‹ Crypto Risk & Custody Lesson 11 of 16
Contents Lesson 11 of 16

4 min read · professional

Why do bridges lose the most money?

Look at any list of the largest crypto thefts and the same category dominates it. That is not coincidence — it follows from what a bridge structurally is.

The structure guarantees the problem

Chains cannot read each other. A bridge therefore locks an asset on chain A and mints a representation of it on chain B. The representation has value only because something guarantees the lock is real and will be honoured.

So a bridge is two things at once:

  • a pool containing everything anyone has ever bridged, and
  • a verification mechanism — a validator set, a multisig, or a piece of proof-checking code — that decides when the pool releases funds.

The pool grows with adoption. The verification mechanism does not. Compromise it once and the whole pool moves, in one transaction, with no per-user limit and no partial failure. The value at risk scales with usage; the security is a fixed number of keys or a fixed piece of logic.

The documented cases

Ronin, March 2022 — roughly $625m. The Axie Infinity bridge required 5 of 9 validator signatures. The attacker obtained four validator keys operated by Sky Mavis, and a fifth signature via the Axie DAO, which had granted Sky Mavis permission to sign on its behalf during a period of high load in November 2021 — a temporary allowance that was never revoked. The theft was discovered roughly six days later, when a user could not complete a withdrawal. The US Treasury subsequently attributed the incident to the Lazarus Group. Note what failed: not the cryptography, not the contracts, but an expired permission that stayed live and key custody at one company.

Poly Network, August 2021 — roughly $611m. A crafted call to the cross-chain manager contract allowed the attacker to change the keeper responsible for authorising withdrawals, and then to authorise their own. Most of the funds were subsequently returned.

Wormhole, February 2022 — roughly $326m. A signature-verification flaw on the Solana side allowed the attacker to bypass the guardian check and mint 120,000 wrapped ETH with no corresponding deposit. The parent firm replaced the funds.

BNB Chain Token Hub, October 2022 — roughly 2 million BNB minted, on the order of $570m at the time. A flaw in the Merkle proof verification allowed forged proofs. The chain was halted, which limited actual extraction to a fraction of the minted amount — an option no permissionless design offers.

Nomad, August 2022 — roughly $190m. A routine upgrade set an accepted-message root to zero, with the effect that every message validated. The first exploit transaction became a public recipe, and hundreds of addresses copied it and substituted their own recipient. Once an exploit is a confirmed transaction, it is documentation.

What the cases have in common

Read the five again and notice how few are contract-logic failures in the interesting sense. A stale permission. A keeper that could be replaced. A verification bypass. A configuration value set to zero during an upgrade. In most of the largest bridge losses the human quorum or the upgrade process failed, not the chain.

The consequence for anyone holding a bridged asset

A wrapped asset is a credit instrument. Wrapped BTC on another chain is a claim on whoever holds the underlying BTC, subject to the bridge's verification mechanism continuing to work. Holding it means holding bridge risk in addition to price risk.

That extra risk appears nowhere in a price chart. Right up until the moment it does — at which point the wrapped asset can decouple from the thing it represents, because the thing it represents is no longer reliably redeemable.

Try it now

  1. For any bridged asset you hold or can look up, identify exactly what can release the locked collateral: a multisig (what threshold, how many independent signers?), a validator set (how many, run by whom?), or an on-chain light-client verification.
  2. Find the total value locked in that bridge and divide it by the number of keys required to move it. Write the result as "dollars per key." It is a crude number and a clarifying one.
  3. Read one bridge post-mortem end to end and decide whether the failure was in contract code or in key and permission management. Then check whether the audit, if there was one, covered the part that broke.