Incident case file
Sign in to watchZetaChain — Triple-Bug GatewayEVM Cross-Chain Exploit
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x00467f5921f1a343b96b9bf71ae7e9054ae72ea4 (EOA, controls both Ethereum and ZetaChain)
Timeline: ~April 24: Attacker funds wallet via Tornado Cash. April 26, 12:51 UTC: Exploit begins via three combined defects: (1) GatewayZEVM.call() had no access control, (2) GatewayEVM.execute() accepted arbitrary calls including transferFrom, (3) old unlimited ERC-20 approvals never revoked. Attacker deploys exploit contract on ZetaChain, calls unauthenticated GatewayZEVM.call() to emit spoofed Called events; ZetaChain TSS validators sign off; GatewayEVM.execute() executes transferFrom against pre-approved team wallet allowances on 4 destination chains over 9 cross-chain calls. 23:00 UTC: Drain window ends. April 27, ~14:08 UTC: Attacker consolidates 139 ETH. April 27: ZetaChain publicly discloses; pauses cross-chain on mainnet. April 29: Full post-mortem published. Cross-chain transactions later resumed; attack vector blocked.
Sources and coverage
- Articleblog.solidityscan.comhttps://blog.solidityscan.com/zetachain-gateway-hack-analysis/
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/04/28/zetachain-halts-cross-chain-activity-after-gatewayevm-smart-contract-exploit/
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/04/29/how-a-perfect-storm-of-3-bugs-led-to-zetachains-333k-gatewayevm-exploit/
- Articleforklog.comhttps://forklog.com/en/zetachain-discloses-details-of-334000-cross-chain-attack/
- Articlemexc.comhttps://www.mexc.com/news/1061680
- Articlecrowdfundinsider.comhttps://www.crowdfundinsider.com/2026/04/276066-zetachain-suspends-cross-chain-operations-on-mainnet-after-security-incident-involving-gatewayevm-smart-contract/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)