Skip to main content
AVOID.NET

CrossCurve Bridge Hack (February 2026)

avoid.net/crosscurve-bridge-hack-february-202610/100·85% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4t2Wbz…Tvyh

Summary

CrossCurve, a cross-chain DeFi bridge formerly known as EYWA Protocol and backed by Curve Finance founder Michael Egorov, suffered an approximately $3 million exploit on February 1-2, 2026. An attacker exploited a missing access-control validation in the protocol's ReceiverAxelar smart contract to forge cross-chain messages and unlock tokens without corresponding deposits across Ethereum, Arbitrum, and at least seven other networks. As of available reporting, no funds have been confirmed recovered and the attacker has not publicly responded to the team's 72-hour bounty ultimatum.

Connected Entities

1 entities
Organizations
CrossCurve Bridge Hack (February 2026)
Relationships
    Have evidence about CrossCurve Bridge Hack (February 2026)?

    Timeline(9 events)

    September 2023

    Curve Finance founder Michael Egorov becomes an early investor in EYWA Protocol (later rebranded CrossCurve).

    GlobeNewswire / The Defiant

    2 May 2024

    EYWA Protocol announces a $7 million seed round led by Michael Egorov (Curve Finance), with Fenbushi Capital, GBV Capital, Big Brain Holdings, Marshland Capital, and Mulana Capital participating.

    GlobeNewswire

    21 December 2024

    EYWA announces an additional financing round with participation from 1inch co-founder and Kenetic Fund, bringing total disclosed funding to approximately $8.5 million.

    Multiple sources

    February 2026

    Exploit begins at approximately 06:38 PM UTC. Attacker calls expressExecute() on CrossCurve's ReceiverAxelar contract with a forged cross-chain payload, exploiting missing gateway validation to unlock tokens from PortalV2 across multiple chains. PortalV2 balance drops from roughly $3 million to near zero.

    Cantina post-mortem; Olympix post-mortem

    2 February 2026

    CrossCurve publicly discloses the exploit, advises all users to halt interactions with the protocol, and pauses bridge operations. CEO Boris Povar issues a 72-hour ultimatum offering a 10% whitehat bounty for return of funds.

    The Block; Decrypt; BanklessTimes

    2 February 2026

    CrossCurve publishes ten Ethereum wallet addresses identified as having received exploited funds, including 0xAc8f44ceCa92b2a4b30360E5bd3043850a0FFcbE and 0x8c259f1e53e79408095d0ba805554d4cdda15285. Curve Finance separately advises users to review exposure to CrossCurve-related liquidity pools.

    BanklessTimes; CryptoTimes; Decrypt

    5 February 2026

    72-hour bounty deadline passes. CrossCurve indicates escalation to criminal referrals, civil litigation, and coordination with exchanges and analytics firms. No confirmed attacker response is publicly documented.

    Decrypt; BeInCrypto

    16 March 2026

    BlockEden publishes detailed technical post-mortem, confirming the attack flow through expressExecute and the threshold-of-1 configuration flaw as enabling conditions.

    BlockEden

    18 May 2026

    CryptoTimes reports that crypto bridge hacks have exceeded $328 million in losses in 2026, listing CrossCurve as one of the early incidents in the year's elevated attack environment.

    CryptoTimes
    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (1 event). 17 of 18 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 7/28/2026, 5:46:01 PM

    last updated: 7/29/2026, 1:51:42 AM

    4 views

    avoid.net — verified advice for a post-truth world