No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Crypto

ZetaChain admits overlooking bug bounty report before $334K exploit

April 29, 2026
in Crypto
0
Sui-based Nemo Protocol exploited for $2.4m



ZetaChain has acknowledged that a vulnerability behind its recent exploit had already been reported through its bug bounty program, but was treated as expected behavior.

According to ZetaChain’s post-mortem published Wednesday, the incident has triggered an internal review of how the protocol evaluates bug bounty submissions, especially those involving multi-step attack paths that may appear harmless when viewed separately.

The disclosure follows an attack on Sunday that targeted the project’s cross-chain gateway contract, draining about $334,000 across nine transactions on Ethereum, Arbitrum, Base, and BSC, all from wallets controlled by the team. 

ZetaChain stated that no user funds were impacted, a point it had also emphasized a day earlier when it paused cross-chain transactions on its mainnet to contain the breach.

DefiLlama data had earlier estimated the losses at roughly $300,000, while ZetaChain said at the time that it would release a full breakdown after completing its investigation.

Flaws combined to enable full drain

ZetaChain said the attacker chained together three separate design weaknesses that, on their own, did not appear critical but together enabled the exploit. The gateway contract allowed unrestricted cross-chain instructions to be sent, while the receiving side executed nearly any command on any contract, with a limited blocklist that failed to cover basic token transfer functions.

Existing wallets that had interacted with the gateway retained unlimited token approvals, which were not revoked. By combining these conditions, the attacker instructed the gateway to move tokens from those wallets, and the system executed the transfers without resistance.

“This was not an opportunistic attack,” ZetaChain said, outlining how the attacker prepared in advance by funding a wallet through Tornado Cash three days before the exploit, deploying a custom drainer contract on ZetaChain, and running an address poisoning campaign before initiating the transactions.

Bug report dismissed before exploit

In its post-mortem, ZetaChain confirmed that the core issue had been raised earlier through its bug bounty program but was not treated as a threat at the time. The team said this has prompted a reassessment of how it handles reports that describe complex attack combinations rather than isolated bugs.

“This bug was reported and they simply ignored it,” one user wrote on X, adding that current bug bounty structures often fail to reward researchers for identifying vulnerabilities before they are exploited.

Following the incident, ZetaChain said it has disabled the gateway’s arbitrary call functionality through a patch being rolled out to mainnet nodes. The platform has also removed unlimited token approvals from its deposit process, replacing them with exact-amount approvals to reduce risk from similar attack patterns.

Editorial Team

Editorial Team

Related Posts

Czech National Bank eyes 1% Bitcoin reserve allocation for improved returns
Crypto

Czech National Bank eyes 1% Bitcoin reserve allocation for improved returns

April 29, 2026
Czech Central Bank’s Bitcoin Bet Delivers Early Findings, Governor Says
Crypto

Czech Central Bank’s Bitcoin Bet Delivers Early Findings

April 29, 2026
Cointelegraph
Crypto

Celsius Founder Mashinsky Settles FTC Case With $10M Payment

April 29, 2026
Bitcoin and altcoins struggle, while SIREN soars to new heights
Crypto

Polymarket eyes CFTC approval to reopen main platform to U.S. users

April 29, 2026
Kevin Warsh Fed chair nomination heads to Senate Banking Committee vote
Crypto

Kevin Warsh Fed chair nomination heads to Senate Banking Committee vote

April 29, 2026
crypto, Bitcoin
Crypto

Japan Targets Crypto Deals In Real Estate With New Guidance

April 29, 2026
Load More

Popular News

  • Alisha McDarris

    Southwest A-List Preferred: What to Know

    0 shares
    Share 0 Tweet 0
  • Air Canada Wi-Fi: What to Know Before You Fly

    0 shares
    Share 0 Tweet 0
  • Trump says he had ’very productive’ call with Putin ahead of Zelenskiy meeting

    0 shares
    Share 0 Tweet 0
  • Google Meet Is Now Available in CarPlay

    0 shares
    Share 0 Tweet 0
  • Lenovo Is Showing off a Bunch of Quirky Laptop Prototypes

    0 shares
    Share 0 Tweet 0

Latest News

Sui-based Nemo Protocol exploited for $2.4m

ZetaChain admits overlooking bug bounty report before $334K exploit

April 29, 2026
0

ZetaChain has acknowledged that a vulnerability behind its recent exploit had already been reported through its bug bounty program, but...

Stocks making the biggest moves premarket: STX, HOOD, HUM, GNRC

Stocks making the biggest moves premarket: STX, HOOD, HUM, GNRC

April 29, 2026
0

Check out the companies making the biggest moves premarket: Seagate Technology — The data storage stock popped almost 18%. Seagate...

Heron Finance: US private credit loan quality “stable”

Heron Finance: US private credit loan quality “stable”

April 29, 2026
0

The quality of loans underpinning the largest US private credit funds remain stable, according to investment advisor Heron Finance’s latest...

Czech National Bank eyes 1% Bitcoin reserve allocation for improved returns

Czech National Bank eyes 1% Bitcoin reserve allocation for improved returns

April 29, 2026
0

Czech National Bank Governor Aleš Michl has endorsed a 1% Bitcoin allocation in central bank reserves, citing improved returns without...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.