ZetaChain Loses $334,000 in Exploit After Dismissing Bug Report
ZetaChain is a Layer 1 blockchain focused on omnichain interoperability, with Gateway contracts that relay instructions across Ethereum, Arbitrum, Base and BNB Smart Chain. The vulnerability had been reported through a bug bounty program but was deemed intended functionality. The incident highlights how underestimating design flaws that can be chained together may amplify asset risks in cross-chain protocols.
On April 26, 2026, an attacker exploited arbitrary cross-chain calls, overly broad contract execution permissions and unlimited approvals that had not been revoked. Across nine transactions on four chains, the attacker stole about $334,000 from wallets controlled by ZetaChain, while user funds were unaffected. The team issued a postmortem on April 29, pledging to review its vulnerability-classification process, disable arbitrary calls and adopt approvals for exact amounts.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.