PANews reported on April 28th that, according to SlowMist's analysis, the root cause of the ZetaChain attack lies in the lack of access control and input validation in the GatewayZEVM contract's `call` function. This allows any user to initiate cross-chain calls through GatewayZEVM and execute arbitrary operations on external chains via relays. Attackers exploited this vulnerability to construct malicious cross-chain events on ZetaChain. After the relays captured these events, they executed malicious calls on the target chain via TSS, thereby stealing funds.
SlowMist analyzes the cause of the ZetaChain attack: the GatewayZEVM contract's call function lacks access control.
Share to:
Author: PA一线
This content is for market information only and is not investment advice.
Follow PANews official accounts, navigate bull and bear markets together
Recommended Reading
PANews App
24/7 blockchain news tracking and in-depth analysis.

