Elevated risk — novel cross-chain architecture with inherent complexity from Universal EVM and TSS-based multi-chain signing, partially offset by clean track record and active bug bounty program.
Risk Breakdown
Top Risks
ZetaChain's observer/signer architecture uses Threshold Signature Scheme (TSS) keys to send authenticated messages to external chains — compromise of the TSS key threshold could enable unauthorized cross-chain transactions, including minting unbacked assets or draining locked funds on connected chains.
The Universal EVM enables smart contracts on ZetaChain to read, write, and control assets across multiple external chains atomically — this cross-chain composability creates novel attack surfaces where a vulnerability in one chain's integration could propagate losses across all connected chains.
ZETA token has declined significantly from launch, with the project pivoting toward AI integration (Anuma, launched January 2026) — this strategic shift creates execution risk as resources are split between the original cross-chain interoperability mission and new AI infrastructure ambitions.
A 2023 Code4rena audit identified high-severity vulnerabilities including fake ZetaReceived events and potential token theft vectors — while fixed before mainnet, these findings highlight the complexity of the cross-chain messaging architecture and the potential for undiscovered vulnerabilities.
Frequently Asked Questions
Is ZetaChain safe to use?
What are the main risks of using ZetaChain?
What is ZetaChain's risk score breakdown?
How does ZetaChain compare to other Bridge protocols?
Has ZetaChain ever been hacked or exploited?
Incident History
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.