Registry
Incidents
Browse bridge incident cases with evidence-backed outcome tracking.
| Incident | Date | Bridge | Type | Reported loss | Recovery | Reimbursement | Outcome | Resolution | Maturity | Freshness |
|---|---|---|---|---|---|---|---|---|---|---|
| THORChain 2026 GG20 TSS vault exploit In May 2026, a newly churned node operator exploited a vulnerability in THORChain's GG20 threshold-signature implementation, reconstructed a vault private key, and drained approximately $10.7 million from one Asgard vault across multiple chains. | 2026-05-15 | THORChain | Exploit | $10.7 million official estimate; more than $11 million later analytics estimate | Unknown | Unknown | Paused Long Term | Unresolved | reviewed | current |
| LI.FI 2024 facet approval exploit A newly deployed smart-contract facet omitted validation around arbitrary external calls, allowing an attacker to drain assets from 153 Ethereum and Arbitrum wallets with infinite approvals. | 2024-07-16 | LI.FI | Exploit | Approximately $11.6 million | Unknown | Announced | Active After Incident | Unresolved | reviewed | current |
| Holograph 2024 unauthorized HLG mint A malicious actor exploited the Holograph Operator contract and minted one billion additional HLG tokens on Mantle. The team patched the initial exploit, temporarily locked the protocol, coordinated account freezes, and announced a staged burn plan and external investigation. | 2024-06-13 | Holograph Protocol | Unauthorized Token Mint | 1 billion HLG unauthorized mint; realized loss not fixed | Partial Freeze And Burn Plan | Not Announced | Historical Protocol Inactive | Unresolved | reviewed | current |
| SOCKET 2024 Gateway approval exploit An attacker used an incomplete input-validation path in the Socket Gateway contract to drain assets from Ethereum wallets that had granted approvals to the affected route. SOCKET paused the contracts, removed the route, restored service, and later reported recovering 1,032 ETH. | 2024-01-16 | SOCKET Protocol | Exploit | Approximately $3.3 million | Partial Recovery | Announced | Active After Incident | Unresolved | reviewed | current |
| Orbit Bridge 2024 Ethereum vault exploit On January 1, 2024, an unidentified attacker removed approximately $81.5 million in ETH, WBTC, USDT, USDC, and DAI from the Orbit Bridge Ethereum vault. The Ethereum vault was shut down, and later recovery and partial service-resumption plans remained incomplete. | 2024-01-01 | Orbit Bridge | Exploit | $81.5 million | Unknown | In Progress | Limited After Incident | Unresolved | reviewed | current |
| Multichain 2023 abnormal MPC asset outflows In July 2023, more than $125 million in assets moved out of Multichain-controlled bridge contracts to unknown addresses. The protocol then stopped services and later announced that operations would cease after losing access to key operational systems and funds. | 2023-07-06 | Multichain | Abnormal Transfers | More than $125 million in abnormal outflows | Unknown | Unknown | Dead After Incident | Unresolved | reviewed | current |
| Allbridge Core 2023 BNB Chain pool exploit Attackers used flash-loan-funded deposits, withdrawals, and swaps to exploit flawed liquidity-accounting logic in Allbridge Core's BUSD and USDT pools on BNB Chain. | 2023-04-02 | Allbridge Core | Exploit | Approximately $650,000 official postmortem; about $573,000 initial estimate | Partial Recovery | Completed | Active After Incident | Final outcome known | reviewed | current |
| pNetwork 2022 pGALA contract-control incident A deployment misconfiguration allowed covert takeover of the pGALA token contract on BNB Chain. pNetwork stopped processing pGALA bridge operations and performed an emergency whitehat drain of the PancakeSwap pool; the GALA collateral on Ethereum was not stolen from the bridge. | 2022-11-03 | pNetwork | Security Misconfiguration | No bridge collateral loss reported | Whitehat Recovery | Announced | Affected Token Deprecated | Unresolved | reviewed | current |
| BSC Token Hub 2022 forged-proof exploit In October 2022, an attacker exploited BSC Token Hub by forging a bridge proof, creating and taking two million BNB. The nominal value was nearly $570 million, while BNB Chain later stated that about $100 million remained unrecovered after validators paused and resumed the network. | 2022-10-06 | BSC Token Hub | Exploit | Nearly $570 million minted; about $100 million unrecovered | Partial Recovery | Not Applicable | Deprecated After Incident | Unresolved | reviewed | current |
| Rainbow Bridge August 2022 fabricated-block attack attempt An attacker submitted a fabricated NEAR block to the Rainbow Bridge contract with a 5 ETH safe deposit. Automated watchdogs challenged the transaction in under approximately 31 seconds; no user funds were reported lost and the attacker forfeited the deposit. | 2022-08-20 | Rainbow Bridge | Attempted Exploit | No user-fund loss reported | Not Required | Not Applicable | Attack Thwarted | Final outcome known | reviewed | current |
| Celer cBridge 2022 DNS hijacking A DNS cache-poisoning attack redirected some cBridge frontend users toward malicious smart contracts capable of draining approved tokens. Celer took the frontend offline, advised approval revocation, and restored it with additional monitoring. | 2022-08-17 | Celer cBridge | Frontend Compromise | Approximately $240,000 reported | None | Announced | Active After Incident | Unresolved | reviewed | current |
| Nomad Bridge 2022 message verification exploit In August 2022, Nomad Bridge was exploited after a message verification flaw made fraudulent withdrawals copyable by many participants. Public reporting commonly describes the loss as roughly $190 million, with partial recovery and unresolved recovery/reimbursement questions. | 2022-08-01 | Nomad Bridge | Exploit | $190 million | Partial Recovery | In Progress | Limited After Incident | Unresolved | reviewed | current |
| Harmony Horizon Bridge 2022 exploit In June 2022, Harmony's Horizon Bridge was exploited for roughly $100 million. Later public statements and FBI material linked the theft to Lazarus Group actors, while recovery and reimbursement details remain incomplete in this seed record. | 2022-06-24 | Harmony Horizon Bridge | Exploit | $100 million | Partial Recovery | In Progress | Dead After Incident | Unresolved | reviewed | current |
| Rainbow Bridge May 2022 fabricated-block attack attempt An attacker attempted to submit a fabricated NEAR block to the Rainbow Bridge light client on Ethereum. A watchdog challenged the submission before funds could be released, and no bridge or user funds were reported lost. | 2022-05-01 | Rainbow Bridge | Attempted Exploit | No user-fund loss reported | Not Required | Not Applicable | Attack Thwarted | Final outcome known | reviewed | current |
| Ronin Bridge validator-key compromise In March 2022, Ronin Bridge was exploited after validator keys were compromised, leading to one of the largest reported bridge losses in crypto history. The incident later became a reference case for bridge validator and cross-chain security risk. | 2022-03-29 | Ronin Bridge | Exploit | $620 million | Partial Recovery | Completed | Active After Incident | Final outcome known | reviewed | current |
| LI.FI 2022 approval-drain exploit An unchecked external-call path in LI.FI's pre-bridge swap logic allowed an attacker to invoke token contracts and drain assets from wallets that had granted infinite approvals. | 2022-03-20 | LI.FI | Exploit | Approximately $600,000 | None | Partial | Active After Incident | Unresolved | reviewed | current |
| Meter Passport 2022 false-deposit exploit An attacker directly called a modified ERC-20 deposit handler that failed to verify the transaction value, enabling unbacked BNB and WETH minting and withdrawal of bridge reserves across multiple networks. | 2022-02-05 | Meter Passport | Exploit | $4.25 million official estimate; about $4.4 million secondary estimate | Unknown | In Progress | Active After Incident | Unresolved | reviewed | current |
| Wormhole 2022 wrapped ETH mint exploit In February 2022, Wormhole was exploited through a vulnerability that allowed unauthorized wrapped ETH minting on Solana. Public reporting described a loss of roughly $320 million, and the bridge deficit was later backfilled. | 2022-02-02 | Wormhole | Exploit | $320 million | Not Applicable | Completed | Active After Incident | Final outcome known | reviewed | current |
| QBridge 2022 zero-value deposit exploit In January 2022, a logic flaw in QBridge allowed an attacker to submit deposit calls without transferring ETH, mint unbacked xETH on BNB Chain, and use that collateral to withdraw roughly $80 million from Qubit markets. | 2022-01-27 | QBridge | Exploit | $80 million stolen; $90.8 million later damage estimate | Unknown | In Progress | Dead After Incident | Unresolved | reviewed | current |
| Nerve Bridge 2021 metapool exploit An attacker exploited an inconsistent exchange-amount calculation in Saddle-derived metapool code used by Nerve Bridge. BlockSec reported that the fUSDT and UST pools were drained and that the attacker gained approximately 900 BNB. | 2021-11-15 | NerveNetwork | Metapool Exploit | Approximately 900 BNB attacker profit | Unknown | Unknown | Protocol Active After Incident | Unresolved | reviewed | current |
| Synapse 2021 nUSD metapool exploit An attacker manipulated the Avalanche nUSD metapool virtual price by approximately 12.5% through a bug in the Saddle-derived metapool implementation. The attacker attempted to move approximately $8.2 million in nUSD through the bridge while validators were offline; the malicious transaction was not processed and affected liquidity providers were to be made whole. | 2021-11-06 | Synapse Protocol | Exploit | No ultimate fund loss reported; approximately $8.2 million nUSD protected | Funds Protected | In Progress | Active After Incident | Unresolved | reviewed | current |
| pNetwork 2021 pBTC-on-BSC exploit A bug in pNetwork's Rust event-log extraction caused malicious peg-out requests to be processed on the pBTC-on-BSC bridge. The attacker stole 277 BTC collateral; other pTokens bridges were stopped and were not successfully drained. | 2021-09-19 | pNetwork | Exploit | 277 BTC | None Confirmed | Announced | Bridge Family Later Deprecated | Unresolved | reviewed | current |
| Poly Network 2021 cross-chain exploit In August 2021, Poly Network was exploited for more than $600 million across multiple chains. The case became a major reference point because the attacker later returned most or all of the funds, making it a recovery-centered bridge incident rather than a permanent-loss case. | 2021-08-10 | Poly Network | Exploit | $610 million | Full Recovery | Not Applicable | Active After Incident | Final outcome known | reviewed | current |
| THORChain 2021 ETH Router exploit 2 A second July 2021 attack used a fake router and malicious refund memo to make Bifrost accept a fabricated deposit event, draining economically significant ERC-20 assets from THORChain's Ethereum-side liquidity. | 2021-07-22 | THORChain | Exploit | Approximately $8 million | Unknown | Completed | Active After Incident | Final outcome known | reviewed | current |
| THORChain 2021 ETH Router exploit 1 In July 2021, an attacker used a contract positioned in front of THORChain's ETH Router to make Bifrost report deposits that had not actually been received, ultimately draining ETH and contributing to protocol insolvency. | 2021-07-15 | THORChain | Exploit | $8 million official estimate; $5 million secondary estimate | Unknown | Completed | Active After Incident | Final outcome known | reviewed | current |
| ChainSwap July 10–11, 2021 quota exploit A logic flaw in ChainSwap's cross-chain quota code allowed non-whitelisted addresses to increase bridge quota and affect 20 bridged assets. ChainSwap reported a combined value of approximately $4 million and took the bridge offline. | 2021-07-10 | ChainSwap | Exploit | Approximately $4 million | None | In Progress | Active After Incident | Unresolved | reviewed | current |
| ChainSwap July 2, 2021 exploit An attacker exploited the ChainSwap bridge and withdrew assets from wallets that had interacted with it. The team froze the bridge and nodes, deployed a fix, and estimated total damage at approximately $800,000. | 2021-07-02 | ChainSwap | Exploit | Approximately $800,000 | Partial Recovery | In Progress | Active After Incident | Unresolved | reviewed | current |
No matching incident cases.
Clear or change the current search and filter settings.