TradeExplorerDocsTwitterSupport

Backed by

Paradigm

Paradigm

INTEGRATE API

TradeExplorerDocsTwitterSupport

INTEGRATE

Backed by

Paradigm

Paradigm

← All articles
Every Major Bridge Hack and What Broke illustration

Every Major Bridge Hack and What Broke

Rift Research

Last updated

Bridge exploits account for more than $2.8 billion in losses since 2022, roughly 69% of all funds stolen from DeFi in that period. Trackers using different start dates and inclusion criteria report different totals; this figure and its 2022 start date come from a single consistent source. Almost none of them were cryptography failures. The chains worked. The signature schemes worked. What failed was a key held by a person, a verification routine that did not verify, a configuration changed during an upgrade, or an off-chain component nobody was auditing.

This page classifies incidents by what broke and what a user could have checked in advance. It is not a catalogue of every incident; several trackers do that better.


The short version

  1. Bridges are the most exploited component in crypto. More than $2.8 billion since 2022, roughly 69% of DeFi losses in that period.
  2. No major bridge hack broke the underlying cryptography. Every one failed at a trust component sitting beside it.
  3. Low thresholds were disproportionately targeted. Ronin required 5 of 9. Harmony required 2 of 5. Both fell.
  4. Two of the largest were verification routines that did not verify. Wormhole's signature check delegated to the wrong program and performed no check at all. Nomad's routine upgrade set the trusted root to zero, which made every proof valid.
  5. Recovery is rare and partial. Wormhole users were made whole by a backer, not the protocol. Nomad recovered roughly $36 million of $190 million. Harmony recovered nothing.
  6. The attack surface has moved. Contract exploits dominated 2022. Social engineering, supply-chain compromise and off-chain infrastructure dominate now.

On the figures. Where sources agree, a single number is used. Where they differ, the most widely reported figure is used and the variance is noted. Cumulative totals carry their start date, because trackers using different start dates and methodologies report materially different numbers.


Eight root causes, and what you could have checked

Root causeWhat happenedExampleWhat was checkable in advance
Key compromiseEnough signing keys were stolen through ordinary IT attack to meet the thresholdRonin, March 2022, $624M (reported between $600M and $625M). Validator keys compromised through a fake job offer. Harmony Horizon, June 2022, ~$100M, 2-of-5 multisigThe threshold and whether signers are genuinely independent. Both were public before the attacks
Verification that did not verifyThe contract accepted a signature set without checking itWormhole, February 2022, $326M, roughly 120,000 ETH. The verify_Signatures routine delegated to a stale program version, so no check was performedAudit coverage of the verification path specifically, not audit count
Trusted root misconfigurationAn upgrade set a security parameter to a value that made every proof validNomad, August 2022, ~$190M. A routine upgrade zeroed the trusted rootUpgrade process, timelock, and whether config changes are reviewed as code
Proof forgeryThe proof system accepted a forged inputBNB Bridge, October 2022, reported at approximately $568MMaturity and independent review of the proof system
Minting authoritySomeone could mint tokens without adding backingeBTC on Monad, May 2026, ~$76.6M. An admin key was compromised and the attacker called the mint functionWho can mint, and whether reserves are verifiable on-chain rather than by attestation
Off-chain coordination compromiseThe contracts held. The infrastructure around them did notGarden, October 2025 ($11.4M) and July 2026 ($450k), both solver-layerWhether the off-chain layer is in audit scope at all. Usually it is not
Custody concentrationNot an attack. One party held the keys and became unavailableMultichain, 2023. Users were still pursuing recovery through courts years laterWhether key distribution is disclosed, and what happens if one holder disappears
Standing user approvalsThe protocol was not breached. Stale unlimited allowances were drainedSocket, 2024Your own approvals. This one is entirely under your control

What does the pattern actually show?

The cryptography was never the weak point. Not once. Every incident above traces to a person, a configuration, a permission, or a server.

Warnings were often public. A researcher had identified Harmony's exact vulnerability and predicted the outcome. The threshold was not raised. The attack arrived 83 days later.

Low thresholds were selected for. Attackers went where fewer keys had to be compromised. A 2-of-5 is not a security model, it is two spear-phishing campaigns.

The failures were mundane. A fake job offer. A deprecated function left in place. A config value changed during a routine upgrade. None of these were novel cryptographic breaks.


Has the pattern changed?

Yes, and it matters for how you evaluate a bridge today.

2022 was the peak of contract exploits. Qubit, Wormhole, Ronin, Harmony, Nomad and BNB Bridge combined for roughly $1.9 billion in a single year. Most were smart contract flaws or key compromise.

The attack surface has since moved off-chain. Bridge exploits have been substantially replaced by social engineering and supply-chain compromise, with DPRK-linked activity attributed to a large share. Chainalysis attributed at least $2 billion in crypto theft to North Korean actors in 2025 alone.

Bridges have not stopped being targets. Roughly $329 million was attributed to bridge hacks in 2026 as of May that year. This figure moves and should carry its as-of date whenever it is cited.

The practical shift. Auditing the contract is now table stakes and no longer sufficient. The recent failures are in solver infrastructure, admin keys, deployment pipelines and the humans holding credentials. Those are the parts that no audit report covers.


What happens after a bridge is drained?

Recovery is the least-discussed part of the record and the most relevant if you are the one exposed.

  • Wormhole users were made whole because Jump Crypto covered the 120,000 ETH. That was a backer's balance-sheet decision, not a protocol mechanism.
  • Nomad recovered roughly $36 million of $190 million through a bounty offering white hats a 10% keep.
  • Harmony recovered nothing. A $10 million bounty produced no meaningful result.
  • Multichain users were still in court years afterwards.

The lesson. There is no reliable recovery mechanism. Whether you are made whole depends on whether someone with a balance sheet decides to make you whole. Design around the assumption that a loss is final.


What can you actually check before depositing?

Six questions, derived from the failure record rather than from theory.

  1. What is the threshold, and are the signers genuinely independent? Ronin's fifth signature came from a delegation the operator still effectively controlled.
  2. Is the verification path specifically audited? Audit count is a weak signal. Coverage of the code that checks proofs is the relevant one.
  3. What happens during an upgrade? Nomad's loss came from a routine upgrade. Ask whether configuration changes are timelocked and reviewed as code.
  4. Who can mint, and how would you know if they did? On-chain proof of reserves answers this. An attestation asks you to trust a report.
  5. Is the off-chain layer in audit scope? Solvers, relayers, admin infrastructure. Usually the answer is no, and that is where the recent failures are.
  6. What is your exposure window? Holding a wrapped representation is an open-ended exposure. Completing a native swap closes it in minutes.

Where does Rift sit in this taxonomy?

Rift is exposed to several of these categories and it is worth being specific about which.

Off-chain coordination and infrastructure. Rift's execution runs in a hardware enclave in a data centre. Compromise of the hardware vendor or the data centre operator is the analogue of the off-chain compromise category, and it is the primary risk.

Dependency inheritance. Rift routes through other venues. A venue compromised while holding funds mid-route loses those funds. Every dependency in the path is inherited.

Code risk. No formal audit has taken place. The code is open source and heavily tested, which is not the same thing.

Upgrade risk, mitigated but present. Upgrades are gated by an Ethereum contract holding the approved image hash, a hardware-key multisig and a seven-day timelock, during which any single uncompromised signer can refund all users. That is a longer and more public window than Nomad had, not an elimination of the category.

Not applicable. Rift settles to native assets and does not issue a wrapped representation, so the minting-authority category does not apply, and the exposure window is the duration of the trade rather than open-ended.


Sources

Related: Is a TEE Safer Than a Multisig Bridge? compares the trust models these incidents tested. How to Move Bitcoin to Ethereum covers the exposure window on wrapped representations.

Get the best execution.

TRADE

INTEGRATE

The ultimate onchain trading API.
Any asset. Best Price. One click.

PRODUCT

TradeExplorerIntegrate
Rift

© 2026 RIFT RESEARCH, INC.

/// @RIFTHQ

© 2026 RIFT RESEARCH, INC.

Rift/// @RIFTHQ