Key Insights
- Bridge exploits have caused multibillion-dollar losses across major crypto networks.
- Validator failures and forged proofs can release collateral without chain failure.
- New bridge models reduce some risks but still expose liquidity and solver weaknesses.
Cross-chain bridges promise smooth travel between blockchains, yet their security record often turns that journey into an expensive detour. These systems lock assets on one chain and release matching tokens elsewhere. When validators, relayers, proofs, upgrade keys, or monitors fail, attackers can mint unbacked assets or unlock collateral. The connected blockchains may keep working while the bridge accepts false information, making cross-chain infrastructure a persistent security weak point.
Bridge Exploits Create Multibillion-Dollar Losses
Chainlink, citing DefiLlama, places total bridge hack losses above $2.8 billion. Its review says bridges account for nearly 40% of all value-hacked across Web3. The figure shows how a narrow part of crypto infrastructure has absorbed a large share of industry losses.
An academic dataset tracked 49 bridge attacks from June 2021 through September 2024. Researchers estimated almost $4.3 billion in losses across those incidents. Classification methods differ, especially when studies count messaging layers, recovered assets, or related protocol failures.
Chainalysis said that around 13 bridge attacks had already taken about $2 billion by August 2022, and by then bridges made up roughly 69% of every crypto wallet or so that was stolen in that year. This concentration seemed to come from two angles, the sheer amount of value parked in those bridges and also the power that their verification setups got to enforce.
Why can one bridge failure cause severe damage while the connected blockchains continue operating normally? Bridges rely on external trust systems that interpret events across separate networks. A false message can therefore release real collateral or create spendable tokens without breaking either blockchain.
Ronin, Wormhole, and Nomad Reveal Core Weaknesses
Ronin showed how validator concentration can create one point of failure. In March 2022, the North Korean-linked Lazarus Group obtained 5 of the bridge’s 9 validator keys. That majority approved withdrawals of 173,600 ETH and 25.5 million USDC, worth more than $600 million then. The team detected the breach 6 days later.
Ethereum’s consensus continued working, but Ronin’s smaller validator committee approved the transfers. Wormhole exposed another weakness in February 2022 when an attacker fooled its Solana contract. The attacker minted 120,000 uncollateralized wrapped ETH and redeemed 93,750 tokens for native ETH on Ethereum.
The attacker also exchanged part of the remaining tokens on Solana. About $326 million faced exposure because Wormhole accepted forged authorization. The incident showed that wrapped assets depend on accurate signature checks and reliable proof systems linking tokens to locked reserves.
Nomad suffered a different failure in August 2022. A routine upgrade set a trusted root to zero, allowing invalid messages to pass. Copycat attackers repeated the original transaction with new receiving addresses and drained about $190 million. Two months later, attackers withdrew 2 million BNB from BSC Token Hub, worth nearly $570 million before network intervention limited withdrawals.
Key and Proof Failures Continue Into 2026
Private-key concentration remained dangerous after 2022. The FBI linked the $100 million Harmony Horizon Bridge theft to Lazarus Group. Multichain then recorded more than $125 million in unauthorized withdrawals during July 2023 before it stopped operating. Chainalysis reported that infrastructure controlled through its chief executive weakened the intended distribution of its multiparty-computation keys.

Orbit Bridge lost about $81.7 million around December 31, 2023. Security reviews indicated that attackers compromised 7 of its 10 multisignature keys. The “multisig” structure failed to provide broad protection because signers, servers, or recovery systems shared common control points.
The pattern remained visible in 2026. On April 13, Hyperbridge accepted a Merkle Mountain Range proof containing an out-of-bounds leaf. Its verifier checked a legitimate leaf, skipped the forged one, and returned success. Hyperbridge reported realized losses above $2 million and patched out-of-bounds, duplicate, and unsorted leaf handling.
Syscoin had another incident on June 7, 2026, with the UTXO-to-NEVM bridge reportedly releasing 5 billion SYS without authorization. From what was said, Syscoin Core and the NEVM relay parsed the transaction data in different ways, like kinda not in sync. After that happened, the tokens came back, and then they went into a burn process, and Syscoin itself kept the bridge paused for review, so yes, nothing more moved for a bit.
More recent intent-based bridges, in theory, need less dependence on pooled lock and mint vaults. But honestly, they swap one headache for another, because solver risks and liquidity issues can show up too. There was a 2026 study that looked at 3.5 million intents moving $9.24 billion across Mayan Swift, Across, and deBridge during the stretch from June through November 2025. Researchers identified 210 historically profitable liquidity-exhaustion opportunities against deBridge, with 80.5% profitable under tested conditions. Across resisted those tests because it had deeper liquidity and lower solver margins.
Security results have improved across the sector. Immunefi found bridge incidents fell from 73% of DeFi losses in 2022 to 3% in 2025. Median DeFi losses per incident also dropped from $6 million to $1.5 million. Current defenses include independent validators, hardware-secured keys, audited proof checks, transaction limits, delayed upgrades, live monitoring, and automatic circuit breakers.
Conclusion: The Final Take
Cross-chain bridges remain crypto’s weakest link because they sit between networks that were never built to trust one another. Every transfer depends on code, validators, keys, and monitoring systems working together without error. When one part fails, attackers can release locked assets or create tokens that lack real backing. Security has improved, but repeated breaches show that complexity and concentrated control still leave bridges exposed. Stronger verification and faster safeguards remain essential today for users, protocols, and wider crypto markets.

