A missing validation check seemingly allowed multiple attackers to spoof cross-chain messages and drain the protocol's PortalV2 contract.