ZetaChain, an interoperability-focused Layer 1 blockchain, has halted all cross-chain transactions on its mainnet after detecting a targeted exploit against its GatewayEVM smart contract, a core component that routes cross-chain activity between ZetaChain and connected EVM networks. The incident, discovered on April 27, involved unauthorized use of the GatewayEVM contract that impacted only internal team wallets, with the project and multiple trackers reporting that no user funds or external protocol assets were compromised. According to ZetaChain’s public updates, the team quickly blocked the attack vector and suspended cross-chain operations as a precaution while it conducts a forensic investigation and prepares a detailed post‑mortem on the root cause and exploit path. On-chain security analysis cited by media points to a vulnerability in the GatewayEVM / GatewayZEVM call function, reportedly lacking adequate access control and input validation, which allowed an attacker to trigger malicious cross‑network calls that drained funds from wallets controlled by the team. Third‑party data providers such as DeFiLlama estimate the loss at around $300,000, though ZetaChain has not yet confirmed an exact figure and has stated only that losses are limited to internal funds. Operationally, ZetaChain’s mainnet infrastructure and blockchain services remain online, but cross-chain transfers are paused until the investigation and patch are complete, meaning users cannot currently bridge assets via GatewayEVM even though their balances are unaffected. The incident has drawn attention because ZetaChain positions itself as a “universal” cross‑chain Layer 1 connecting networks like Bitcoin, Ethereum, and Polygon, so a vulnerability in its core bridging contract underscores ongoing security challenges for interoperability protocols and smart‑contract bridges. Market data providers reported a modest price decline in the ZETA token following news of the exploit, reflecting immediate market sensitivity to bridge‑related security events even when user funds are not directly impacted.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Compromised

Comments