CrossCurve Bridge Hack (February 2026)
Summary
CrossCurve, a cross-chain DeFi bridge formerly known as EYWA Protocol and backed by Curve Finance founder Michael Egorov, suffered an approximately $3 million exploit on February 1-2, 2026. An attacker exploited a missing access-control validation in the protocol's ReceiverAxelar smart contract to forge cross-chain messages and unlock tokens without corresponding deposits across Ethereum, Arbitrum, and at least seven other networks. As of available reporting, no funds have been confirmed recovered and the attacker has not publicly responded to the team's 72-hour bounty ultimatum.
Connected Entities
1 entities · 10 linked investigationsTimeline(9 events)
2023-09-01
Curve Finance founder Michael Egorov becomes an early investor in EYWA Protocol (later rebranded CrossCurve).
GlobeNewswire / The Defiant2024-05-02
EYWA Protocol announces a $7 million seed round led by Michael Egorov (Curve Finance), with Fenbushi Capital, GBV Capital, Big Brain Holdings, Marshland Capital, and Mulana Capital participating.
GlobeNewswire2024-12-21
EYWA announces an additional financing round with participation from 1inch co-founder and Kenetic Fund, bringing total disclosed funding to approximately $8.5 million.
Multiple sources2026-02-01
Exploit begins at approximately 06:38 PM UTC. Attacker calls expressExecute() on CrossCurve's ReceiverAxelar contract with a forged cross-chain payload, exploiting missing gateway validation to unlock tokens from PortalV2 across multiple chains. PortalV2 balance drops from roughly $3 million to near zero.
Cantina post-mortem; Olympix post-mortem2026-02-02
CrossCurve publicly discloses the exploit, advises all users to halt interactions with the protocol, and pauses bridge operations. CEO Boris Povar issues a 72-hour ultimatum offering a 10% whitehat bounty for return of funds.
The Block; Decrypt; BanklessTimes2026-02-02
CrossCurve publishes ten Ethereum wallet addresses identified as having received exploited funds, including 0xAc8f44ceCa92b2a4b30360E5bd3043850a0FFcbE and 0x8c259f1e53e79408095d0ba805554d4cdda15285. Curve Finance separately advises users to review exposure to CrossCurve-related liquidity pools.
BanklessTimes; CryptoTimes; Decrypt2026-02-05
72-hour bounty deadline passes. CrossCurve indicates escalation to criminal referrals, civil litigation, and coordination with exchanges and analytics firms. No confirmed attacker response is publicly documented.
Decrypt; BeInCrypto2026-03-16
BlockEden publishes detailed technical post-mortem, confirming the attack flow through expressExecute and the threshold-of-1 configuration flaw as enabling conditions.
BlockEden2026-05-18
CryptoTimes reports that crypto bridge hacks have exceeded $328 million in losses in 2026, listing CrossCurve as one of the early incidents in the year's elevated attack environment.
CryptoTimesDecision Log
- #1publish⛓ pending7/28/2026, 5:46:16 PMhash: HLTQqnJHH8tg3nhsJp7XzuMVixChY6bw1HdEWG3Cukcp
15 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 7/28/2026, 5:46:01 PM
last updated: 7/28/2026, 9:12:15 PM
avoid.net — verified advice for a post-truth world