ZetaChain admits overlooking bug bounty report before $334K exploit
ZetaChain has acknowledged that a vulnerability behind its recent exploit had already been reported through its bug bounty program, but was treated as expected behavior. According to ZetaChains post-mortem published Wednesday, the incident has triggered an internal review of how the protocol evaluates bug bounty submissions, especially those involving multi-step attack paths that may appear harmless when viewed separately. The disclosure follows an attack on Sunday that targeted the projects cross-chain gateway contract, draining about $334,000 across nine transactions on Ethereum, Arbitrum, Base, and BSC, all from wallets controlled by the team. ZetaChain stated that no user funds were impacted, a point it had also emphasized a day earlier when it paused cross-chain transactions on its mainnet to contain the breach. DefiLlama data had earlier estimated the losses at roughly $300,000, while ZetaChain said at the time that it would release a full breakdown after completing its investigation. Flaws combined to enable full drain ZetaChain said the attacker chained together three separate design weaknesses that, on their own, did not appear critical but together enabled the exploit. The gateway contract allowed unrestricted cross-chain instructions to be sent, while the receiving side executed nearly any command on any contract, with a limited blocklist that failed to cover