Ignored Warning Led to ZetaChain's $334K Crypto Exploit
ZetaChain was exploited for roughly $334,000 after attackers combined multiple design flaws — unrestricted cross-chain messages, overly broad contract-execution permissions, and lingering unlimited token approvals — to drain protocol-controlled funds across Ethereum, Arbitrum, Base and BNB Smart Chain. The vulnerability had reportedly been flagged via the project’s bug-bounty program but was dismissed as intended behavior. No user funds were affected. In its post‑mortem ZetaChain said the attack was premeditated (funding via Tornado Cash, custom draining contract, address‑poisoning) and has since disabled arbitrary-call functionality and moved to exact-amount token approvals while reviewing bug‑bounty triage. Market impact is limited by the small size of the loss, but the incident raises renewed scrutiny and negative sentiment around cross‑chain bridges and protocol security, which could pressure adoption and valuations for bridge-native projects.