Registry

Incidents

Browse bridge incident cases with evidence-backed outcome tracking.

27 incident cases Default sort: newest incident date
Incident Date Bridge Type Reported loss Recovery Reimbursement Outcome Resolution Maturity Freshness
THORChain 2026 GG20 TSS vault exploit In May 2026, a newly churned node operator exploited a vulnerability in THORChain's GG20 threshold-signature implementation, reconstructed a vault private key, and drained approximately $10.7 million from one Asgard vault across multiple chains.
2026-05-15 THORChain Exploit $10.7 million official estimate; more than $11 million later analytics estimate Unknown Unknown Paused Long Term Unresolved reviewed current
LI.FI 2024 facet approval exploit A newly deployed smart-contract facet omitted validation around arbitrary external calls, allowing an attacker to drain assets from 153 Ethereum and Arbitrum wallets with infinite approvals.
2024-07-16 LI.FI Exploit Approximately $11.6 million Unknown Announced Active After Incident Unresolved reviewed current
Holograph 2024 unauthorized HLG mint A malicious actor exploited the Holograph Operator contract and minted one billion additional HLG tokens on Mantle. The team patched the initial exploit, temporarily locked the protocol, coordinated account freezes, and announced a staged burn plan and external investigation.
2024-06-13 Holograph Protocol Unauthorized Token Mint 1 billion HLG unauthorized mint; realized loss not fixed Partial Freeze And Burn Plan Not Announced Historical Protocol Inactive Unresolved reviewed current
SOCKET 2024 Gateway approval exploit An attacker used an incomplete input-validation path in the Socket Gateway contract to drain assets from Ethereum wallets that had granted approvals to the affected route. SOCKET paused the contracts, removed the route, restored service, and later reported recovering 1,032 ETH.
2024-01-16 SOCKET Protocol Exploit Approximately $3.3 million Partial Recovery Announced Active After Incident Unresolved reviewed current
Orbit Bridge 2024 Ethereum vault exploit On January 1, 2024, an unidentified attacker removed approximately $81.5 million in ETH, WBTC, USDT, USDC, and DAI from the Orbit Bridge Ethereum vault. The Ethereum vault was shut down, and later recovery and partial service-resumption plans remained incomplete.
2024-01-01 Orbit Bridge Exploit $81.5 million Unknown In Progress Limited After Incident Unresolved reviewed current
Multichain 2023 abnormal MPC asset outflows In July 2023, more than $125 million in assets moved out of Multichain-controlled bridge contracts to unknown addresses. The protocol then stopped services and later announced that operations would cease after losing access to key operational systems and funds.
2023-07-06 Multichain Abnormal Transfers More than $125 million in abnormal outflows Unknown Unknown Dead After Incident Unresolved reviewed current
Allbridge Core 2023 BNB Chain pool exploit Attackers used flash-loan-funded deposits, withdrawals, and swaps to exploit flawed liquidity-accounting logic in Allbridge Core's BUSD and USDT pools on BNB Chain.
2023-04-02 Allbridge Core Exploit Approximately $650,000 official postmortem; about $573,000 initial estimate Partial Recovery Completed Active After Incident Final outcome known reviewed current
pNetwork 2022 pGALA contract-control incident A deployment misconfiguration allowed covert takeover of the pGALA token contract on BNB Chain. pNetwork stopped processing pGALA bridge operations and performed an emergency whitehat drain of the PancakeSwap pool; the GALA collateral on Ethereum was not stolen from the bridge.
2022-11-03 pNetwork Security Misconfiguration No bridge collateral loss reported Whitehat Recovery Announced Affected Token Deprecated Unresolved reviewed current
BSC Token Hub 2022 forged-proof exploit In October 2022, an attacker exploited BSC Token Hub by forging a bridge proof, creating and taking two million BNB. The nominal value was nearly $570 million, while BNB Chain later stated that about $100 million remained unrecovered after validators paused and resumed the network.
2022-10-06 BSC Token Hub Exploit Nearly $570 million minted; about $100 million unrecovered Partial Recovery Not Applicable Deprecated After Incident Unresolved reviewed current
Rainbow Bridge August 2022 fabricated-block attack attempt An attacker submitted a fabricated NEAR block to the Rainbow Bridge contract with a 5 ETH safe deposit. Automated watchdogs challenged the transaction in under approximately 31 seconds; no user funds were reported lost and the attacker forfeited the deposit.
2022-08-20 Rainbow Bridge Attempted Exploit No user-fund loss reported Not Required Not Applicable Attack Thwarted Final outcome known reviewed current
Celer cBridge 2022 DNS hijacking A DNS cache-poisoning attack redirected some cBridge frontend users toward malicious smart contracts capable of draining approved tokens. Celer took the frontend offline, advised approval revocation, and restored it with additional monitoring.
2022-08-17 Celer cBridge Frontend Compromise Approximately $240,000 reported None Announced Active After Incident Unresolved reviewed current
Nomad Bridge 2022 message verification exploit In August 2022, Nomad Bridge was exploited after a message verification flaw made fraudulent withdrawals copyable by many participants. Public reporting commonly describes the loss as roughly $190 million, with partial recovery and unresolved recovery/reimbursement questions.
2022-08-01 Nomad Bridge Exploit $190 million Partial Recovery In Progress Limited After Incident Unresolved reviewed current
Harmony Horizon Bridge 2022 exploit In June 2022, Harmony's Horizon Bridge was exploited for roughly $100 million. Later public statements and FBI material linked the theft to Lazarus Group actors, while recovery and reimbursement details remain incomplete in this seed record.
2022-06-24 Harmony Horizon Bridge Exploit $100 million Partial Recovery In Progress Dead After Incident Unresolved reviewed current
Rainbow Bridge May 2022 fabricated-block attack attempt An attacker attempted to submit a fabricated NEAR block to the Rainbow Bridge light client on Ethereum. A watchdog challenged the submission before funds could be released, and no bridge or user funds were reported lost.
2022-05-01 Rainbow Bridge Attempted Exploit No user-fund loss reported Not Required Not Applicable Attack Thwarted Final outcome known reviewed current
Ronin Bridge validator-key compromise In March 2022, Ronin Bridge was exploited after validator keys were compromised, leading to one of the largest reported bridge losses in crypto history. The incident later became a reference case for bridge validator and cross-chain security risk.
2022-03-29 Ronin Bridge Exploit $620 million Partial Recovery Completed Active After Incident Final outcome known reviewed current
LI.FI 2022 approval-drain exploit An unchecked external-call path in LI.FI's pre-bridge swap logic allowed an attacker to invoke token contracts and drain assets from wallets that had granted infinite approvals.
2022-03-20 LI.FI Exploit Approximately $600,000 None Partial Active After Incident Unresolved reviewed current
Meter Passport 2022 false-deposit exploit An attacker directly called a modified ERC-20 deposit handler that failed to verify the transaction value, enabling unbacked BNB and WETH minting and withdrawal of bridge reserves across multiple networks.
2022-02-05 Meter Passport Exploit $4.25 million official estimate; about $4.4 million secondary estimate Unknown In Progress Active After Incident Unresolved reviewed current
Wormhole 2022 wrapped ETH mint exploit In February 2022, Wormhole was exploited through a vulnerability that allowed unauthorized wrapped ETH minting on Solana. Public reporting described a loss of roughly $320 million, and the bridge deficit was later backfilled.
2022-02-02 Wormhole Exploit $320 million Not Applicable Completed Active After Incident Final outcome known reviewed current
QBridge 2022 zero-value deposit exploit In January 2022, a logic flaw in QBridge allowed an attacker to submit deposit calls without transferring ETH, mint unbacked xETH on BNB Chain, and use that collateral to withdraw roughly $80 million from Qubit markets.
2022-01-27 QBridge Exploit $80 million stolen; $90.8 million later damage estimate Unknown In Progress Dead After Incident Unresolved reviewed current
Nerve Bridge 2021 metapool exploit An attacker exploited an inconsistent exchange-amount calculation in Saddle-derived metapool code used by Nerve Bridge. BlockSec reported that the fUSDT and UST pools were drained and that the attacker gained approximately 900 BNB.
2021-11-15 NerveNetwork Metapool Exploit Approximately 900 BNB attacker profit Unknown Unknown Protocol Active After Incident Unresolved reviewed current
Synapse 2021 nUSD metapool exploit An attacker manipulated the Avalanche nUSD metapool virtual price by approximately 12.5% through a bug in the Saddle-derived metapool implementation. The attacker attempted to move approximately $8.2 million in nUSD through the bridge while validators were offline; the malicious transaction was not processed and affected liquidity providers were to be made whole.
2021-11-06 Synapse Protocol Exploit No ultimate fund loss reported; approximately $8.2 million nUSD protected Funds Protected In Progress Active After Incident Unresolved reviewed current
pNetwork 2021 pBTC-on-BSC exploit A bug in pNetwork's Rust event-log extraction caused malicious peg-out requests to be processed on the pBTC-on-BSC bridge. The attacker stole 277 BTC collateral; other pTokens bridges were stopped and were not successfully drained.
2021-09-19 pNetwork Exploit 277 BTC None Confirmed Announced Bridge Family Later Deprecated Unresolved reviewed current
Poly Network 2021 cross-chain exploit In August 2021, Poly Network was exploited for more than $600 million across multiple chains. The case became a major reference point because the attacker later returned most or all of the funds, making it a recovery-centered bridge incident rather than a permanent-loss case.
2021-08-10 Poly Network Exploit $610 million Full Recovery Not Applicable Active After Incident Final outcome known reviewed current
THORChain 2021 ETH Router exploit 2 A second July 2021 attack used a fake router and malicious refund memo to make Bifrost accept a fabricated deposit event, draining economically significant ERC-20 assets from THORChain's Ethereum-side liquidity.
2021-07-22 THORChain Exploit Approximately $8 million Unknown Completed Active After Incident Final outcome known reviewed current
THORChain 2021 ETH Router exploit 1 In July 2021, an attacker used a contract positioned in front of THORChain's ETH Router to make Bifrost report deposits that had not actually been received, ultimately draining ETH and contributing to protocol insolvency.
2021-07-15 THORChain Exploit $8 million official estimate; $5 million secondary estimate Unknown Completed Active After Incident Final outcome known reviewed current
ChainSwap July 10–11, 2021 quota exploit A logic flaw in ChainSwap's cross-chain quota code allowed non-whitelisted addresses to increase bridge quota and affect 20 bridged assets. ChainSwap reported a combined value of approximately $4 million and took the bridge offline.
2021-07-10 ChainSwap Exploit Approximately $4 million None In Progress Active After Incident Unresolved reviewed current
ChainSwap July 2, 2021 exploit An attacker exploited the ChainSwap bridge and withdrew assets from wallets that had interacted with it. The team froze the bridge and nodes, deployed a fix, and estimated total damage at approximately $800,000.
2021-07-02 ChainSwap Exploit Approximately $800,000 Partial Recovery In Progress Active After Incident Unresolved reviewed current