DEFENCE / RADAR

Public snapshot

CrossCurve·Crypto / Web3·

Tokens were drained from the bridge.

CrossCurve disclosed exploitation of a bridge-contract vulnerability and identified ten addresses that received the funds. The attached record does not establish the complete downstream scope.

Report freshness and timeline

Incident occurred
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Reported cause: ExpressExecute function was not properly restricted
Consequence
Reported: Tokens were drained from the bridge.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
CrossCurve
Industry
Crypto / Web3
Disclosed
Event date
Entry path
Exploited Vulnerability
Data involved
Crypto Assets
Reported impact
Asset theft · Operational disruption
Attached evidence
7 independent domains · 8 sources

2)Evidence-backed incident path

  1. 01

    Entry path

    Initial access involved exploited vulnerability.

    ConfidenceSecondary
    Exact excerpt

    an attacker exploited a flaw “involving the exploitation of a vulnerability in one of the smart contracts”

    decrypt.co · Feb 02
    E1
  2. 02

    Reported cause

    ExpressExecute function was not properly restricted

    ConfidenceSecondary
    Exact excerpt

    The ExpressExecute function was not properly restricted

    crosscurve.medium.com · Feb 04
    E2
  3. 03

    Observed

    Tokens were drained from the bridge.

    ConfidenceProbable
    Exact excerpt

    an estimated $3 million worth of tokens was drained

    halborn.com · Feb 09
    E3

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • That a Defence review would have prevented this incident

4)Relevance to your product

A single protocol invariant can carry the weight of the complete asset path.

This pattern applies when…

  • Products that implement cross-chain bridges or privileged contract execution.
  • Teams that test authorization boundaries in smart contracts.

Diagnostic questions

  1. Do value and authorization invariants hold across every contract path?
  2. Can one actor manipulate pricing, accounting or bridge state out of sequence?
  3. Are privileged operations bounded under adversarial composition?

This incident does not establish your product's risk.

5)Sector context — Crypto / Web3

126 incident threads in the 365-day public record
  1. 0 incident threads
  2. 1 incident threads
  3. 1 incident threads
  4. 0 incident threads
  5. 15 incident threads
  6. 15 incident threads
  7. 6 incident threads
  8. 15 incident threads
  9. 17 incident threads
  10. 14 incident threads
  11. 16 incident threads
  12. 26 incident threads
Same incident family
98
Protocol exploit
Confirmed share
14%
18 confirmed · 108 reported
Display family
Vulnerability exploitation
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Crypto / Web3 in Radar →

6)Defence control mapping

Context-only control area

Protocol and contract control area

  • Do value and authorization invariants hold across every contract path?
  • Can one actor manipulate pricing, accounting or bridge state out of sequence?
  • Are privileged operations bounded under adversarial composition?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.
  • This control is outside the current public external web/API review offer.

7)Public evidence ledger

8 attached sources across 7 independent domains. No attached source is marked as an organization or regulator primary source.

  1. E3
    halborn.comExplained: The CrossCurve Hack (February 2026)Other public report · Feb 09 · Cited
    Other public reportCited
    Exact excerpt
    $3 million worth of tokens was drained
  2. E1
    decrypt.coCrossCurve Threatens Legal Action After $3M Cross-Chain Bridge Exploit - DecryptEstablished press · Feb 02 · Cited
    Established pressCited
    Exact excerpt
    an attacker exploited a flaw “involving the exploitation of a vulnerability in one of the smart contracts”
  3. E2
    crosscurve.medium.comFAQ — User questions following the CrossCurve bridge exploit | by CrossCurve | Feb, 2026 | MediumOther public report · Feb 04 · Cited
    Other public reportCited
    Exact excerpt
    The ExpressExecute function was not properly restricted
  4. S4
    uinat.comCrossCurve DeFi Bridge Exploited for $3M Through Message Validation Bypass | UINATOther public report · Feb 01 · Attached
    Other public reportAttached
  5. S5
    ainvest.comCrypto Protocol CrossCurve Under Attack, $3M ExploitedOther public report · Feb 01 · Attached
    Other public reportAttached
  6. S6
    crypto.newsCrossCurve exploited for $3 million in multi-network bridge attackOther public report · Feb 02 · Attached
    Other public reportAttached
Show all 8 sourcesShow the first six sources
  1. S7
    banklesstimes.comCrossCurve Bridge Suffers $3M Exploit Across Multiple Chains | BanklessTimesOther public report · Feb 02 · Attached
    Other public reportAttached
  2. S8
    ainvest.comCrossCurve Bridge Exploit: $3M Flow Analysis and Recovery CatalystOther public report · Feb 02 · Attached
    Other public reportAttached

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →