Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

Wall Street is coming to Consensus Miami — and it’s not just to watch

15 minutes ago

DeFi Exploits Push Builders to Rethink Emergency Controls

17 minutes ago

Bitcoin’s Upside Capped by $82K Sell Wall as UAE’s OPEC Exit Triggers Risk Sell-Off

20 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Wednesday, April 29
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»ZetaChain Dismissed Bug Report That Could Have Prevented $334K Exploit
Cryptocurrency & Free Speech Finance

ZetaChain Dismissed Bug Report That Could Have Prevented $334K Exploit

News RoomBy News Room1 hour agoNo Comments3 Mins Read1,333 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
ZetaChain Dismissed Bug Report That Could Have Prevented 4K Exploit
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

The vulnerability that led to ZetaChain’s recent exploit had been flagged through its bug bounty program before the attack, but was dismissed as intended behavior.

In a post-mortem published Wednesday, the team said the incident has prompted a review of how it handles bug bounty submissions, particularly reports involving chained attack vectors that may appear harmless in isolation but are dangerous in combination.

“This bug was reported and they simply ignored it,” one user wrote on X. “That’s how bug bounty programs work with these protocols currently; they incentivize losses for the protocol, the TVL, and the user’s balance instead of paying the researcher for discovering and fixing the bug,” they added.

ZetaChain lost approximately $334,000 to a premeditated exploit on Sunday that targeted its cross-chain gateway contract. The exploit drained funds across nine transactions on four chains, including Ethereum, Arbitrum, Base and BSC, all from ZetaChain-controlled wallets. No user funds were affected.

Related: Crypto hackers stole $17B over past 10 years: DefiLlama

Attacker exploits small design flaws

ZetaChain said in its post-mortem that the attacker exploited three design flaws that, individually, might have seemed minor, but together opened the door to a full drain. First, the gateway allowed anyone to send arbitrary cross-chain instructions with no restrictions. Second, on the receiving end, it would execute almost any command on any contract, with a blocklist so narrow it missed basic token transfer functions.

Third, wallets that had previously used the gateway had left unlimited spending permissions in place that were never cleaned up. By combining all three, the attacker simply told the gateway to transfer tokens from victim wallets to their own, and the gateway complied.

Source: ZetaChain

“This was not an opportunistic attack,” ZetaChain said in its post-mortem. The attacker funded their wallet through Tornado Cash three days before the exploit, deployed a purpose-built drainer contract on ZetaChain and ran an address poisoning campaign before seeding it into their transaction history via dust transfers.

ZetaChain added that a patch permanently disabling the arbitrary call functionality is being rolled out to mainnet nodes. The platform also removed unlimited token approvals from its deposit flow, replacing them with exact-amount approvals going forward.

Related: Ethical hacker intercepts $2.6M in Morpho Labs exploit

AI DeFi exploit success rate increases

A new study by a16z tested whether an off-the-shelf AI agent could go beyond identifying DeFi vulnerabilities and actually produce working exploits. Using OpenAI’s Codex against a dataset of 20 real Ethereum price manipulation incidents, researchers ran the agent in a sandboxed environment with no access to future transaction data and no guidance on how the attacks worked. The agent succeeded in just 10% of cases.

However, when researchers fed the agent structured knowledge about common attack patterns and exploit workflows, the success rate jumped to 70%.

Magazine: How to fix suspected insider trading on Polymarket and Kalshi

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Cryptocurrency & Free Speech Finance

Wall Street is coming to Consensus Miami — and it’s not just to watch

15 minutes ago
Cryptocurrency & Free Speech Finance

DeFi Exploits Push Builders to Rethink Emergency Controls

17 minutes ago
Cryptocurrency & Free Speech Finance

Bitcoin’s Upside Capped by $82K Sell Wall as UAE’s OPEC Exit Triggers Risk Sell-Off

20 minutes ago
Cryptocurrency & Free Speech Finance

DeFi absorbs $292 million shock as AAVE-led rescue steadies markets: Standard Chartered

1 hour ago
Cryptocurrency & Free Speech Finance

Ethereum ICO Whale Who Turned $3,100 Into $23M Wakes Up After a Decade

1 hour ago
Cryptocurrency & Free Speech Finance

A tiny group is winning on Polymarket as under 1% of wallets take half the profits

2 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

DeFi Exploits Push Builders to Rethink Emergency Controls

17 minutes ago

Bitcoin’s Upside Capped by $82K Sell Wall as UAE’s OPEC Exit Triggers Risk Sell-Off

20 minutes ago

Today in Supreme Court History: April 29, 1745

54 minutes ago

Bahrain sentences photographer Sayed Baqer Al-Kamel to 10 years in prison

1 hour ago
Latest Posts

DeFi absorbs $292 million shock as AAVE-led rescue steadies markets: Standard Chartered

1 hour ago

ZetaChain Dismissed Bug Report That Could Have Prevented $334K Exploit

1 hour ago

Ethereum ICO Whale Who Turned $3,100 Into $23M Wakes Up After a Decade

1 hour ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

Wall Street is coming to Consensus Miami — and it’s not just to watch

15 minutes ago

DeFi Exploits Push Builders to Rethink Emergency Controls

17 minutes ago

Bitcoin’s Upside Capped by $82K Sell Wall as UAE’s OPEC Exit Triggers Risk Sell-Off

20 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.