Cross-chain bridge security risks are frequent: 10 major attack cases resulted in losses exceeding $1.9 billion.

robot
Abstract generation in progress

Frequent Security Incidents of Cross-Chain Bridges: A Review of the Top 10 Attack Cases, Involving Over $1.9 Billion

In recent years, with the development of blockchain technology, cross-chain bridges have become an important infrastructure connecting different public chains, and their security has attracted significant attention. However, due to their management of large amounts of funds and frequent operations, cross-chain bridges have become popular targets for hacker attacks. This article will review 10 significant cross-chain bridge attack incidents that have occurred recently, summarize the lessons learned, and provide warnings for the industry.

Review of the Top 10 Attacks on Cross-Chain Bridges: Involving over $1.9 billion, $1.55 billion has been compensated or recovered

1. ChainSwap: 8 million USD loss

In July 2021, ChainSwap suffered two attacks, resulting in a total loss of approximately $8 million. The second attack affected more than 20 projects using ChainSwap. The reason for the attack was that the protocol did not strictly verify the validity of signatures. In the aftermath, several projects compensated users for their losses through snapshots and reissuing tokens.

2. Poly Network: All $610 million stolen has been recovered.

In August 2021, Poly Network was attacked, resulting in a loss of approximately $610 million across multiple chains. The attacker exploited a vulnerability in the contract's permission management to modify the validator address on the target chain. Ultimately, all stolen funds were returned.

3. Multichain: $6 million loss has been compensated

In January 2022, Multichain discovered a significant vulnerability affecting multiple tokens. Approximately 7,962 user addresses were impacted, resulting in a loss of $6.04 million. The vulnerability stemmed from the contract not properly verifying the legitimacy of tokens. The team has recovered nearly 50% of the funds and has provided compensation.

4. QBridge: $80 million loss, only 2% compensation

In January 2022, the lending protocol Qubit’s QBridge was attacked, resulting in a loss of approximately $80 million. The attacker exploited a contract vulnerability to mint xETH tokens out of thin air on BSC. Currently, 98% of the stolen funds have not been reimbursed.

5. Meter.io: $4.4 million loss, promises future revenue compensation

In February 2022, the Meter Passport cross-chain bridges were attacked, resulting in a loss of 4.4 million dollars. The reason was an "incorrect trust assumption" in the contract. The project team promised to compensate users for their losses with future earnings.

6. Ronin: $620 million loss has been compensated

In March 2022, the Ronin chain behind Axie Infinity suffered a social engineering attack, resulting in a loss of 6.2 million USD. The attackers infiltrated the system through fake recruitment and took control of multiple validation nodes. The developer Sky Mavis raised 150 million USD to compensate users.

7. Wormhole: $326 million loss has been compensated

In February 2022, Wormhole was attacked, resulting in a loss of approximately $326 million. The attacker exploited a signature verification vulnerability on the Solana side to mint a large amount of whETH. Jump Crypto injected 120,000 ETH into Wormhole to cover the losses.

8. EvoDeFi: Estimated millions of dollars in losses unaddressed

In June 2022, USDT severely depegged on the Oasis ecosystem DEX ValleySwap due to insufficient liquidity on the source chain of the cross-chain bridge EVODeFi. The specific amount of loss is unknown, but it is expected to reach the tens of millions of dollars. User losses have yet to be resolved.

9. Horizon: Nearly $100 million in losses, compensation plan in progress

In June 2022, Harmony's Horizon cross-chain bridge was attacked, resulting in a loss of approximately $100 million. The cause may be a private key leak. The project team is discussing compensation plans with the community.

10. Nomad: $190 million loss, part of the funds are expected to be recovered

In August 2022, the Nomad cross-chain bridges were attacked, resulting in a loss of $190 million. The attack stemmed from a low-level error during a contract upgrade. Some white hat hackers have expressed their willingness to return the funds, but the specific compensation plan has not yet been determined.

Summary

Cross-chain bridges, as a high-risk area, are inevitably subject to attacks even from top projects. However, projects with strong financial backing and a robust team background tend to handle compensation issues better after security incidents. For users, choosing stronger cross-chain bridge projects may be more prudent. At the same time, project teams should strengthen real-time monitoring and rapid response mechanisms to minimize potential losses.

W-4.06%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Share
Comment
0/400
DegenWhisperervip
· 1h ago
So you want free money... I'm so confused.
View OriginalReply0
LightningLadyvip
· 21h ago
All done, right?
View OriginalReply0
MetaverseHobovip
· 21h ago
There are too many of these things.
View OriginalReply0
OldLeekMastervip
· 21h ago
We suckers really suffer!
View OriginalReply0
InscriptionGrillervip
· 21h ago
I advise all suckers to take it easy. Even a signature can hit such a low-level vulnerability.
View OriginalReply0
DaoTherapyvip
· 21h ago
This smart contract is still too fragile.
View OriginalReply0
PanicSellervip
· 21h ago
Can you still sit still? Run!
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)