CrossCurve disclosed a roughly $3 million cross-chain bridge exploit after attackers abused a validation weakness, prompting the protocol to pursue legal action while investigators worked to trace the stolen funds. Reporting on the incident said the attack targeted the bridge’s transaction verification logic rather than a simple wallet compromise, underscoring how weaknesses in cross-chain message validation can let adversaries authorize fraudulent transfers and drain locked assets.
A larger breach hit KelpDAO, where attackers stole about $290 million in rsETH by exploiting its LayerZero-based bridge path with effectively 1-of-1 DVN verification, allowing a forged packet to be accepted on Ethereum without a legitimate source-chain transaction. The theft was widely attributed to North Korea-linked Lazarus/TraderTraitor, and recovery efforts later included burning more than 117,000 rsETH held by the exploiter on Arbitrum, restoring backing through an Aave-controlled recovery wallet, increasing bridge requirements to four independent attestors and 64 block confirmations, and beginning a migration to Chainlink CCIP after investigators characterized the incident as an operational and verification failure rather than a confirmed public smart-contract bug.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
KelpDAO said rsETH remained fully backed and that withdrawals were expected to resume within 24 hours after the first tranche was returned to the smart contract. It also announced security changes including four independent attestors, 64 block confirmations, deprecation of some layer-2 routes, and migration to Chainlink CCIP.
KelpDAO and Aave completed a recovery step by burning 117,132 rsETH held by the exploiter on Arbitrum. Kelp said the approximately $278 million backing would be restored in tranches from the Aave Recovery Guardian multisig.
A GitHub proof-of-concept published technical evidence that KelpDAO's LayerZero route effectively relied on single-DVN 1-of-1 verification, allowing a forged packet to be accepted without a legitimate source-chain transaction. The write-up concluded the immediate cause was single-verifier failure and the broader cause was insecure bridge configuration.
Reporting in April linked the KelpDAO theft to TraderTraitor, a Lazarus Group unit tied to North Korea. LayerZero said the attackers compromised external verification infrastructure, poisoned RPC data, disrupted backups, and used DDoS pressure to force reliance on falsified transaction data.
A second forged packet for 40,000 rsETH became claimable, but KelpDAO blacklisted the recipient before the attacker could complete the withdrawal. Cyvers said this prevented roughly another $100 million in losses.
Attackers fraudulently withdrew 116,500 rsETH from KelpDAO's Ethereum-side OFT adapter, an incident later valued at roughly $290 million to $294 million. The exploit abused KelpDAO's cross-chain bridge verification path on the Unichain-to-Ethereum route.
After the $3 million exploit, CrossCurve publicly threatened legal action in response to the attack. This marked the project's initial public response to the incident.
CrossCurve suffered a cross-chain bridge exploit that resulted in losses of roughly $3 million. Reporting on Feb. 2 describes the incident as exposing a validation flaw in the bridge.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
5 references tracked. Mallory keeps watching after this page renders.
cointelegraph.com
Open sourcegithub.com
Open sourcenknews.org
Open sourcethecyberexpress.com
Open sourcedecrypt.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.