CrossCurve·Crypto / Web3·
Tokens were drained from the bridge.
CrossCurve disclosed exploitation of a bridge-contract vulnerability and identified ten addresses that received the funds. The attached record does not establish the complete downstream scope.
Report freshness and timeline
- Incident occurred
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Reported cause: ExpressExecute function was not properly restricted
- Consequence
- Reported: Tokens were drained from the bridge.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- CrossCurve
- Industry
- Crypto / Web3
- Disclosed
- Event date
- Entry path
- Exploited Vulnerability
- Data involved
- Crypto Assets
- Reported impact
- Asset theft · Operational disruption
- Attached evidence
- 7 independent domains · 8 sources
2)Evidence-backed incident path
- 01
Entry path
Initial access involved exploited vulnerability.
ConfidenceSecondaryExact excerpt
E1“an attacker exploited a flaw “involving the exploitation of a vulnerability in one of the smart contracts””
decrypt.co · Feb 02 - 02
Reported cause
ExpressExecute function was not properly restricted
ConfidenceSecondaryExact excerpt
E2“The ExpressExecute function was not properly restricted”
crosscurve.medium.com · Feb 04 - 03
Observed
Tokens were drained from the bridge.
ConfidenceProbableExact excerpt
E3“an estimated $3 million worth of tokens was drained”
halborn.com · Feb 09
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Reported
Present in public reporting; not independently established by Radar.
Not publicly established
No qualifying public evidence in the attached record.
- That a Defence review would have prevented this incident
4)Relevance to your product
A single protocol invariant can carry the weight of the complete asset path.
This pattern applies when…
- Products that implement cross-chain bridges or privileged contract execution.
- Teams that test authorization boundaries in smart contracts.
Diagnostic questions
- Do value and authorization invariants hold across every contract path?
- Can one actor manipulate pricing, accounting or bridge state out of sequence?
- Are privileged operations bounded under adversarial composition?
This incident does not establish your product's risk.
5)Sector context — Crypto / Web3
- 0 incident threads
- 1 incident threads
- 1 incident threads
- 0 incident threads
- 15 incident threads
- 15 incident threads
- 6 incident threads
- 15 incident threads
- 17 incident threads
- 14 incident threads
- 16 incident threads
- 26 incident threads
- Same incident family
- 98 Protocol exploit
- Confirmed share
- 14% 18 confirmed · 108 reported
- Display family
- Vulnerability exploitation Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Crypto / Web3 in Radar →6)Defence control mapping
Context-only control area
Protocol and contract control area
- Do value and authorization invariants hold across every contract path?
- Can one actor manipulate pricing, accounting or bridge state out of sequence?
- Are privileged operations bounded under adversarial composition?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
- This control is outside the current public external web/API review offer.
7)Public evidence ledger
8 attached sources across 7 independent domains. No attached source is marked as an organization or regulator primary source.
- E3halborn.comExplained: The CrossCurve Hack (February 2026)Other public report · Feb 09 · CitedOther public reportCited
Exact excerpt
“$3 million worth of tokens was drained”
- E1decrypt.coCrossCurve Threatens Legal Action After $3M Cross-Chain Bridge Exploit - DecryptEstablished press · Feb 02 · CitedEstablished pressCited
Exact excerpt
“an attacker exploited a flaw “involving the exploitation of a vulnerability in one of the smart contracts””
- E2crosscurve.medium.comFAQ — User questions following the CrossCurve bridge exploit | by CrossCurve | Feb, 2026 | MediumOther public report · Feb 04 · CitedOther public reportCited
Exact excerpt
“The ExpressExecute function was not properly restricted”