Bridge Security & Risks
A history of major bridge exploits (Poly Network, Wormhole, Ronin, Harmony, Nomad, BSC Token Hub, Multichain, Orbit), the trust models behind them, and how to evaluate bridge safety.
21 min · advanced · part of Cross-Chain & Bridges: Connecting Blockchains
What you'll learn
- Bridges Are the Highest-Value Targets in Crypto
- Poly Network — August 10, 2021 — $611M (Returned)
- Wormhole — February 2, 2022 — $325M
- Ronin Bridge — March 23, 2022 — $625M
- Harmony, Nomad, BSC Token Hub, Multichain, Orbit
- Bridge Trust Models: Trusted, Trust-Minimized, Optimistic
- How to Evaluate Bridge Safety
- Practical Self-Protection
- Where Bridge Security Is Heading
- For Deeper Reading
Key terms
- Lazarus Group
- A North Korean state-sponsored advanced persistent threat group attributed by U.S. Treasury OFAC to the Ronin Bridge ($625M, March 2022) and Harmony Horizon ($100M, June 2022) exploits, and suspected in Orbit Bridge ($82M, December 2023). Their playbook centers on social engineering of validator operators (notably the LinkedIn/PDF malware vector against Sky Mavis).
- Multisig threshold
- The minimum number of signatures required to authorize a transaction in a multi-signature scheme. Ronin used 5-of-9 (compromised exactly 5); Harmony used 2-of-5 (compromised 2). Threshold sizing relative to value secured is a critical security parameter.
- Validator compromise
- An attack where adversaries gain control of enough bridge validators to authorize fraudulent transactions, typically through hacking, social engineering, or insider threat. The dominant cause of major bridge losses 2021-2024.
- Replica contract initialization bug
- The Nomad Bridge vulnerability (August 2022) where a routine upgrade left the Replica contract in a state that effectively validated any message, leading to a "decentralized robbery" of $190M by hundreds of copycat addresses.
- Forged Merkle proof
- The BSC Token Hub vulnerability (October 6, 2022) where an attacker constructed a falsified Merkle proof that bypassed verification and minted 2 million BNB ($570M nominal) before Binance paused the chain.
- OFAC sanction
- A U.S. Treasury Office of Foreign Assets Control designation that prohibits U.S. persons from transacting with sanctioned addresses. OFAC sanctioned the Ronin Bridge attacker wallet on April 14, 2022, formally attributing the exploit to Lazarus Group.
- Trust-minimized bridge
- A bridge whose security relies on cryptographic proofs (light clients, ZK proofs) rather than human/validator trust. Cosmos IBC and emerging ZK bridges from Polyhedra, Succinct, and others fall into this category.
- Risk Management Network
- Chainlink CCIP's independent secondary verifier committee that monitors all CCIP messages and can block them on anomaly detection, complementing primary OCR consensus among Decentralized Oracle Network nodes.
- Bug bounty
- A reward offered by a protocol to security researchers who responsibly disclose vulnerabilities. Bounty size relative to TVL signals seriousness — small bounties on large bridges are a known red flag.
- Time-locked upgrade
- A smart contract upgrade mechanism that imposes a mandatory delay between proposing and implementing changes, allowing the community time to review. Reduces risk of malicious or accidental upgrades but also slows incident response.
- TVL (Total Value Locked)
- The total assets deposited in a protocol or bridge. For bridges specifically, TVL approximates the bounty available to a successful exploiter and is one of the key metrics for risk assessment.
- Canonical L2 bridge
- The bridge operated by an L2's own development team (Polygon PoS bridge, Arbitrum bridge, Base bridge, Optimism bridge). Shares security with the L2 itself and is typically the safest option for that destination, though slower for optimistic rollup withdrawals (typically 7 days).
Read the full lesson in the CryptoBipto app.
Open lessonEducational only — not financial advice.
