BlocktoBlockto

Trending

ZetaChain Bug Report Dismissed Before $334K Cross-Chain Exploit
GENERAL NEWS

Photo: Illustrative

ZetaChain Bug Report Dismissed Before $334K Cross-Chain Exploit

A critical vulnerability in ZetaChain that later led to a $334,000 exploit had been reported earlier through its bug bounty program but was dismissed as intended functionality, according to the project’s post-mortem. The incident has triggered a review of how complex security reports are evaluated, especially those involving multiple chained weaknesses.

Tristan R.
By Tristan R.

Senior Author · April 29, 2026

2 min
Key takeaways
A critical vulnerability in ZetaChain that later led to a $334,000 exploit had been reported earlier through its bug bounty program but was dismissed as intended functionality, according to the project’s post-mortem.
The incident has triggered a review of how complex security reports are evaluated, especially those involving multiple chained weaknesses.
Multi-Chain Exploit Targeted Gateway Contract The attack drained around $334,000 from ZetaChain controlled wallets across nine transactions on four blockchains, including Ethereum, Arbitrum, Base, and BNB Smart Chain.

A critical vulnerability in ZetaChain that later led to a $334,000 exploit had been reported earlier through its bug bounty program but was dismissed as intended functionality, according to the project’s post-mortem. The incident has triggered a review of how complex security reports are evaluated, especially those involving multiple chained weaknesses.

Multi-Chain Exploit Targeted Gateway Contract

The attack drained around $334,000 from ZetaChain controlled wallets across nine transactions on four blockchains, including Ethereum, Arbitrum, Base, and BNB Smart Chain. No user funds were affected.

The exploit worked by combining three issues: unrestricted cross-chain instructions, overly permissive execution of contract commands with a weak blocklist, and previously granted unlimited wallet approvals that were never revoked. Together, these allowed attackers to transfer tokens from connected wallets into their own.

Pre-Planned Attack and Security Response

The attacker reportedly funded their wallet via Tornado Cash, deployed a custom drainer contract, and conducted address poisoning before executing the exploit. ZetaChain has since patched the gateway by disabling arbitrary calls and replacing unlimited approvals with exact-amount permissions. The case has raised broader concerns about bug bounty evaluation standards and DeFi security practices.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Tristan R.
Tristan R.

8+ years covering crypto markets, macro, and geopolitics. Previously at Decrypt and CoinDesk. Focused on the intersection of digital assets and traditional finance.