ZetaChain has been exploited, according to Odaily, with initial analysis indicating that the vulnerability stems from the GatewayZEVM contract's call function lacking access control and input validation. This flaw allowed attackers to initiate malicious cross-chain calls and execute arbitrary operations on the target chain to transfer funds.
The attackers reportedly forged cross-chain events to trigger relayers to execute malicious calls, resulting in the theft of funds. The transactions related to this attack have now been disclosed.