The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Sourcing
1source

via CoinTelegraph

CoinTelegraph · track record
34Stories
100%Verified
230d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Markets/ZetaChain Dismissed Bug Report Before $334K Exploit
VERIFIEDBy Xavier Rivera· ·1 min read

ZetaChain Dismissed Bug Report Before $334K Exploit

ZetaChain dismissed a bug bounty report on a vulnerability that enabled a $334,000 exploit via its cross-chain gateway. The incident prompts a review of bug bounty processes and includes a patch rollout.

Source:CoinTelegraph
Post
ZetaChain Dismissed Bug Report Before $334K Exploit
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

ZetaChain dismisses a bug bounty report on its cross-chain gateway before an exploit drains $334,000 from ZetaChain wallets across nine transactions on Ethereum, Arbitrum, Base, and BSC. No user funds affected. Post-mortem cites three design flaws enabling arbitrary instructions and unlimited approvals in a premeditated attack. ZetaChain patches arbitrary calls, switches to exact approvals, and improves bounty reviews.

ZetaChain's vulnerability behind a $334,000 exploit was reported through its bug bounty program before the attack but dismissed as intended behavior.

The team published a post-mortem on Wednesday detailing the Sunday incident, which targeted its cross-chain gateway contract. The exploit drained funds across nine transactions on four chains—Ethereum, Arbitrum, Base, and BSC—from ZetaChain-controlled wallets. No user funds were affected.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
ZetaChain attributes the attack to three design flaws: the gateway allowed arbitrary cross-chain instructions without restrictions; it executed nearly any command on any contract due to a narrow blocklist missing basic token transfers; and wallets retained unlimited spending permissions from prior use.

The post-mortem describes a premeditated attack. The attacker funded their wallet via Tornado Cash three days prior, deployed a drainer contract on ZetaChain, and conducted address poisoning via dust transfers.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
ZetaChain now reviews bug bounty submissions, especially chained attack vectors. A patch disables arbitrary call functionality on mainnet nodes, and deposit flows replace unlimited approvals with exact-amount ones.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
CryptoSecurityDeFiExploit
More fromCoinTelegraph
  • SoFi moves entire card program to SoFiUSD stablecoin settlement

    Markets · 2d
  • Bitmine buys 28k ETH, hits 97% of 5% supply goal

    Markets · 18d
  • Stripe and Advent International Propose $53 Billion PayPal Takeover

    Markets · 2mo
More inMarkets
  • SoFi moves entire card program to SoFiUSD stablecoin settlement

    Markets · 2d
  • Warren Buffett steps down as Berkshire Hathaway chairman

    Markets · 8d
  • Copart Agrees to Buy ACV Auctions for $1.9 Billion in Cash

    Markets · 13d
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Markets →
  • Markets· 

    APAC leads crypto adoption as Bitget revises breach to $388M

    APAC nations hold nine of the top 20 spots in the 2026 crypto adoption ranking while Bitget revised its breach figure to about $387.5 million from an initial $351.6 million. Regional banks are also testing 24-hour settlement and blockchain bond issuance.

  • Tech· 

    High-Severity Flaw in D-Link DIR-895L Router Has a Public Exploit

    CVE-2026-100740 is an out-of-bounds write in the L2TP code of the D-Link DIR-895L router on firmware A1_102b07. It can be triggered remotely, scores 8.6 (high), and an exploit is public.

  • Tech· 

    IBM Discloses Two More Guardium Data Protection 12.2 Flaws, Including a CVSS 8.8 Bug

    NVD published two more high-severity CVE records for IBM Guardium Data Protection 12.2 on September 25: CVE-2026-85542 (CVSS 8.8), a command injection bug, and CVE-2026-85029 (CVSS 7.5), a path traversal flaw. IBM lists fix pack SqlGuard_12.0p233.

  • Tech· 

    Microsoft Outlook Flaw CVE-2026-100208 Could Allow Remote Code Execution

    Microsoft Office Outlook has an integer overflow flaw, CVE-2026-100208, that could let an unauthorized attacker run code over a network. Microsoft scores it 7.5 (High), and an attack needs user interaction.

  • Tech· 

    IBM Power Server Firmware Flaw CVE-2026-93306 Can Crash the ASMI Web Interface

    CVE-2026-93306, published by NVD on September 25, lets an unauthenticated attacker on the management network crash the ASMI web server in IBM server firmware with a malformed HTTPS request. IBM rates it 7.1 (High) and has released fixed firmware for Power11, Power10 and Power9 systems.