Cross-Chain Bridge Exploits
Every major bridge and cross-chain infrastructure exploit, with the amount lost, the root cause, and a primary source for each figure.
Bridge failures get reported as smart contract failures. Some of them are. But when you classify the largest incidents by what actually went wrong, 62% of the losses on this page trace to an authorization failure rather than a broken calculation.
Either an attacker held enough keys to sign, or they reached a privileged function they should never have been able to call. In both cases the code ran as written. That is a governance problem wearing a technical costume, and it is why the same category of loss keeps recurring after each generation of contracts gets audited harder than the last.
What actually goes wrong
An attacker obtained enough signing authority to authorize transfers. The contract behaved correctly.
The contract accepted a signature or merkle proof it should have rejected.
A privileged function could be called by someone who should not have been able to call it.
Accounting, deposit or approval handling behaved differently from intent.
The defect shipped in an upgrade or initialization step rather than in the original design.
Group the first and third categories together, since both answer the same question of whether the system treated an attacker as entitled, and they account for 62% of everything lost here. Verification and logic defects, the failures an audit is designed to catch, account for the rest. Both matter. But the industry spends far more on the second than the first, and the losses do not follow that ratio.
The incidents
18 incidents · Last updated 23 August 2026.
| Date | Protocol | Lost | Root cause |
|---|---|---|---|
|
Gravity Bridge
Roughly $4.3MM in USDC, 274 ETH and smaller balances were withdrawn in what researchers judge a compromised signing key rather than a contract defect. The bridge locks tokens on Ethereum and mints mirrored versions on Cosmos, so valid validator signatures are sufficient to make a forged withdrawal look legitimate. Outcome: Network halted. Part of the proceeds laundered through ChangeNow and Binance. The eighth bridge exploit of a month in which PeckShield tracked over $328MM in bridge losses. |
$5.4MM | Key or signer compromise | |
|
Verus (Ethereum Bridge)
A forged Merkle proof was accepted by the bridge contract. Both sides ran validation, but neither checked that the input amount recorded on Verus matched the payout amount claimed on Ethereum. The attacker drew out 103.6 tBTC, 1,625 ETH and 147,000 USDC. Outcome: The attacker returned 4,052.4 ETH, retaining roughly 25% as a self-declared whitehat bounty. |
$11.58MM | Signature or proof verification flaw | |
|
Thorchain
Cross-chain infra
An attacker drained roughly $10.8MM across four chains. Investigators attribute it to a flaw in the protocol's GG20 threshold-signature implementation that leaked enough vault key material to reconstruct a private key, with suspicion falling on a newly churned node inside the validator set. Outcome: Trading and signing halted for roughly 13 hours. RUNE fell 12%. |
$10.8MM | Key or signer compromise | |
|
Kelp DAO
Cross-chain infra
A single signing authority with no fallback was used to mint 116,500 ETH of unbacked tokens. The proceeds were laundered inside 46 minutes. Outcome: Triggered roughly $4Bn in asset migrations across cross-chain middleware. |
$292MM | Key or signer compromise | |
|
Ronin Network (second incident)
A contract upgrade introduced a withdrawal flaw that an MEV bot found and exercised before any malicious actor did. Outcome: Fully returned by the whitehat operators within days. |
$12MM | Upgrade or configuration error | |
|
LI.FI
A newly deployed facet allowed arbitrary calls, which the attacker used to drain 153 wallets holding infinite approvals to the LI.FI contract. A structurally similar flaw had been exploited in 2022. Outcome: Not recovered. Approvals revoked and the facet removed. |
$11.6MM | Contract logic flaw | |
|
Socket / Bungee
A route contract failed to validate user-supplied calldata, letting the attacker drain wallets that had granted the aggregator unlimited token approvals. Only users with live approvals were affected. Outcome: Roughly two thirds returned. Users urged to revoke approvals. |
$3.3MM | Contract logic flaw | |
|
Orbit Chain
Seven of the bridge's validator signatures were produced by an attacker who had obtained the corresponding keys, draining the vault in a single sequence on New Year's Eve. Outcome: Not recovered. |
$81.5MM | Key or signer compromise | |
|
HECO Bridge (HTX)
A compromised operator account authorized withdrawals from the bridge. HTX exchange hot wallets were drained for a further sum in the same incident window. Outcome: Not recovered. Losses covered by HTX. |
$86.8MM | Key or signer compromise | |
|
Multichain
Funds moved out of multiple bridge contracts in a pattern consistent with control of the operator keys, during a period when the CEO had reportedly been detained and held sole custody of key material. Outcome: Protocol shut down. Not recovered. |
$126MM | Key or signer compromise | |
|
BNB Chain (Token Hub)
A flaw in IAVL merkle proof verification let the attacker forge a proof for a withdrawal that was never deposited, minting 2MM BNB. Outcome: Chain halted by validators; the majority of funds were frozen before they could leave. |
$566MM | Signature or proof verification flaw | |
|
Nomad
A routine initialization set a trusted root to zero, which made every message appear pre-approved. Once the first transaction was public, hundreds of accounts copied it in an open free-for-all. Outcome: Roughly a fifth returned by whitehats. The rest not recovered. |
$190MM | Upgrade or configuration error | |
|
Harmony (Horizon Bridge)
The bridge ran a 2-of-5 multisig, so compromising two signers was enough to authorize any transfer. The quorum was the vulnerability. Outcome: Not recovered. |
$100MM | Key or signer compromise | |
|
Ronin Network
The attacker obtained 5 of 9 validator keys, 4 through a compromised operator and a 5th via an allowlist left in place after an earlier scaling arrangement. Every signature was valid. Outcome: Attributed by the FBI to the Lazarus Group. Largely not recovered; users made whole by Sky Mavis and investors. |
$624MM | Key or signer compromise | |
|
Wormhole
The Solana-side contract could be tricked into accepting a forged guardian signature set, letting the attacker mint 120,000 wETH without depositing anything. Outcome: Jump Crypto replaced the shortfall within days; funds later counter-exploited back in 2023. |
$326MM | Signature or proof verification flaw | |
|
Qubit Finance (QBridge)
A deposit function accepted a zero-value transfer as though collateral had arrived, letting the attacker mint borrowing power against nothing. 206,809 BNB was drained. Outcome: Not recovered. |
$80MM | Contract logic flaw | |
|
pNetwork
A flaw in peg-out handling let the attacker mix legitimate and forged requests, draining pBTC collateral from the bridge. Outcome: Partially recovered after the protocol offered a bounty. |
$12.5MM | Contract logic flaw | |
|
Poly Network
The attacker reached a privileged function and reassigned the keeper role to an address they controlled, then authorized withdrawals as the protocol. Outcome: Substantially all funds returned by the attacker within days. |
$612MM | Access control flaw |
Methodology
What is included. Protocols whose function is moving value between chains: bridges, cross-chain liquidity networks and the middleware that secures them. Incidents are listed where a public figure and at least one named source exist. Exchange hot-wallet thefts, lending protocol exploits and oracle manipulations are out of scope even when they involve wrapped assets, because mixing them in would inflate the totals and blur the root-cause analysis this page exists to support.
How amounts are stated. USD at the time of the incident, as reported by the cited source, not restated to current prices. Restating would silently diverge from every source listed here. Where sources disagree, the figure most consistently reported is used and rounded rather than presented with false precision.
How root cause is assigned. Each incident carries exactly one root cause, chosen as the failure without which the exploit would not have worked. Where a protocol has published a post-mortem, that document governs. Where none exists, the incident is marked undisclosed rather than inferred.
What this page is not. It is not a complete census of every bridge incident. Small exploits and those without a credible public figure are omitted deliberately. The totals should be read as a floor.
Corrections. If a figure, date or root cause here is wrong, tell me and it will be corrected with the source noted.
Cite this dataset
Free to use with attribution.
Moonis, O. (23 August 2026). Cross-Chain Bridge Exploit Database.
https://www.omarmoonis.com/learn/bridge-exploits/