Skip to main content
Sign in

CrossCurve (formerly EYWA) Bridge Exploit (Feb 2026)

avoid.net/crosscurve-formerly-eywa-bridge-exploit-feb-202612/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·JwdPyg…jdzj

Summary

On February 1, 2026, CrossCurve — a cross-chain DEX and bridge protocol operating under the EYWA brand — suffered a critical exploit of its ReceiverAxelar bridge contract via a missing Axelar Gateway validation check. Approximately $1.4 million in liquid assets were confirmed stolen, while the total PortalV2 contract balance drained was approximately $3 million (including largely illiquid EYWA tokens). No funds were recovered as of the investigation date.

Connected Entities

1 entities
Organizations
CrossCurve (formerly EYWA) Bridge Exploit (Feb 2026)
Relationships
    Have evidence about CrossCurve (formerly EYWA) Bridge Exploit (Feb 2026)?

    Timeline(10 events)

    September 2023

    Curve Finance founder Michael Egorov joins EYWA as a backer in its seed round alongside Fenbushi Capital and GBV Capital. Total fundraising reported at $7–8.5 million.

    The Defiant — Top VCs Join EYWA's Seed Round Led by Curve's Founder

    31 January 2026

    Attacker identifies the unprotected expressExecute() function in CrossCurve's ReceiverAxelar contract and begins probing the vulnerability.

    CrossCurve's $3M Bridge Exploit — BlockEden.xyz

    February 2026

    At 18:38:23 UTC, the primary exploit transaction executes on Ethereum (block 24,363,854), draining the PortalV2 contract of approximately 999.8 million EYWA tokens via a spoofed Berachain cross-chain message. Subsequent transactions target Arbitrum and other supported chains, extracting liquid assets including USDT.

    EYWA PortalV2 Axelar Exploit Analysis — DarkNavy

    February 2026

    Stolen Arbitrum assets converted to WETH via CoW Protocol and bridged to Ethereum through Across Protocol. EYWA tokens remain in attacker's primary wallet, illiquid.

    CrossCurve Bridge Hack: An Integration Blunder — Cantina

    February 2026

    CrossCurve CEO Boris Povar publicly confirms the exploit, urges all users to halt protocol activity, and activates a war room with MixBytes. Ten Ethereum addresses linked to the hack are publicly identified.

    CrossCurve Bridge Suffers $3M Exploit Across Multiple Chains — BanklessTimes

    2 February 2026

    CrossCurve issues 72-hour ultimatum under SafeHarbor WhiteHat policy: return 90% of funds (retain 10% bounty) or face criminal referrals, civil litigation, and exchange-level asset freezes coordinated via Chainalysis and TRM Labs. Deadline counted from block 24,364,392.

    CrossCurve Threatens Legal Action After $3M Cross-Chain Bridge Exploit — Decrypt

    5 February 2026

    CrossCurve escalates bounty offer to 20% in an attempt to incentivize attacker cooperation. No response from attacker is publicly reported.

    CrossCurve $1.4M Exploit: What Went Wrong? — QuillAudits Medium

    21 February 2026

    IoTeX ioTube bridge exploited for approximately $4.3–4.4 million via compromised validator private key, representing a separate February 2026 bridge attack.

    IoTeX Confirms $4.3M ioTube Bridge Breach — CryptoTimes

    March 2026

    CrossCurve completes Hashlock audit of its LayerZero OFT messaging contracts. One medium and three low-severity findings identified and resolved. Contracts awarded a 'Secure' rating.

    CrossCurve Reinforces Cross-Chain Security with Hashlock Audit — TheCryptoUpdates
    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (3 events). 22 of 24 cited source URLs have an Internet Archive snapshot.

    model: claude-code-investigator

    generated: 6/8/2026, 2:45:36 AM

    last updated: 7/26/2026, 11:10:22 PM

    3 views

    avoid.net — verified advice for a post-truth world