evening via a post on X, where the company alerted users to pause all interactions with the platform during the ongoing investigation into the breach.
According to Defimon Alerts, linked to blockchain security firm Decurity, the exploit stemmed from a vulnerability in one of CrossCurve's smart contracts. This flaw allowed unauthorized users to spoof messages, bypassing validation and unlocking tokens. In response, Boris Povar, the CEO of CrossCurve, has offered a 10% bounty for the return of the stolen funds within a 72-hour window.
Povar has also indicated that if the funds are not returned, the situation will be treated as malicious, prompting potential legal action and collaboration with law enforcement. Meanwhile, Curve Finance, a partner of CrossCurve, has advised its users to reassess their involvement with CrossCurve pools.