Ignored Warning Led to ZetaChain’s $334K Crypto Exploit
Crypto Ignored Warning Led to ZetaChains $334K Crypto Exploit The vulnerability had reportedly been submitted earlier through the projects bug bounty program but was dismissed as intended behavior. In its post-mortem, ZetaChain said the attacker combined multiple design flaws, including unrestricted cross-chain instructions, overly broad contract execution permissions, and leftover unlimited token approvals from previous wallet interactions. The attacker also allegedly prepared in advance by funding wallets through Tornado Cash. ZetaChain Hack Raises New Questions ZetaChain recently suffered that resulted in losses of approximately $334,000. The attackers drained protocol-controlled funds across multiple blockchain networks including Ethereum, , Base, and BNB Smart Chain. Importantly, no user funds were impacted. The incident attracted a lot of attention because the vulnerability behind the attack had reportedly been identified earlier through ZetaChains bug bounty program, but was dismissed by the team as intended. After the exploit, ZetaChain released a explaining that the breach was not caused by a single catastrophic flaw, but rather by several smaller design weaknesses that became dangerous when combined. According to the report, the protocols gateway contract allowed anyone to submit arbitrary cross-chain instructions without sufficient restrictions. Once those instructions reached their destination chain, the gateway could execute commands on nearly any smart contract. Although a