← Radar

Incident case file

Sign in to watch

ZetaChain — Triple-Bug GatewayEVM Cross-Chain Exploit

Incident date April 26, 2026

0 views

ResolvedEthereumArbitrumBaseBSCSmart contract exploitCluster: ZETA-MULTI-2026-04

Estimated loss

$333.9K

Victims identified

3
Victim group joining is coming soon.

Investigation

95%

Facts and investigation

Attacker: 0x00467f5921f1a343b96b9bf71ae7e9054ae72ea4 (EOA, controls both Ethereum and ZetaChain)

Funds moved to: Parked at 0x67107480FF880A876b7aA0C6CDc3ad92dC4a998a (~139 ETH). Attacker pre-funded via Tornado Cash 3 days prior.
Exploit Contract (ZetaChain): 0xd9dbEec028C12D2dA09a05C9d26709c0Ec722BC1. Profits Wallet: 0x67107480FF880A876b7aA0C6CDc3ad92dC4a998a. GatewayEVM Proxy: 0x48B9AACC350b20147001f88821d31731Ba4C30ed. Victim wallets: 0x8F1AA4DC8EFDB3FAA5060179E90EC3572FF86E38, 0x0cE7f583F4B8a9Dc6942F8b61BE60b7B9dAc9832, 0x7c9e7bb0e823fe08251064420116096b418d7060

Timeline: ~April 24: Attacker funds wallet via Tornado Cash. April 26, 12:51 UTC: Exploit begins via three combined defects: (1) GatewayZEVM.call() had no access control, (2) GatewayEVM.execute() accepted arbitrary calls including transferFrom, (3) old unlimited ERC-20 approvals never revoked. Attacker deploys exploit contract on ZetaChain, calls unauthenticated GatewayZEVM.call() to emit spoofed Called events; ZetaChain TSS validators sign off; GatewayEVM.execute() executes transferFrom against pre-approved team wallet allowances on 4 destination chains over 9 cross-chain calls. 23:00 UTC: Drain window ends. April 27, ~14:08 UTC: Attacker consolidates 139 ETH. April 27: ZetaChain publicly discloses; pauses cross-chain on mainnet. April 29: Full post-mortem published. Cross-chain transactions later resumed; attack vector blocked.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)