SlowMist reported that ZetaChain was attacked and exploited. Preliminary analysis indicates the vulnerability stems from a lack of access control and input validation in the GatewayZEVM contract's `call` function. Attackers could exploit this to initiate malicious cross-chain calls and perform arbitrary operations on the target chain to transfer funds via the relay mechanism. SlowMist stated that attackers forged cross-chain events to trigger malicious calls to the relay, thereby stealing funds. The related attack transactions have been disclosed.