Skip to content

Deep dive · Hacks & Collapses · 10 min

Bridge Hacks: Why Cross-Chain Is the Most-Hacked Category

Bridges have lost over $2.5 billion. Ronin, Wormhole, Nomad — why connecting chains is the hardest security problem in crypto.

On this page
Why this matters

Cross-chain bridges are the most-hacked category in crypto. By 2024, bridges had lost over $2.5 billion to exploits — more than any other type of protocol. The reason is structural: a bridge must hold massive pools of assets on one chain and issue representations on another, which means it is a giant honeypot. If the bridge's security model (multisig, validator set, or smart-contract logic) fails, the attacker gets everything. Understanding why bridges break is essential for anyone using cross-chain products.

What is a bridge, and why is it a honeypot?

A connects two blockchains so that assets can move between them. The most common design is lock-and-mint: you lock your ETH on Ethereum, and the bridge mints a “wrapped” representation (wETH) on Solana. When you want to go back, you burn the wETH on Solana and the bridge unlocks your real ETH on Ethereum.

Lock, mint, burn, unlock

Ethereumbridge contractlock 10 ETHeveryone’s locked ETHunlock 10 ETHSolanamint 10 wETHburn 10 wETHTHEN MINTTHEN UNLOCK
Lock ETH on Ethereum and the bridge mints the same amount of wETH on Solana; burn the wETH and it unlocks the ETH. Everyone’s locked ETH sits in one contract, which is why bridges are targets.

The security problem is obvious once you state it: the bridge contract on Ethereum is holding all the locked ETH from all the people who have ever bridged. If the bridge's authorization system is compromised — whether through a smart-contract bug, a compromised multisig key, or a fake validator set — the attacker can unlock (or mint unlimited representations of) everything. The bridge is a centralized custodian disguised as a decentralized protocol, holding billions in a single contract.

The three failure modes

Bridges break in three main ways:

  1. Smart-contract bug: The bridge's code has a flaw (like Wormhole's signature verification or Nomad's initialization bug) that lets an attacker forge authorizations or mint unlimited tokens.
  2. Validator key compromise: The bridge uses a set of validators (or a multisig) to approve cross-chain messages, and an attacker steals enough keys to control the majority (like Ronin, where 5 of 9 keys were compromised).
  3. Centralized operator: A single party (or small multisig) controls the bridge, and they go rogue or get compromised.

All three reduce to the same root cause: concentrated trust in a system that holds enormous value.

The major bridge hacks

The following four hacks illustrate each failure mode. Together they account for over $1.7 billion in losses.

Ronin Bridge (Sky Mavis)

$625M lost

March 2022 · Ethereum ↔ Ronin (Axie Infinity)

What happened: The largest crypto hack at the time. The attacker stole 173,600 ETH and 25.5M USDC from the Ronin bridge — the sidechain that powers Axie Infinity, a popular play-to-earn game.

How: The attacker compromised 5 of 9 validator keys (the majority needed to approve withdrawals). Sky Mavis didn't discover the breach for 6 days — it was alerted by a user who couldn't withdraw. The attacker later turned out to be North Korea's Lazarus Group. Key compromise was social engineering: an engineer was tricked into applying for a fake job with a malicious PDF.

Wormhole Bridge

$326M lost

February 2022 · Solana ↔ Ethereum

What happened: An attacker minted 120,000 wrapped ETH (wETH) on Solana without depositing real ETH on Ethereum, then redeemed it for real ETH. The bridge was drained in a single transaction.

How: Wormhole's bridge used a signature verification system to authorize minting. The attacker exploited a flaw in the signature verification — bypassing the guardian multisig check — to forge the authorization and mint wETH out of thin air. The root cause was a smart-contract bug in how the bridge validated guardian signatures.

Nomad Bridge

$190M lost

August 2022 · Multi-chain

What happened: A catastrophic bug allowed anyone — literally anyone — to withdraw funds from the Nomad bridge by sending a specific transaction. A crowd of copycat attackers joined in.

How: A routine update to the Nomad bridge initialized a "trusted root" to 0x00...00 (zero). This meant every message was treated as valid. Once one attacker discovered this, the exploit became public knowledge, and a crowd of copycat attackers drained the bridge in a frenzy. It was described as "the most decentralized hack in history" — there was no single attacker.

Poly Network

$611M lost

August 2021 · Multi-chain (BSC, Polygon, Ethereum)

What happened: One of the largest hacks at the time. An attacker exploited a vulnerability in Poly Network's cross-chain contract to withdraw funds from multiple chains. Remarkably, the attacker later returned most of the funds.

How: The attacker exploited a vulnerability in how Poly Network verified cross-chain transaction parameters. They could forge the parameters to claim funds that didn't belong to them. After Poly Network publicly appealed to the attacker and law enforcement, the attacker (self-identified as a "white hat") returned ~$611M — saying they did it "for fun" and to expose the vulnerability.

Why bridges are uniquely vulnerable

Bridges are not just “another type of protocol” — they have a structural vulnerability that other protocols don't share:

  • They are giant honeypots. A single bridge contract holds all the locked assets from everyone who has ever used it. A successful attack drains everything at once. Compare this to a lending protocol, where each loan is collateralized individually.
  • Cross-chain validation is hard. A bridge on Ethereum needs to verify that something happened on Solana. This requires an oracle or validator set that attests to Solana's state. That oracle/validator set is a trust layer — and trust layers can be compromised.
  • Upgradeability adds risk. Many bridges use upgradeable smart contracts (so bugs can be fixed), which means the upgrade key is a central point of failure. If the upgrade key is compromised, the attacker can replace the bridge logic with anything.
  • The attack surface is large. A bridge involves smart contracts on multiple chains, a validator/oracle system, an upgrade mechanism, and off-chain infrastructure. Each component is a potential attack vector.

The Ronin Bridge case study: social engineering + key compromise

The Ronin Bridge hack ($625M, March 2022) was the largest crypto hack at the time — and a perfect illustration of the validator-key-compromise failure mode. (It has since been surpassed by the February 2025 hack of the Bybit exchange, ~$1.4–1.5B, also attributed to North Korean actors.) The Ronin bridge used 9 validators; 5 signatures were needed to approve a withdrawal. The attacker (North Korea's ) compromised 5 of 9 validator keys through social engineering: an Axie Infinity engineer was tricked into applying for a fake job, opening a malicious PDF that installed malware and gave the attacker access to the validator infrastructure.

The most damning detail: Sky Mavis didn't discover the breach for 6 days. They were alerted by a user who couldn't withdraw funds. The attacker had been slowly draining the bridge, undetected, for nearly a week. This highlights a key operational failure: the bridge had no real-time monitoring or anomaly detection for large withdrawals.

The Nomad Bridge case study: the most decentralized hack

The Nomad Bridge hack ($190M, August 2022) is the most bizarre. A routine update to the bridge's smart contract initialized a “trusted root” to zero (0x00...00). This meant that every message was treated as valid — no authorization check was actually being performed. Once one attacker discovered this and posted the exploit, a crowd of copycat attackers joined in, draining the bridge in a free-for-all.

It was described as “the most decentralized hack in history” — there was no single attacker, no sophisticated exploit, no key compromise. Just a bug that made authorization a no-op, and a crowd of opportunists. It is a pure demonstration of the smart-contract-bug failure mode, and a reminder that sometimes the simplest bugs are the most devastating.

What would fix this?

The bridge problem is one of the hardest unsolved problems in crypto. Proposed solutions include:

  • Light-client bridges: Instead of trusting a validator set, each chain runs a light client of the other chain and verifies state directly. Much more secure, but hard to build between chains with different consensus mechanisms.
  • ZK bridges: Use zero-knowledge proofs to cryptographically prove that a transaction happened on chain A, without trusting a validator set. See the Zero-Knowledge deep dive.
  • Rate limits and timelocks: Cap how much can be withdrawn per day, with a delay before large withdrawals execute. This limits the damage of a compromise (the Ronin hack would have been smaller with a daily cap).
  • Insurance and overcollateralization: Hold more reserves than are at risk, and insure against loss. This doesn't prevent hacks but mitigates the fallout.

As of 2026, the bridge problem is not solved. Most bridges in production still rely on validator sets or multisigs. Treat cross-chain bridging as a high-risk activity: minimize the time and amount of assets on bridges, and prefer bridges with strong security audits and real-time monitoring.

Key takeaways

  • By 2024, cross-chain bridges had lost over $2.5 billion — more than any other category of crypto protocol. The structural reason is that a bridge is a giant honeypot: it holds all locked assets from all users in a single contract.
  • Bridges break in three ways: smart-contract bugs (Wormhole, Nomad), validator key compromise (Ronin), and centralized operator failure. All three reduce to concentrated trust holding enormous value.
  • The Ronin Bridge hack ($625M) was the largest crypto hack until the Bybit hack of February 2025 (~$1.4–1.5B) — caused by North Korea's Lazarus Group compromising 5 of 9 validator keys via social engineering. Sky Mavis didn't discover it for 6 days.
  • The Nomad Bridge hack ($190M) showed that a single initialization bug can turn a bridge into an open vault that anyone can drain — no sophisticated attacker required.
  • The bridge problem is not solved. Light-client bridges and ZK bridges are promising but not yet widely deployed. In the meantime, minimize time and amount of assets on bridges, and treat cross-chain activity as high-risk.
Educational only, not financial or legal advice.