No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Crypto

ZetaChain Dismissed Bug Report That Could Have Prevented $334K Exploit

April 29, 2026
in Crypto
0
Cointelegraph


The vulnerability that led to ZetaChain’s recent exploit had been flagged through its bug bounty program before the attack, but was dismissed as intended behavior.

In a post-mortem published Wednesday, the team said the incident has prompted a review of how it handles bug bounty submissions, particularly reports involving chained attack vectors that may appear harmless in isolation but are dangerous in combination.

“This bug was reported and they simply ignored it,” one user wrote on X. “That’s how bug bounty programs work with these protocols currently; they incentivize losses for the protocol, the TVL, and the user’s balance instead of paying the researcher for discovering and fixing the bug,” they added.

ZetaChain lost approximately $334,000 to a premeditated exploit on Sunday that targeted its cross-chain gateway contract. The exploit drained funds across nine transactions on four chains, including Ethereum, Arbitrum, Base and BSC, all from ZetaChain-controlled wallets. No user funds were affected.

Related: Crypto hackers stole $17B over past 10 years: DefiLlama

Attacker exploits small design flaws

ZetaChain said in its post-mortem that the attacker exploited three design flaws that, individually, might have seemed minor, but together opened the door to a full drain. First, the gateway allowed anyone to send arbitrary cross-chain instructions with no restrictions. Second, on the receiving end, it would execute almost any command on any contract, with a blocklist so narrow it missed basic token transfer functions.

Third, wallets that had previously used the gateway had left unlimited spending permissions in place that were never cleaned up. By combining all three, the attacker simply told the gateway to transfer tokens from victim wallets to their own, and the gateway complied.

Source: ZetaChain

“This was not an opportunistic attack,” ZetaChain said in its post-mortem. The attacker funded their wallet through Tornado Cash three days before the exploit, deployed a purpose-built drainer contract on ZetaChain and ran an address poisoning campaign before seeding it into their transaction history via dust transfers.

ZetaChain added that a patch permanently disabling the arbitrary call functionality is being rolled out to mainnet nodes. The platform also removed unlimited token approvals from its deposit flow, replacing them with exact-amount approvals going forward.

Related: Ethical hacker intercepts $2.6M in Morpho Labs exploit

AI DeFi exploit success rate increases

A new study by a16z tested whether an off-the-shelf AI agent could go beyond identifying DeFi vulnerabilities and actually produce working exploits. Using OpenAI’s Codex against a dataset of 20 real Ethereum price manipulation incidents, researchers ran the agent in a sandboxed environment with no access to future transaction data and no guidance on how the attacks worked. The agent succeeded in just 10% of cases.

However, when researchers fed the agent structured knowledge about common attack patterns and exploit workflows, the success rate jumped to 70%.

Magazine: How to fix suspected insider trading on Polymarket and Kalshi

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
Editorial Team

Editorial Team

Related Posts

Sui-based Nemo Protocol exploited for $2.4m
Crypto

ZetaChain admits overlooking bug bounty report before $334K exploit

April 29, 2026
Czech National Bank eyes 1% Bitcoin reserve allocation for improved returns
Crypto

Czech National Bank eyes 1% Bitcoin reserve allocation for improved returns

April 29, 2026
Czech Central Bank’s Bitcoin Bet Delivers Early Findings, Governor Says
Crypto

Czech Central Bank’s Bitcoin Bet Delivers Early Findings

April 29, 2026
Cointelegraph
Crypto

Celsius Founder Mashinsky Settles FTC Case With $10M Payment

April 29, 2026
Bitcoin and altcoins struggle, while SIREN soars to new heights
Crypto

Polymarket eyes CFTC approval to reopen main platform to U.S. users

April 29, 2026
Kevin Warsh Fed chair nomination heads to Senate Banking Committee vote
Crypto

Kevin Warsh Fed chair nomination heads to Senate Banking Committee vote

April 29, 2026
Load More
Next Post
French asset manager Amundi disclosed it received over €3bn (£2.6bn) of private assets net inflows in the first quarter of this year.

Amundi records positive private assets inflows in Q1

Popular News

  • Alisha McDarris

    Southwest A-List Preferred: What to Know

    0 shares
    Share 0 Tweet 0
  • Air Canada Wi-Fi: What to Know Before You Fly

    0 shares
    Share 0 Tweet 0
  • The key global oil contract tops $115 as Strait of Hormuz impasse continues

    0 shares
    Share 0 Tweet 0
  • Google Meet Is Now Available in CarPlay

    0 shares
    Share 0 Tweet 0
  • Trump says he had ’very productive’ call with Putin ahead of Zelenskiy meeting

    0 shares
    Share 0 Tweet 0

Latest News

French asset manager Amundi disclosed it received over €3bn (£2.6bn) of private assets net inflows in the first quarter of this year.

Amundi records positive private assets inflows in Q1

April 29, 2026
0

French asset manager Amundi disclosed it received over €3bn (£2.6bn) of private assets net inflows in the first quarter of...

Cointelegraph

ZetaChain Dismissed Bug Report That Could Have Prevented $334K Exploit

April 29, 2026
0

The vulnerability that led to ZetaChain’s recent exploit had been flagged through its bug bounty program before the attack, but...

Student Employment Specialist - HigherEdJobs

Student Employment Specialist – HigherEdJobs

April 29, 2026
0

Job DescriptionThe OpportunityEmbry-Riddle Aeronautical University is currently recruiting for a Student Employment Specialist within the Human Resources...

These 5 AI-proof jobs are hiring — here’s how much they pay and how to get them

These 5 AI-proof jobs are hiring — here’s how much they pay and how to get them

April 29, 2026
0

Careers that are not as vulnerable to AI right now share a few common traits: they require physical presence, specialized...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.