Crypto2Community
HomeCrypto NewsReviewsGuidesGamblingTradingPress Release

Crypto 2 Community

  • About Us
  • Editorial Policy
  • Why Trust Us
  • Contact Us
  • Privacy Policy
  • Submit a Press Release

Cryptocurrency

  • Best Cryptos to Buy Now
  • Best Crypto Exchanges
  • How To Buy Cryptocurrency
  • Best Crypto Wallets
  • Best Altcoins to Buy

Gambling

  • Best Bitcoin Casinos
  • Best Ethereum Casinos
  • Best Crypto Live Casinos
  • Best Crypto Faucet Casinos
  • Provably Fair Bitcoin Casinos

Best Platforms

  • eToro Review
  • BC.Game Review
  • Jackbit Review
  • Metaspins Review
  • CryptoLeo Review

© 2026 Crypto2Community.com

CAUTION: The content presented on this platform is not intended as financial guidance, and we lack the authorization to offer investment advice. Any material found on this website should not be construed as an endorsement or recommendation of any specific trading strategy or investment decision. The information provided herein is of a general nature, and therefore it is essential to evaluate it in the context of your objectives, financial circumstances, and requirements.

Investment activities involve speculation and entail inherent risks to your capital. This website is not intended for utilization in jurisdictions where the described trading or investment activities are prohibited, and it should only be accessed by individuals who are legally permitted to do so. Depending on your country or state of residence, your investment may not be eligible for investor protection, hence it is advisable to conduct thorough research independently or seek appropriate guidance. While this website is accessible to you free of charge, please note that we may receive commissions from the companies featured on this site.

Disclosure: 18+ Rules regarding online gambling vary from country to country, please ensure you are following them and gamble responsibly. The content on this website is provided for entertainment purposes only. We may utilise affiliate links within our content, and receive commission.

Home/Crypto News
Crypto News

ZetaChain Exploit Reveals Ignored Bug Report Behind $334K Loss

Author
Austin Mwendia
Austin Mwendia
Crypto Writer
Fact Checked by Joshua Downes
Last updated: April 29, 2026
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.
TweetShareLinkedIn0
ZetaChain Exploit Reveals Ignored Bug Report Behind $334K Loss

Highlights:

  • The ZetaChain exploit has been traced to a missed bug report that later enabled a $334K drain from internal wallets.
  • The gateway design allowed attackers to combine flaws and move funds across multiple chains without additional approvals.
  • The exploit adds to the rising DeFi incidents targeting approval and contract weaknesses.

ZetaChain said an attacker used a previously reported vulnerability to drain about $333,868 on April 26 from its GatewayEVM system. ZetaChain published a post-mortem on Wednesday explaining how the attacker executed the exploit. The attacker targeted the GatewayEVM contract within ZetaChain’s cross-chain messaging pipeline. The attacker drained funds from three ZetaChain-controlled wallets between 12:51 UTC and 23:00 UTC.

Advertisement

Banner

BREAKING: 🚨 ZetaChain identifies cross-chain messaging loophole as root cause of exploit that drained $333,868 from team wallets through three combined vulnerabilities.

— BlockAI News (@BlockAI_News) April 29, 2026

ZetaChain said a security researcher had reported the vulnerability earlier through its bug bounty program. The team reviewed the submission and classified the issue as intended behavior. That decision left the GatewayEVM contract exposed before the attack. The attacker later used the same flaw to trigger token transfers from approved wallets.

Users on X questioned why ZetaChain dismissed the bug report. One user said, “This bug was reported, and they simply ignored it.” The user added that some protocols fail to reward valid findings and react only after losses occur.

This bug was reported and they simply ignored it. That's how bug bounty programs work with these protocols currently; they incentivize losses for the protocol, the TVL, and the user's balance instead of paying the researcher for discovering and fixing the bug.

— Zero cool (@cr4shls0v3rr1d3) April 29, 2026

ZetaChain disclosed the incident on April 27 after detecting suspicious transactions. The team paused all cross-chain operations on the same day to stop further transfers. Engineers blocked the exploit path and began analyzing the combined flaws. ZetaChain confirmed that the attacker did not access user funds and only drained internal wallets. The post-mortem identified the GatewayEVM contract and messaging pipeline as the entry points used in the exploit.

How Gateway Design Gaps Enabled Multi-Chain Drain

ZetaChain said the attacker combined three design flaws to execute the exploit across multiple chains. Each flaw appeared limited during testing, but enabled full access when combined.

The GatewayEVM contract allowed external users to send cross-chain instructions without strict permission checks. The receiving contract executed most commands and accepted functions such as transferFrom. Wallets that had interacted with the gateway retained unlimited token approvals from earlier deposits.

These approvals allowed the contract to move tokens without fresh authorization. The attacker used these permissions to transfer funds from affected wallets. Each transaction instructed the gateway to call transferFrom and move tokens to the attacker’s address. The contract executed these instructions and completed the transfers.

The attacker executed nine transactions across Ethereum, Arbitrum, Base, and BNB Smart Chain. The attacker drained USDC and USDT from the wallets and swapped the assets into ETH through decentralized exchanges. The exploiter consolidated about 139 ETH into a single wallet after swaps.

ZetaChain said the GatewayEVM contract serves as the main entry point for cross-chain activity. This structure allowed the attacker to affect multiple networks through one contract.

ZetaChain Exploit Shows Planned Attack and Response

ZetaChain said the attacker prepared the exploit over several days before executing the drain on April 26. The attacker funded the wallet through Tornado Cash three days before the exploit. The attacker deployed a custom drainer contract to support execution.

The exploiter used address poisoning to interfere with transaction tracking. The exploiter sent dust transfers to insert malicious addresses into wallet histories. ZetaChain removed unlimited token approvals from its deposit system and introduced exact-amount approvals. Engineers are reviewing the system before restoring cross-chain transactions. ZetaChain advised users who interacted with the gateway to revoke ERC-20 token allowances.

Data shows that at least 11 DeFi exploits occurred within ten days. A separate exploit involving Kelp DAO exposed similar risks in cross-chain infrastructure.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

Visit eToro

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Advertisement

Banner

Tags

Crypto BugDeFiGatewayEVMHackZetaChain
Austin Mwendia
Author

Austin Mwendia

Austin Mwendia is a passionate crypto journalist with three years of experience. He has contributed to various media outlets, covering blockchain technology, market analysis, and financial trends. He is committed to educating readers and expanding the adoption of blockchain and decentralized finance.

View full profile ›

ℹ️About Crypto2Community's Editorial Process

Crypto2Community's editorial policy is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict editorial policy and sourcing standards, and each page undergoes diligent review by our team of top crypto industry experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

More by this author:

  • Ripple and OKX Partner to Expand RLUSD Access Worldwide
  • Dogecoin Price Analysis – DOGE Breakout Puts $0.20 Target in Focus
  • Hong Kong Warns Public About Fake Stablecoins Tied to Licensed Issuers

Related Articles:

Ripple and OKX Partner to Expand RLUSD Access Worldwide
Ripple and OKX Partner to Expand RLUSD Access Worldwide
Crypto News1 hours ago
Syed Ali Haider
By Syed Ali Haider4/29/2026
Dogecoin Price Analysis – DOGE Breakout Puts $0.20 Target in Focus
Dogecoin Price Analysis – DOGE Breakout Puts $0.20 Target in Focus
Crypto News2 hours ago
Syed Ali Haider
By Syed Ali Haider4/29/2026
Hong Kong Warns Public About Fake Stablecoins Tied to Licensed Issuers
Hong Kong Warns Public About Fake Stablecoins Tied to Licensed Issuers
Crypto News2 hours ago
Syed Ali Haider
By Syed Ali Haider4/29/2026

Advertisement

Banner

Advertisement

Banner

🔥Latest offers

Play Now

9.85 Stars

🔥 Get up to 60% with all rewards

Claim Bonus

9.65 Stars

💸 300% deposit bonus up to 20,000 USD

Visit eToro

9.95 Stars

Best Crypto Exchange 2025

Virtual currencies are highly volatile. Your capital is at risk.

Visit KuCoin

9.55 Stars

Trading features & low fees

Popular Topics

  • Sei Price Prediction 2025, 2030, 2040
  • Uniswap Price Prediction 2025, 2030, 2040
  • Near Protocol Price Prediction 2025, 2030, 2040
  • Loopring Price Prediction 2025, 2030, 2040
  • Chainlink Price Prediction 2025, 2030, 2040

Trending News

  • ZetaChain Exploit Reveals Ignored Bug Report Behind $334K Loss
  • Ripple and OKX Partner to Expand RLUSD Access Worldwide
  • Hong Kong Warns Public About Fake Stablecoins Tied to Licensed Issuers
  • Dogecoin Price Analysis – DOGE Breakout Puts $0.20 Target in Focus
  • Humanity Protocol Price Prediction – H Eyes $0.229 as Volume Spikes
  • Cynthia Lummis Pushes Developer Safeguards in CLARITY Act
  • South Korea Prepares to Tax Crypto Gains in 2027
  • Canada Moves to Ban Crypto ATMs Amid Rising Scams
  • Galaxy Digital Posts $216 Million Q1 Loss as Crypto Market Drops
  • ZCash Price Prediction – ZEC Eyes $539 If Fed Delivers Dovish Signal
  • Ondo Taps Broadridge for Proxy Voting on Tokenized Stocks and ETFs
  • Bitcoin Price Analysis – Can BTC Break $79K or Drop Toward $62K After Fed Decision?
  • Jack Dorsey’s Block Launches Bitcoin Proof-of-Reserves to Boost Transparency
  • Best Altcoins to Watch Today, April 28 – XRP, Pi Network, Terra Classic
  • Bitbank Rolls Out Bitcoin Payment Card with Direct Monthly Bill Settlement
  • Ethereum Outpaces Bitcoin in Number of Non-Empty Wallets, Santiment Says
  • DeFi United Plans rsETH Recovery After $292M KelpDAO Bridge Exploit
  • ZetaChain Halts Cross-Chain Activity After GatewayEVM Exploit
  • Stablecoin Market Hits $317B as USDC Leads Institutional Demand
  • Crypto Weekly Market Wrap April 27: Institutional Inflows, Regulation, Exploits, and Policy Updates