{"id":746,"date":"2022-10-25T16:08:42","date_gmt":"2022-10-25T16:08:42","guid":{"rendered":"https:\/\/mapleblock.capital\/blog\/?p=746"},"modified":"2022-12-05T11:32:44","modified_gmt":"2022-12-05T11:32:44","slug":"september-2022-bridge-attacks","status":"publish","type":"post","link":"https:\/\/mapleblock.capital\/blog\/september-2022-bridge-attacks\/","title":{"rendered":"September 2022 &#8211; Bridge Attacks"},"content":{"rendered":"<div id=\"bsf_rt_marker\"><\/div>\n<p>From the conception of Bitcoin in 2009 to the multi-chain environment we observe today, the crypto space has come a long way, and as the industry developed, so did the spectrum of means to exploit it. Every so often, the industry has suffered from major attacks draining the ecosystem of millions of dollars, and in recent times, the primary victims of these hacks have been blockchain bridges.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>What are Blockchain Bridges, and why are they important?<\/strong><\/h1>\n\n\n\n<p>The key to enabling interoperability, bridge protocols facilitate the transfer of assets and information across multiple blockchain networks. Blockchains are naturally isolated networks with unique native coins, governance, and consensus mechanisms making cross-chain communication difficult. This is where bridges come in to induce compatibility. Several established networks in the space have distinct features and variable degrees of security, decentralization, transaction speed, and fees. Users predominantly working with one chain may want to move their assets to another desirable network per their requirements. Bridge protocols make this happen.&nbsp;&nbsp;<\/p>\n\n\n\n<p>For example, Bob has some $ETH on the Ethereum mainnet and wants to transfer it to his friend but is weary of the network&#8217;s high transaction costs. He notices that the L2 solution Polygon offers much better transaction throughput at a minimal cost. Through a bridge protocol, Bod can securely move his $ETH on the mainnet to $wETH or Wrapped $ETH on Polygon. A wrapped token is essentially a cryptocurrency pegged to a native coin that can be used on an external network.&nbsp;<\/p>\n\n\n\n<p>Bridge-based interoperability will augment the transition to Web3, empowering the ecosystem in various ways:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Further decentralization of the ecosystem&nbsp;<\/strong><\/h4>\n\n\n\n<p>While complete decentralization within individual blockchain networks is a primary concern for several blockchain projects, the capacity to establish network interoperability across various blockchains represents an even more advanced realization of the promise of blockchain technology to decentralize systems and economies where thousands of application-specific Layer 1 solutions are interconnected through a decentralized network.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Scalability and cheaper transactions<\/strong><\/h4>\n\n\n\n<p>Scalability is another significant issue that blockchain bridges may aid in resolving. Different networks will need to serve more significant transaction volumes and offer faster processing as blockchain gains prominence. Bridges may be utilized to provide scalability solutions where the transactional demand is dispersed throughout chain connections thanks to their capacity to enable cross-chain transfers. Additionally, users may move their assets from a network like&nbsp;Ethereum to a platform with minimal fees through bridges.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Increasing cryptocurrency payments and acceptance<\/strong><\/h4>\n\n\n\n<p>Interoperability issues significantly hampered the adoption of cryptocurrencies as a means of payment. Several establishments only took Bitcoin as payment in the form of&nbsp;cryptocurrencies, but&nbsp;the blockchain bridge enables immediate payments at the point of purchase.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Specialized Web3 services<\/strong><\/h4>\n\n\n\n<p>&nbsp;Blockchain protocols&#8217; flexibility to combine and match different pieces of fragmented infrastructure is the key to creating wholly new Web3 instruments and platforms. Many experts contend that interoperable smart contracts could revolutionize sectors like healthcare, law, or real estate, for example, by making it possible for crucial business data to be transferred between private networks and public networks in a customizable and malleable fashion. Interoperability across blockchains may potentially allow for multi-token transactions and multi-token wallet systems, which would considerably simplify the cryptocurrency user experience.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>Types of bridges<\/strong><\/h1>\n\n\n\n<p>Bridges can be classified based on various criteria:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Classification based on function<\/strong><\/h4>\n\n\n\n<p><strong>Chain-To-Chain Bridges: <\/strong>These bridges are primarily made to facilitate the transfer of assets between two specific blockchains and&nbsp;often employ the lock and mint system. Examples: Polygon&#8217;s PoS Bridge and Binance bridge between BSC and ETH.<\/p>\n\n\n\n<p><strong>Multi-Chain Bridges: <\/strong>These bridges are capable of moving assets across different blockchains. They are designed to be deployed to any type of L1 or L2 blockchain solution. Connext and cBridge are a few examples.<\/p>\n\n\n\n<p><strong>Data-Specific Bridges: <\/strong>These are interoperability protocols that exclusively transmit arbitrary data between various blockchains. These protocols often serve as the foundation for decentralized applications (dApps) and enable cross-chain composability. Examples include IBC,&nbsp;Data Movr, and Celer Inter-Chain&nbsp;Message Framework.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Classification based on chains bridged<\/strong><\/h4>\n\n\n\n<p><strong>L1 &lt;&gt; L1 Bridges:<\/strong> These bridges connect different Layer 1 solutions. For example, the Binance bridge and Avalanche bridge would be popular examples.<\/p>\n\n\n\n<p><strong>L1 &lt;&gt; L2 Bridges:<\/strong> Layer 1 solutions are connected to different Layer 2 solutions built upon them. For example, bridges that connect Ethereum Mainnet to Arbitrum or Optimism.<\/p>\n\n\n\n<p><strong>L2&lt;&gt;L2 Bridges:<\/strong> The youngest variant in the cross-chain infrastructure domain, these bridges connect different Layer 2 solutions. Example: Orbiter<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Classification based on architecture<\/strong><\/h4>\n\n\n\n<p><strong>Trusted Bridges:<\/strong> These bridges rely on a centralized system or entity to function. They have trust presumptions on the handling of money and the Bridge&#8217;s security. Most users rely on the operator of the Bridge&#8217;s reputation. These bridges demand that users cede ownership of their crypto holdings.<\/p>\n\n\n\n<p><strong>Trustless Bridges: <\/strong>Algorithms and smart contracts are used to operate trustless bridges. They are trustless, meaning that the Bridge&#8217;s security and that of the underlying blockchain are identical. Trustless bridges provide customers the ability to maintain control over their money through smart contracts.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Classification based on asset transfer mechanisms<\/strong><\/h4>\n\n\n\n<p><strong>Pool\u2013Based Bridges: <\/strong>Under such a mechanism, the bridge operator maintains pools of respective native tokens on either side of the Bridge. For example, a user intending to transfer USDT tokens from Ethereum to Solana must first deposit assets to the bridge contract (pool) on the Ethereum side. The user will provide the Solana address, and the bridge operator deposits Solana native USDT from the Bridge pool on the Solana side into the specified address.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh5.googleusercontent.com\/V4uBXYdx7y4aFwhkwRTgsA7_DxzH-zGkSV9JFb1orpciPqbMEs0cU5Hkjw7MeDJMsM3tYTjhlQ2okVgmCWJ3nrruIsZXmHjhlrZmwNQwOTTgIzr23qMfPUx6JVj_0XaTlj-cm8GZ5hdS_T9Fcch590_nNxVjn1sWpB_6crgvaQ9ZftF8bgAKw1MSmQ\" alt=\"\" \/><\/figure>\n\n\n\n<p><strong>Lock &amp; Mint \/ Burn &amp; Redeem: <\/strong>The &#8220;locking&#8221; or &#8220;burning&#8221;&nbsp;followed by the minting or redeeming&nbsp;is another prevalent transfer mechanism.&nbsp;Employing the same example as before, the user again starts by depositing USDT in Ethereum to a bridge-owned contract address and entering the recipient address on Solana, completing the &#8220;locking&#8221; phase. Bridge then &#8220;mints&#8221; or issues its own or a &#8220;wrapped&#8221; version of the deposited asset on the Solana chain and deposits it in the recipient address. The value of these newly created tokens depends on the prospect of one day being able to exchange them for the underlying asset on the sender chain. The wrapped tokens are transmitted back to the sender chain and &#8220;burned&#8221; on the target chain when the user &#8220;redeems&#8221; the tokens on the origin chain.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh6.googleusercontent.com\/1zlr4i_i_Bpy05hT0-Vp8EXSF5KpA38GpREyAoUN7KI7bPT_xDCZJOMKZkOoXG0YDT7Q9sUk-Dgw5Zl7vTxBDdphbrjWb3pWmIjdMGU2_Y0IVTj2C8cQI46E-mx_W9WyfAnl-CkOTPpMsuDRd9Gnbp57KaXi1gBD2nbQHyBf8FRxSGIWBfuhCTGMGA\" alt=\"\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh6.googleusercontent.com\/7DhPKonGip24wIVrM2x3hftDPvyjF39k-DA2GdsI6IvpahirKGnANJAK6OFo3bRiQQq6-Bln1anyyRAPjcKEq9jpsD2MyW4Vy9FMxPKeBOd3iEwKVVLb_mGlcoWyQknBbgImfujy2ZBy4MYtG1HCBiuiqHqbuGh5fnj9NuzZt-PGjE0bUpDQGPo9DA\" alt=\"\" \/><\/figure>\n\n\n\n<p><strong>Atomic Swaps: <\/strong>Assets on the source chain are exchanged for assets on the destination chain via atomic swaps. In general, they lack the trustworthiness of lock &amp; mint or burn &amp; mint procedures since they operate through&nbsp;self-executing smart contracts for asset exchanges and do not need a third party.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>Why are bridges vulnerable?<\/strong><\/h1>\n\n\n\n<p>For two fundamental reasons, cross-chain bridges are inherently insecure.<\/p>\n\n\n\n<p>First off, bridges merely broaden the attack surface that would-be hackers might exploit by making the bitcoin ecosystem more complicated.<\/p>\n\n\n\n<p>Second, due to the lack of a larger development community, many are constructed fundamentally differently from the blockchains they connect. As a result, the code is not as thoroughly examined for potential problems.&nbsp;<\/p>\n\n\n\n<p>Many have described bridges as sitting ducks for hackers. Bridges feature smart contracts on both the blockchains involved in the exchange so that users may trade tokens. Since smart contracts are public, anybody, even malicious parties, may examine them for flaws. Additionally, they are created to be unchangeable and impossible to alter. An updated smart contract must be used to address the problem. It may take time and resources to address this flaw, leaving the Bridge open to future money theft. Additionally, vast quantities of various currencies are required for bridges to trade tokens quickly between blockchains. Because of their enormous reserves, bridges are a popular target for hackers, and the rise in the number of assaults we have observed on bridges is a definite sign that they regard this as a lucrative opportunity.<\/p>\n\n\n\n<p>Bridges also raise the total risk for the bitcoin ecosystem as a whole since they run the danger of transmitting vulnerability&nbsp;across the ecosystem.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Bridge Attacks<\/strong><\/h3>\n\n\n\n<p>Bridge protocols are absolutely essential to actualize the Web3 future, but it is currently the weakest link in the industry infrastructure. With more than <a href=\"https:\/\/blog.chainalysis.com\/reports\/cross-chain-bridge-hacks-2022\/\">$2 billion<\/a> worth of cryptocurrencies stolen across 13 hacks, bridge attacks are now responsible for 69% of stolen funds in 2022.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh4.googleusercontent.com\/xrFJgj1wDKHxjuYdgUTOn-x7PP8k5AaY_CFNLs5ZsbcbUTCPdDLmE3dUNiaXZ6KeEWo-v8cZBxXlUcG_BjfYt9NhEcg18SlaLDCZ8DYVNeHmIbvOUQPqDIOCZIElFs8jAEoUAcVZW8he_E0spOdlKSrYnAYQ0xs43aBfYOoiwVk4RyEZK6phhWcRbA\" alt=\"\" \/><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>ChainSwap&nbsp;<\/strong><\/h4>\n\n\n\n<p>Then among the leading protocols in the interoperability infrastructure subdomain and backed by prominent venture funds such as Alameda Research and OKEx, Chainswap is a cross-chain asset bridge. On 10th July 2022, the protocol suffered a major attack as hackers exploited the vulnerabilities in Chainswap smart contracts. Back then, Chainswap primarily supported projects to launch Ethereum tokens on Binance Smart Chain (BSC). Highjacking projects&#8217; contracts on BSC, the attackers minted tokens on the chain and proceeded to sell them on the network&#8217;s most popular DEX PancakeSwap for <a href=\"https:\/\/medium.com\/wilder-world\/important-update-chainswap-hack-cf2153480887\">$wBNB<\/a>, <a href=\"https:\/\/nordfinance.medium.com\/chainswap-hack-transparency-update-2-ef43cff3e511\">$BUSD<\/a>, and other coins. The attackers also stole assets from Ethereum mainnet, which were staked in Chainswap&#8217;s contracts to sell them for <a href=\"https:\/\/medium.com\/wilder-world\/important-update-chainswap-hack-cf2153480887\">$DAI<\/a>.&nbsp;<\/p>\n\n\n\n<p>Around 20 projects, including Wilder Worlds, Antimatter, Option Room, Umbrella Network, Blank, Nord Finance, Razor Network, Peri, Unido, Oro, Vortex, Corra, ROCKS, Dafi, and Unifarm lost assets worth over <a href=\"https:\/\/finance.yahoo.com\/news\/chainswap-hackers-steal-8m-crash-121056965.html\">$8 million<\/a>. Over 14 tokens plunged 99% in the aftermath. The sale of vast amounts of minted tokens drained liquidity pools for many projects, further afflicting them. Moreover, this incident came after an earlier attack conducted on 2nd July 2021, in which the protocol lost around $800K.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Multichain&nbsp;<\/strong><\/h4>\n\n\n\n<p>Multichain, formerly known as Anyswap, is one of the most notable names in the cross-chain space, with a TVL of over <a href=\"https:\/\/defillama.com\/protocol\/multichain\">$1.7 billion<\/a>. On 17th January 2022, the Multi-chain team declared that security firm Debaub discovered a critical vulnerability in the network and immediately asked users to revoke permissions for $wETH, $PERI, $OMT, $wBNB, $MATIC, and $AVAX on the protocol&#8217;s bridging router since they were on the verge of drained by hackers, but unfortunately, the exploit was already underway.<\/p>\n\n\n\n<p>The attack resulted from a single function in the protocol&#8217;s contract named <em>anySwapOutUnderlyingWithPermit<\/em>. Multi-chain router allows users to swap between any two chains freely through an internal mechanism that wraps the actual token with its &#8220;anyToken&#8221;. For example, to conduct a transfer of $ETH from Ethereum mainnet to BSC, the protocol first wraps $ETH to create $anyETH. $ETH will serve as the underlying asset for the wrapped token, which Multichain also uses for internal accounting. During the transfer, wrapped tokens will be added to the Multi-chain anyETH BSC contract and burned on the anyETH Ethereum contract. The compromised function was created to facilitate this mechanism. Under a standard transaction, the function would have taken a wrapped anyToken address as input and unwrapped it to receive the address for the underlying asset, but in a particular exploit, when the contract deployed by the attacker was unwrapped, an address to a $wETH contract was obtained instead. Thus user&#8217;s $wETH authorized to Multichain&#8217;s contract were directly transferred to the attacker&#8217;s malicious contract token address. Furthermore, it was revealed that the function was never used before the attack and could have been deleted long before.<\/p>\n\n\n\n<p>Security firm PeckShield reported that more than <a href=\"https:\/\/twitter.com\/PeckShieldAlert\/status\/1483363515411099651?s=20\">450 $wETH<\/a>, then worth around $1.3 million, were affected. In total, hackers made away with <a href=\"https:\/\/twitter.com\/TalBeerySec\/status\/1483898136678617089\">$3 million<\/a> as <a href=\"https:\/\/twitter.com\/TalBeerySec\/status\/1483550455536005135\">Multichain<\/a> and <a href=\"https:\/\/twitter.com\/TalBeerySec\/status\/1483903235144441862\">some individual victims<\/a> began offering bounties to the attackers to recover whatever they could.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Qubit<\/strong><\/h4>\n\n\n\n<p>Qubit is a DeFi platform that primarily provides money market services to connect lenders and borrowers efficiently, along with peripheral bridging services. In another attack on an Ethereum and BSC network bridge,&nbsp; an attacker targeted the platform&#8217;s X-bridge protocol on 27th January 2022 to drain the Bridge of crypto assets valued at over <a href=\"https:\/\/cointelegraph.com\/news\/qubit-finance-suffers-80-million-loss-following-hack\">$80 million<\/a> around the incident.&nbsp;<\/p>\n\n\n\n<p>The attacker exploited the <em>deposit<\/em> function in Qubit&#8217;s bridge contract to dupe the protocol into thinking that $ETH had been deposited into the contract. Qubit offers a feature called X-collateral that enables users to collateralize their assets on other chains without moving assets. For example, users could deposit 1 $ETH in Qubit&#8217;s contract through the <em>deposit<\/em> function on the Ethereum mainnet to get 1 $xETH which will be minted on BSC. The newly minted token could now interact with the BSC ecosystem or could be used to borrow other tokens. The attacker called the <em>deposit<\/em> function with meticulously constructed input data to exploit particular vulnerabilities within the function code. The <em>deposit<\/em> function logic further invokes the <em>QBridgeHandler <\/em>contract, which conducts the data verification. The hacker provided a null address which is considered a whitelisted and an externally owned address (EOA), along with a sufficiently large ETH amount as inputs to successfully <a href=\"https:\/\/certik.medium.com\/qubit-bridge-collapse-exploited-to-the-tune-of-80-million-a7ab9068e1a0\">circumvent three statements within the <em>QBridgeHandler<\/em> contract meant to ensure the correctness of the inputs<\/a>. One of the root causes of the exploit was the fact that a vital function within the <em>deposit<\/em> code, <em>safeTransferFrom<\/em>, failed to revert when a null address was provided.&nbsp;<\/p>\n\n\n\n<p>This enabled the hacker to mint 77,162 $xETH, then worth over $185 million, without actually depositing any $ETH. These tokens were used to borrow 15,688 $wETH ($37.6 million), 767 $BTC-B ($28.5 million), approximately $9.5 million in various stablecoins, and roughly $5 million in $CAKE, $BUNNY, and $MDX before swapping everything for <a href=\"https:\/\/cointelegraph.com\/news\/qubit-finance-suffers-80-million-loss-following-hack\">206,809 BNB coins<\/a>. All valuations mentioned here were recorded as of the date the attack occurred.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Wormhole<\/strong><\/h4>\n\n\n\n<p>Wormhole is among the most significant communication protocols connecting Solana to the rest of the ecosystem, but unfortunately, that is not how many remember its name. In one of the largest hacks the industry has ever experienced, on 2nd February 2022, exploiting Portal, the token Bridge built on the Wormhole protocol, the attacker made away with assets valued at around <a href=\"https:\/\/www.theverge.com\/2022\/2\/3\/22916111\/wormhole-hack-github-error-325-million-theft-ethereum-solana\">$325 million<\/a> at the time of the incident.&nbsp;<\/p>\n\n\n\n<p>Before the hack, a typical transfer between Ethereum and Solana through the Wormhole bridge went through the following process:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>First, the <em>completeTransfer <\/em>function is called on the Ethereum Wormhole bridge contract.&nbsp;<\/li>\n\n\n\n<li>Then, the <a href=\"https:\/\/github.com\/wormhole-foundation\/wormhole\/blob\/9a4af890e3e2d4729fe70e43aaced39ba8b33e35\/solana\/bridge\/program\/src\/instructions.rs#L162\"><em>post_vaa<\/em><\/a> function is called on the Solana side. <em>post_vaa <\/em>further calls the <em>verify_signatures<\/em> function.<\/li>\n\n\n\n<li>The <a href=\"https:\/\/github.com\/wormhole-foundation\/wormhole\/blob\/ca509f2d73c0780e8516ffdfcaf90b38ab6db203\/solana\/bridge\/program\/src\/api\/verify_signature.rs#L68\"><em>verify_signatures<\/em><\/a><em> <\/em>function is called to obtain a set of signatures from the 19 <a href=\"https:\/\/wormhole.com\/network\/\">&#8220;Guardians&#8221;<\/a> that sign off on all the transfers between Solana and other networks. But, this function delegates the actual validation to a Solana built-in system cryptographic utility program called the <a href=\"https:\/\/github.com\/solana-labs\/solana\/blob\/7ba57e7a7c87fca96917a773ed944270178368c9\/sdk\/program\/src\/secp256k1_program.rs\"><em>secp256k1_program<\/em><\/a>.<\/li>\n\n\n\n<li>The <em>secp256k1_program<\/em> further relies on a standard Solana function called <a href=\"https:\/\/github.com\/solana-labs\/solana\/blob\/7ba57e7a7c87fca96917a773ed944270178368c9\/sdk\/program\/src\/sysvar\/instructions.rs#L180-L188\"><em>load_instruction_at<\/em><\/a><em> <\/em>present within the <a href=\"https:\/\/github.com\/solana-labs\/solana\/blob\/7ba57e7a7c87fca96917a773ed944270178368c9\/sdk\/program\/src\/sysvar\/instructions.rs\"><em>sysvar::instructions<\/em><\/a>, a system account. The function takes in a system program address as an input.<\/li>\n<\/ul>\n\n\n\n<p>A slight digression. An account here can be considered a structure comprising certain variables used to store data and functions to process them. The Solana architecture is composed of such system accounts. The <em>sysvar::instructions<\/em> accounts specifically contain serialized transaction instructions. &#8220;Programs&#8221; or &#8220;Accounts&#8221; in Solana are essentially equivalent to smart contracts in Ethereum.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>After the signatures are verified, the <em>post_vaa<\/em> function checks whether there are enough signatures to reach the consensus to post a Validator Action Approval (VAA), and only then <em>signature_set <\/em>is created and sent to the <em>complete_wrapped<\/em> function.<\/li>\n\n\n\n<li>The transfer is finally authorized by the <em>complete_wrapped<\/em> function to mint $whETH (Wormhole $ETH) on Solana.<\/li>\n<\/ul>\n\n\n\n<p>Trouble began when Solana depreciated the <em>load_instruction_at <\/em>and replaced it with <em>load_transaction_at_checked<\/em> since the old function did not verify whether the input was received from a trusted system account. Before the Wormhole could deploy the update, the vulnerability was exploited. The attacker created a <a href=\"https:\/\/solscan.io\/account\/2tHS1cXX2h1KBEaadprqELJ6sV9wLoaSdX68FqsrrZRd\">program<\/a> and conducted a <a href=\"https:\/\/solscan.io\/tx\/4pR7c2kBt4u2queevbLmQEe5yQ5UU5HtDHQbC32x2aRsaPhTXqrRr29CoQdXbJ8WEvV6ynZHtUcHcvmoWNxAfAzv\">valid transaction<\/a> through it. The attacker-controlled program&#8217;s address was then given as an input to the <em>load_instruction_at <\/em>function and, using the VAA verification from the previous valid transaction; the attacker was able to mint <a href=\"https:\/\/solscan.io\/tx\/2zCz2GgSoSS68eNJENWrYB48dMM1zmH8SZkgYneVDv2G4gRsVfwu5rNXtK5BKFxn7fSqX9BvrBc1rdPAeBEcD6Es\">120,000 $wETH<\/a> on Solana without any reciprocative deposit on the Ethereum side. <a href=\"https:\/\/rekt.news\/wormhole-rekt\/\">93,750 $ETH<\/a> was bridged back to Ethereum through three transactions, while the remaining&nbsp; $whETH were liquidated on Solana into $USDC and $SOL.<\/p>\n\n\n\n<p>In the aftermath of the attacker, <a href=\"https:\/\/www.forbes.com\/sites\/billybambrough\/2022\/02\/03\/crypto-price-alert-ethereum-rival-solana-suddenly-in-free-fall-after-huge-325-million-hack\/?sh=548910e14bb5\">$SOL fell over 10%<\/a> as the presence of a massive amount of unbacked $whETH was distressing for several Solana-based platforms. The parent of Wormhole, Jump Crypto, a subsidiary of the HFT firm Jump Trading, immediately stabilized the situation by <a href=\"https:\/\/www.reuters.com\/technology\/crypto-network-wormhole-hit-with-possible-320-mln-hack-2022-02-03\/\">restoring the entire stolen amount<\/a>. The Wormhole team offered a bug bounty of <a href=\"https:\/\/etherscan.io\/tx\/0x2d8b7901bff18ae6abe1a50aebe44b70559f39ff357b21340843d368b9486859\">$10 million<\/a> to the attacker, the largest offer industry has ever seen.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Meter<\/strong><\/h4>\n\n\n\n<p>Just a few days after the massive Wormhole hack, 2022 witnessed its 4<sup>th<\/sup> major bridge attack, with the DeFi infrastructure platform Meter being the victim. Meter functions as a decentralized EVM-compatible side chain for Ethereum and other public chains and also provides interoperability solutions through Meter Passport, a multi-chain router protocol. Meter Passport is a fork of ChainSafe&#8217;s Chainbridge, but it introduced an additional function that served as the root cause of the exploit.&nbsp;<\/p>\n\n\n\n<p>In an attack quite similar to Qubit&#8217;s, hackers exploited the <em>deposit <\/em>function taking advantage of a wrong trust assumption. There are two <em>deposit<\/em> functions to be mindful of, one in the bridge contract and the other in the handler contract.<\/p>\n\n\n\n<p>Consider the ideal flow for a transfer through the ChainBridge:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>The user invokes the <em>deposit<\/em> function in the bridge contract and states the specific token and the amount.<\/li>\n\n\n\n<li>Bridge further delegates the responsibility of conducting the transfer to the handler contract&#8217;s <em>deposit<\/em> function, asking it to lock or burn the specified amount of tokens depending on the mechanism.<\/li>\n\n\n\n<li>Handler contract calls <em>transferFrom<\/em> function on the token contract to complete the transfer.<\/li>\n<\/ol>\n\n\n\n<p>To facilitate the transfer of native tokens ($ETH on Ethereum or $BNB on BSC), Meter used ChainSafe&#8217;s modular bridging infrastructure to introduce a new function <em>depositEth <\/em>in the bridge contract and modified the handler contract. Under the altered flow<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>The user invokes the <em>depositETH<\/em> function in the bridge contract and specifies the native token and the amount to be transferred.<\/li>\n\n\n\n<li>The bridge contract wraps the native token (Ex. $ETH wrapped to create $wETH) and also asserts the value of the amount stated by the user before <strong>immediately transferring the assets to the handler contract.<\/strong><\/li>\n\n\n\n<li>Under normal circumstances, assets would have been locked or burned, but the modified handler contract <em>deposit<\/em> function has a special clause.<strong> If the assets being bridged are wrapped tokens, it assumes that the Bridge has already completed the transfer to the handler contract and does not charge the user.<\/strong> This assumption holds true within this process.<\/li>\n<\/ol>\n\n\n\n<p>Attackers exploited the Bridge through the original <em>deposit<\/em> function in the bridge contract and the modified function in the handler contract.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>The attacker invoked the <em>deposit<\/em> function in the bridge contract specifying wrapped tokens as the asset to be bridged along with an arbitrary amount. The original <em>deposit<\/em> function does not verify the value of the amount stated like <em>depositETH<\/em> did.<\/li>\n\n\n\n<li>The bridge contract calls the handler contract asking it to lock or burn the assets.<\/li>\n\n\n\n<li>Since the assets being bridged were wrapped tokens, the handler contract incorrectly assumed the Bridge had already completed the transfer.<\/li>\n<\/ol>\n\n\n\n<p>The attacker illegally minted over <a href=\"https:\/\/cointelegraph.com\/news\/latest-defi-bridge-exploit-results-in-4-4m-losses-for-meter\">$4.4 million<\/a> in $BNB and $wETH, severely depleting the Bridge&#8217;s reserves, and moved the loot to Tornado Cash across multiple transactions. The exploit primarily affected the Moonriver ecosystem, a parachain based on Polkadot&#8217;s Kusama network, which was bridged to Ethereum and BSC through Meter. Following the incident, the attacker sold an extensive amount of $BNB coins on SushiSwap, a prominent DEX, causing the BNB price to <a href=\"https:\/\/cointelegraph.com\/news\/latest-defi-bridge-exploit-results-in-4-4m-losses-for-meter\">crash 77% on Moonriver<\/a>. <a href=\"https:\/\/twitter.com\/HundredFinance\/status\/1490394875459682309\">Hundred Finance<\/a>, a lending platform, suffered significant collateral damage in the process as several opportunists, taking advantage of the local $BNB price discrepancy, took on undercollateralized loans. Surprisingly two of the loans were repaid, but Hundred Finance still took a <a href=\"https:\/\/cointelegraph.com\/news\/latest-defi-bridge-exploit-results-in-4-4m-losses-for-meter\">$3.3 million<\/a> hit.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Ronin<\/strong><\/h4>\n\n\n\n<p>The largest crypto hack ever, with assets then valued at over <a href=\"https:\/\/cointelegraph.com\/news\/the-aftermath-of-axie-infinity-s-650m-ronin-bridge-hack\">$600 million<\/a> stolen, Ronin reaffirmed Crypto&#8217;s &#8220;bridge&#8221; problem to an unignorable degree.&nbsp;<\/p>\n\n\n\n<p>Sky Mavis, the developer behind the GameFi sensation Axie Infinity, launched the Ronin network to expedite transaction throughput needed to accommodate the P2E game&#8217;s massive user base. The network follows a Proof of Authority (PoA) consensus algorithm whether a limited number of designated validators stake their identity or reputation to approve transactions. PoA models generally deliver superior TPS statistics, albeit at the cost of decentralization and trustlessness. The Ronin network relied on nine validators where a consensus of 5 validators is required to approve a transaction.<\/p>\n\n\n\n<p>On the day of the exploit, 23rd March 2022, private keys for four validators that were maintained by Sky Mavis were compromised, and the attackers obtained the signature for the fifth validator belonging to Axie DAO through a backdoor in Sky Mavis&#8217;s systems. In November 2021, Sky Mavis and Axie DAO jointly established a gas-free node to trim costs for users and mitigate the heavy transaction volume the network was processing. <a href=\"https:\/\/blog.merklescience.com\/hacktrack\/hack-track-analysis-of-ronin-network-exploit-merkle-science\">The agreement also allowed both parties to sign off transactions on each other&#8217;s behalf.<\/a> This measure was only taken to alleviate the overburdened state of the network around the time and was discontinued after a month, but the access was never revoked. This enabled the attackers to reach the required number of validators to fraudulently approve two withdrawals from the bridge contract, one for <a href=\"https:\/\/etherscan.io\/tx\/0xc28fad5e8d5e0ce6a2eaf67b6687be5d58113e16be590824d6cfa1a94467d0b7\">173,600 $ETH<\/a> and another for <a href=\"https:\/\/etherscan.io\/tx\/0xed2c72ef1a552ddaec6dd1f5cddf0b59a8f37f82bdda5257d9c7c37db7bb9b08\">25.5M $USDC<\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh5.googleusercontent.com\/0XEFs-eP_S56ev5RJuSNyVLvH6Gw_xg-tJbXPdQhrDhVqja5-Em_XH5XwU9MUMZgDROYKPmy8SZiSXd-HW6hDRsQIMUUEbvQkQLRe5p42ZPQh4ShjC9ZQfsP3ppeTrZTrhIHkw66_3AJONXJLkVi4iRsFuXxICM-c9hWBigmGqckCwz3B2JZp9SGbQ\" alt=\"\" \/><\/figure>\n\n\n\n<p>The hack went unnoticed for <a href=\"https:\/\/twitter.com\/Ronin_Network\/status\/1508828719711879168\">six days<\/a> and was discovered only when a user couldn&#8217;t withdraw 5000 $ETH from the Bridge. <a href=\"https:\/\/twitter.com\/ericgoldenx\/status\/1508844665881116674\">The hackers even shorted the $AXS (Axie) token but the trades liquidated before the news broke out.<\/a> As reports surfaced, Sky Mavis immediately moved to replace all the existing validators and upped the consensus requirement to eight validators. The Bridge was shut down in the aftermath of the attack and wasn&#8217;t reopened for three months. Binance blocked addresses that potentially belonged to the hackers and suspended all deposits and withdrawals on the network to support the investigation. The Ronin team conducted extensive forensic analysis and audits with Chainalysis, Certik, and Verichains. At the same time, several security firms tracked the attackers&#8217; complex laundering operations, which involved multiple CEXs, including Houbi, FTX, and crypto.com. The stolen assets were also moved through Tornado Cash and Blender, mixing services used to mask the money trail by depositing assets in huge pools and withdrawing them back through a new address. As the community and concerned authorities dug into the largest crypto hack ever, several interesting details came to light. <a href=\"https:\/\/blog.merklescience.com\/hacktrack\/hack-track-analysis-of-ronin-network-exploit-merkle-science\">The U.S. Department of Treasury&#8217;s Office<\/a> tied the infamous North Korean cybercrime syndicate, the Lazarus Group, to the attack and added an <a href=\"https:\/\/home.treasury.gov\/policy-issues\/financial-sanctions\/recent-actions\/20220414\">Ethereum wallet address<\/a> to a sanctions list. The Block reported that the attackers got into Sky Mavis&#8217;s computers through <a href=\"https:\/\/www.theblock.co\/post\/156038\/how-a-fake-job-offer-took-down-the-worlds-most-popular-crypto-game\">a fake LinkedIn offer<\/a> to a senior engineer. Sky Mavis raised <a href=\"https:\/\/www.coindesk.com\/business\/2022\/04\/06\/sky-mavis-raises-150m-round-led-by-binance-to-reimburse-ronin-attack-victims\/\">$150 million<\/a> in a funding round from Binance, a16z, Dialectic, Paradigm, and Accel to reimburse the victims.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Harmony<\/strong><\/h4>\n\n\n\n<p>In the second major bridge attack involving the theft of private keys, hackers stole assets then worth over <a href=\"https:\/\/techcrunch.com\/2022\/06\/24\/harmony-blockchain-crypto-hack\/\">$100 million<\/a> across approximately <a href=\"https:\/\/www.coindesk.com\/tech\/2022\/07\/27\/harmony-proposes-issuing-one-tokens-to-reimburse-victims-of-100m-hack\/\">65,000<\/a> wallets from Harmony&#8217;s Horizon Bridge.<\/p>\n\n\n\n<p>Harmony protocol is a layer-1 blockchain launched in 2019 with sharding and a unique Effective Proof-of-Stake (EPoS) consensus mechanism. The network is connected to the Ethereum Mainnet and BSC through the Horizon Bridge, Harmony&#8217;s proprietary cross-chain solution. Horizon&#8217;s transaction approval mechanism is based on a <a href=\"https:\/\/etherscan.io\/address\/0x715CdDa5e9Ad30A0cEd14940F9997EE611496De6\">multi-signature (MultiSig)<\/a> wallet, which, as the name implies, requires multiple private keys to be accessed. The Bridge has five validators, and on 24<sup>th<\/sup> June 2022, the attackers hijacked the requisite number of addresses\/keys (<a href=\"https:\/\/etherscan.io\/address\/0xf845A7ee8477AD1FB4446651E548901a2635A915\">one<\/a> and <a href=\"https:\/\/etherscan.io\/address\/0x812d8622C6F3c45959439e7ede3C580dA06f8f25\">two<\/a>) to validate multiple transactions.&nbsp;<\/p>\n\n\n\n<p>Polygon&#8217;s Chief Information Security Officer, <a href=\"https:\/\/twitter.com\/Mudit__Gupta\/status\/1540225234153996288\">Mudit Gupta<\/a>, opined that the compromised keys were most likely associated with hot wallets (wallets that are always connected to the internet) and the attackers assaulted the servers these wallets were running on to access the keys kept in plaintext (basically unencrypted). Surprisingly, Harmony&#8217;s incident report maintains that the keys were protected by <a href=\"https:\/\/twitter.com\/stse\/status\/1540896633172271105\">a passphrase and a key management system<\/a> which ensured that no single machine had access to multiple plaintext keys. Harmony also asserted that only the Ethereum side of the Bridge was jeopardized and upped the consensus requirement to <a href=\"https:\/\/twitter.com\/stse\/status\/1540896636238385152\">4-5 from 2-5<\/a>. Assets in the form of $BUSB, $USDC, $ETH, and $wBTC tokens were stolen across nine transactions and were later swapped for $ETH. These swapped tokens were also laundered through Tornado Cash. Harmony announced a bounty of $1 million, which was later increased to $10 million but to no avail. To reimburse the victims, the network offered two options, both of which involved minting more native $ONE tokens over a three-year period, but the proposal received a significant amount of backlash from the community.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Nomad<\/strong><\/h4>\n\n\n\n<p>In the most recent major bridge attack on 8<sup>th<\/sup> August 2022, Nomad, a cross-chain messaging protocol that connects Ethereum, Avalanche, Evmos, and Moonbeam blockchains, was robbed of almost all of its assets, valued at around <a href=\"https:\/\/www.cnbc.com\/2022\/08\/02\/hackers-drain-nearly-200-million-from-crypto-startup-nomad.html\">$190 million<\/a> at the time of the attack. The attack came just a few days after the protocol raised $22 million in a <a href=\"https:\/\/twitter.com\/nomadxyz_\/status\/1552674247977287680\">seed round<\/a> from Coinbase Ventures, OpenSea, Polygon, and Crypto.com at a valuation of around $225 million.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh3.googleusercontent.com\/UUTk4TdOLN__qUfx-1lOZYsFT4rnPbgyyJqGt1rY7H9JbmNyRRBnA-UP2neZcSvSVtiQb4JtX1Mq3JAD51I7eZrY9bpROOwMCnm9rNqy-RuM4RmDbKRaM5qh5iPhOGEUQDvJlCPYLOvz70AIiOGOKwD-SzgSEj4xiLfAJKNMcgBonzLcfDcVBPkrnw\" alt=\"\" \/><\/figure>\n\n\n\n<p><em>Figure: An exploitative transaction<\/em><\/p>\n\n\n\n<p>The attack on Nomad was enabled by an update to the protocol, which induced a critical error in the <em>Replica<\/em> smart contract&#8217;s message validation mechanism. The bridge architecture follows a two-stage procedure before a message can be approved. The first stage would involve the validation of the input data before processing it in the second stage. Like several other protocols, Nomad commits messages through an internal data structure called Merkle tree. After a message&#8217;s data has been included under a tree and its inclusion is proven by a Merkle proof, the root of the tree is stored in a mapping function within the <em>Replica<\/em> contract. Thus, the mapping function essentially connects a message&#8217;s hash to the tree&#8217;s root. For an unproven message, the default root address is 0x00. When a message is submitted to the <em>process <\/em>function within the <em>Replica<\/em> contract, it validates whether it belongs to a trusted root. Nomad initialized the value of trusted roots to 0x00 in an update, which is considered a common practice, but in this case, the root address coincided with the default value for an unproven one. Thus, the <em>process <\/em>function ascertained all messages as proven. Transactions where attackers sent 0.01 $wBTC to the Bridge on the Moonbeam network to receive 100 $wBTC on Ethereum were observed. Once an attacker initially conducted the exploit, thousands of looters joined in since all they had to do was re-broadcasting the transaction after replacing the attacker&#8217;s address with their own. According to Elliptic, the most prolific hacker netted just below <a href=\"https:\/\/hub.elliptic.co\/analysis\/nomad-loses-156-million-in-seventh-major-crypto-bridge-exploit-of-2022\/\">$42 million<\/a> across 202 self-deployed contracts.<\/p>\n\n\n\n<p>In the aftermath of the attack, Nomad announced a public code review through an <a href=\"https:\/\/immunefi.com\/bounty\/nomad\/\">ImmuneFi<\/a> bounty program. The bridge protocol also offered a bounty of up to 10% to retrieve user funds with the promise of white hat status and no legal action. Nomad&#8217;s funds recovery address has received over <a href=\"https:\/\/cryptonews.com\/news\/over-usd-36m-returned-nomad-bridges-fund-recovery-address.htm#:~:text=Over%20USD%2036M%20Returned%20to%20Nomad%20Bridge's%20Fund%20Recovery%20Address,-Source%3A%20AdobeStock%20%2F%20evgenii&amp;text=Over%20USD%2036m%20has%20so,%22the%20first%20decentralized%20robbery.%22\">$36 million<\/a> from 40 addresses so far.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>Solutions<\/strong><\/h1>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Rigorous Code Audit&nbsp;<\/strong><\/h4>\n\n\n\n<p>Blockchains are frequently connected through the use of cross-chain bridges that employ smart contracts. As a result, smart contract audits are a crucial step in the bridge security procedure. A private&nbsp;smart contract security audit might have stopped many of the worst breaches of cross-chain bridges by finding and fixing flaws before code is published into the blockchain. An extensive bounty program could also be conducted before mainstream release.<\/p>\n\n\n\n<p>The code alone should not be the end of a bridge project&#8217;s security examination. Cross-chain bridges provide complicated ecosystems, and it is essential to consider how the contracts that have been placed on different platforms interact with one another. The expertise of all the impacted platforms, validation of the bridge project&#8217;s rationale, and evaluation of the risks the project confronts are necessary for an audit to be impactful. &#8216;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>P2P Bridges&nbsp;<\/strong><\/h4>\n\n\n\n<p>Inter-chain&nbsp;trading would be more secure with P2P-based bridges. They do not rely on sophisticated smart contracts or centralized liquidity pools since they employ atomic swaps and order book mechanisms&nbsp;instead. Cross-chain P2P&nbsp;swaps can be completely decentralized and trustless since peer-to-peer technology eliminates&nbsp;intermediaries. It is a more secure method of transacting in a cross-chain environment since just one transaction enters and exits concurrently for each exchange. Swaps are referred to be &#8220;atomic&#8221; because, with each order, the deal either closes and the funds are exchanged between the two users, or the transaction fails, and the source funds are returned to the two users. Contracts with hash-time locking enable this (HTLCs).&nbsp;<\/p>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>Conclusion<\/strong><\/h1>\n\n\n\n<p>Blockchain technology has the potential to improve a variety of information systems. But, the basis for its widespread adoption lies squarely with the evolution of cross-chain technology, as currently, there isn&#8217;t a perfect solution to the bridging problem, only trade-offs for specific use cases. The future of the crypto ecosystem will be determined by the continual improvement of the existing promising technologies within the domain and the stringent evaluation of existing sensitive infrastructure.<\/p>\n\n\n\n<p><strong>Author: <\/strong><a href=\"https:\/\/www.linkedin.com\/in\/madhav-bajaj\/\"><strong>Madhav Bajaj<\/strong><\/a><\/p>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>References<\/strong><\/h1>\n\n\n\n<p style=\"font-size:11px\"><a href=\"https:\/\/blog.li.fi\/what-are-blockchain-bridges-and-how-can-we-classify-them-560dc6ec05fa\">What Are Blockchain Bridges And How Can We Classify Them? | by Arjun Chand | LI.FI Blog<\/a><br><a href=\"https:\/\/medium.com\/amber-group\/bridges-designs-trade-offs-and-opportunities-2196b8754e70\">Bridges: Designs, Trade-offs, and Opportunities | by Amber Group | Amber Group | Medium<\/a><br><a href=\"https:\/\/protos.com\/explained-why-hackers-keep-exploiting-cross-blockchain-bridges\/\">Explained: Why hackers keep exploiting cross-blockchain bridges<\/a><\/p>\n\n\n\n<p style=\"font-size:11px\"><strong>Chainswap<\/strong><br><a href=\"https:\/\/cryptopotato.com\/chainswap-exploited-projects-using-the-bridge-protocol-crashed-99\/\">ChainSwap Exploited: Projects Using The Bridge Protocol Crashed 99%<\/a><br><a href=\"https:\/\/decrypt.co\/75698\/chainswap-exploit-leads-to-multi-million-loss-for-defi-tokens\">ChainSwap Exploit Leads to Multi-Million Loss For DeFi Tokens &#8211; Decrypt<\/a><br><a href=\"https:\/\/medium.com\/wilder-world\/important-update-chainswap-hack-cf2153480887\">Important Update: ChainSwap Hack. Firstly, we want to thank the entire\u2026 | by Wilder World | Wilder World | Medium<\/a><br><a href=\"https:\/\/finance.yahoo.com\/news\/chainswap-hackers-steal-8m-crash-121056965.html\">ChainSwap hackers steal $8m and crash token prices<\/a><br><a href=\"https:\/\/optionroom.medium.com\/optionroom-current-post-chainswap-hack-situation-3f5c86d7cd97\">OptionRoom current post ChainSwap hack situation | by OptionRoom | Medium<\/a><br><a href=\"https:\/\/nordfinance.medium.com\/chainswap-hack-transparency-update-2-ef43cff3e511\">ChainSwap Hack: Transparency Update #2 | by Nord Finance | Medium<\/a><br><a href=\"https:\/\/medium.com\/umbrella-network\/an-important-message-to-the-community-about-the-chainswap-hack-e2603de5f0e6\">An Important Message To The Community About The Chainswap Hack | by John Chen | Umbrella Network | Medium<\/a><br><br><b>Multi-chai<\/b>n<br><a href=\"https:\/\/cryptobriefing.com\/multichain-users-lose-1-4m-due-bridge-bug\/\">Multi-chain Users Lose $1.4M Due to Bridge Bug &#8211; Crypto Briefing<\/a><br><a href=\"https:\/\/www.coindesk.com\/business\/2022\/01\/20\/multichain-hack-worsens-as-loss-of-funds-reaches-3m-report\/\">Multichain Hack Worsens as Loss of Funds Reaches $3M: Report<\/a><br><a href=\"https:\/\/medium.com\/zengo\/without-permit-multichains-exploit-explained-8417e8c1639b\">Without Permit: Multichain&#8217;s exploit explained | by Tal Be&#8217;ery | ZenGo | Medium<\/a><br><a href=\"https:\/\/halborn.com\/explained-the-multichain-hack-january-2022\/\">Explained: The Multi-chain Hack (January 2022)<\/a><br><a href=\"https:\/\/cointelegraph.com\/news\/multichain-under-fire-from-users-as-hacking-losses-grow-to-3m\">Multi-chain under fire from users as hacking losses grow to $3M<\/a><br><a href=\"https:\/\/www.gate.io\/blog_detail\/503\/Multichain-Hack-Incidence\">Multichain Hack Incidence-Gate.io Blog | Get Better at Blockchain &amp; Cryptocurrency Blog<\/a><br><br><strong>Qubit<\/strong><br><a href=\"https:\/\/halborn.com\/explained-the-qubit-hack-january-2022\/\">Explained: The Qubit Hack (January 2022)<\/a><br><a href=\"https:\/\/rekt.news\/qubit-rekt\/\">Rekt &#8211; Qubit Finance &#8211; REKT<\/a><br><a href=\"https:\/\/certik.medium.com\/qubit-bridge-collapse-exploited-to-the-tune-of-80-million-a7ab9068e1a0\">Qubit Bridge Collapse Exploited to the Tune of $80 Million | by CertiK | Medium<\/a><br><a href=\"https:\/\/cointelegraph.com\/news\/qubit-finance-suffers-80-million-loss-following-hack\">Qubit Finance suffers $80 million loss following hack<\/a><br><a href=\"https:\/\/www.theverge.com\/2022\/1\/28\/22906366\/cryptocurrency-hackers-steal-qubit-binance-ethereum\">Hackers have stolen $80 million in cryptocurrency from the Qubit DeFi platform &#8211; The Verge<\/a><br><a href=\"https:\/\/losslessdefi.medium.com\/qubit-finance-hack-post-mortem-the-trail-the-hacker-left-behind-f8afa8a0d010\">Qubit Finance Hack Post-Mortem: The Trail the Hacker Left Behind | by Lossless | Medium<\/a><br><a href=\"https:\/\/blockworks.co\/defi-protocol-qubit-finance-loses-80m-in-hack\/\">DeFi Protocol Qubit Finance Loses $80M in Hack &#8211; Blockworks<\/a><br><br><strong>Wormhole<\/strong><br><a href=\"https:\/\/medium.com\/@alxlpsc\/lessons-from-the-wormhole-exploit-3834651c4204\">Lessons from the Wormhole Exploit | by Alex Lupascu | Medium<\/a><br><a href=\"https:\/\/research.kudelskisecurity.com\/2022\/02\/03\/quick-analysis-of-the-wormhole-attack\/\">Quick Analysis of the Wormhole attack \u2013 Kudelski Security Research<\/a><br><a href=\"https:\/\/rekt.news\/wormhole-rekt\/\">Rekt &#8211; Wormhole &#8211; REKT<\/a><br><a href=\"https:\/\/extropy-io.medium.com\/solanas-wormhole-hack-post-mortem-analysis-3b68b9e88e13#:~:text=The%20Wormhole%20bridge%20was%20hacked,(Wormhole%20ETH)%20on%20Solana.\">Solana&#8217;s Wormhole Hack Post-Mortem Analysis | by Extropy.IO | Medium<\/a><br><a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252513054\/Wormhole-offers-10M-to-Ethereum-thieves\">Wormhole offers $10M to Ethereum thieves<\/a><br><a href=\"https:\/\/www.theverge.com\/2022\/2\/3\/22916111\/wormhole-hack-github-error-325-million-theft-ethereum-solana\">Wormhole cryptocurrency platform hacked for $325 million after error on GitHub &#8211; The Verge<\/a><br><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/wormhole-restores-stolen-326-million-after-major-crypto-bailout\/\">Wormhole restores stolen $326 million after major crypto bailout<\/a><br><br><strong>Meter<\/strong><br><a href=\"https:\/\/blog.chainsafe.io\/breaking-down-the-meter-io-hack-a46a389e7ae4\">Breaking Down the Meter Hack | ChainSafe<\/a><br><a href=\"https:\/\/certik.medium.com\/4-3-million-lost-to-another-bridge-hack-db9b028a3c28\">$4.3 Million Lost to Another Bridge Hack | by CertiK | Medium<\/a><br><a href=\"https:\/\/rekt.news\/meter-rekt\/\">Rekt &#8211; Meter &#8211; REKT<\/a><br><a href=\"https:\/\/medium.com\/@Knownsec_Blockchain_Lab\/knownsec-blockchain-lab-meter-io-attack-analysis-38cc5207d4cf\">Knownsec Blockchain Lab | meter.io attack analysis | by Knownsec Blockchain Lab | Medium<\/a><br><a href=\"https:\/\/cointelegraph.com\/news\/latest-defi-bridge-exploit-results-in-4-4m-losses-for-meter\">Latest DeFi bridge exploit results in $4.4M losses for Meter<\/a><br><br><strong>Ronin<\/strong><br><a href=\"https:\/\/rekt.news\/ronin-rekt\/\">Rekt &#8211; Ronin Network &#8211; REKT<\/a><br><a href=\"https:\/\/blog.merklescience.com\/hacktrack\/hack-track-analysis-of-ronin-network-exploit-merkle-science\">Hack Track: Analysis of Ronin Network Exploit | Merkle Science<\/a><br><a href=\"https:\/\/halborn.com\/explained-the-ronin-hack-march-2022\/\">Explained: The Ronin Hack (March 2022)<\/a><br><a href=\"https:\/\/roninblockchain.substack.com\/p\/community-alert-ronin-validators?s=w\">Community Alert: Ronin Validators Compromised<\/a><br><a href=\"https:\/\/cryptopotato.com\/the-biggest-ever-crypto-hack-what-happened-in-the-ronin-bridge-attack\/\">The Biggest Ever Crypto Hack: What Happened in the Ronin Bridge Attack<\/a><br><a href=\"https:\/\/cointelegraph.com\/news\/the-aftermath-of-axie-infinity-s-650m-ronin-bridge-hack\">The aftermath of Axie Infinity&#8217;s $650M Ronin Bridge hack<\/a><br><a href=\"https:\/\/www.coindesk.com\/business\/2022\/06\/24\/axie-infinity-developer-sky-mavis-to-reimburse-victims-of-ronin-bridge-hack\/\">Axie Infinity Developer Sky Mavis to Reimburse Victims of Ronin Bridge Hack<\/a><br><a href=\"https:\/\/www.theverge.com\/2022\/7\/6\/23196713\/axie-infinity-ronin-blockchain-hack-phishing-linkedin-job-offer\">Axie Infinity Ronin blockchain reportedly hacked with fake job offer &#8211; The Verge<\/a><br><a href=\"https:\/\/www.theblock.co\/post\/156038\/how-a-fake-job-offer-took-down-the-worlds-most-popular-crypto-game\">How a fake job offer took down the world&#8217;s most popular crypto game<\/a><br><a href=\"https:\/\/www.outlookindia.com\/business\/ronin-hackers-moved-stolen-625-mln-cryptos-to-bitcoin-network-through-sanctioned-mixers-news-218140\">Ronin Hackers Moved Stolen $625-Mln Cryptos To Bitcoin Network Through Sanctioned Mixers<\/a><br><a href=\"https:\/\/slowmist.medium.com\/report-on-the-ronin-network-exploit-and-aml-analysis-of-stolen-funds-692b2a589a96\">Report on the Ronin Network Exploit and AML Analysis of Stolen Funds | by SlowMist | Aug, 2022 | Medium<\/a><br><br><strong>Harmony<\/strong><br><a href=\"https:\/\/rekt.news\/harmony-rekt\/\">Rekt &#8211; Harmony Bridge &#8211; REKT<\/a><br><a href=\"https:\/\/halborn.com\/explained-the-harmony-horizon-bridge-hack\/\">Explained: The Harmony Horizon Bridge Hack<\/a><br><a href=\"https:\/\/blog.merklescience.com\/hacktrack\/horizonbridge\">Hack Track: Analysis of the Analysis of Harmony&#8217;s Horizon Bridge Exploit | Hack Track | Merkle Science<\/a><br><a href=\"https:\/\/medium.com\/coinmonks\/100m-harmony-hack-explained-366a3216235c\">$100M Harmony Hack Explained. The Harmony Horizon Bridge project was\u2026 | by Andre Costa | Coinmonks | Medium<\/a><br><a href=\"https:\/\/cointelegraph.com\/news\/breaking-harmony-one-s-horizon-bridge-hacked-for-100m\">Breaking: Harmony&#8217;s Horizon Bridge hacked for $100M<\/a><br><a href=\"https:\/\/medium.com\/harmony-one\/harmonys-horizon-bridge-hack-1e8d283b6d66\">Harmony&#8217;s Horizon Bridge Hack. On Thursday, 23rd June, 2022, the Harmony\u2026 | by Matthew Barrett | Harmony | Medium<\/a><br><a href=\"https:\/\/www.coindesk.com\/tech\/2022\/07\/27\/harmony-proposes-issuing-one-tokens-to-reimburse-victims-of-100m-hack\/\">Harmony Proposes Issuing ONE Tokens to Reimburse Victims of $100M Hack<\/a><br><a href=\"https:\/\/talk.harmony.one\/t\/reimbursement-proposal-horizon-incident\/20665\">Reimbursement Proposal [Horizon Incident] &#8211; Community \/ Announcements &#8211; Harmony Community Forum<\/a><br><a href=\"https:\/\/cointelegraph.com\/news\/backlash-as-harmony-proposes-minting-4-97b-tokens-to-reimburse-victims\">Backlash as Harmony proposes minting 4.97B tokens to reimburse victims<\/a><br><br><strong>Nomad<\/strong><br><a href=\"https:\/\/twitter.com\/samczsun\/status\/1554252024723546112\">samczsun on Twitter<\/a><br><a href=\"https:\/\/zerion.io\/blog\/nomad-bridge-hack\/\">Nomad Bridge Hack: A Simple Explanation of $190 Million Attack<\/a><br><a href=\"https:\/\/medium.com\/nomad-xyz-blog\/nomad-bridge-hack-root-cause-analysis-875ad2e5aacd\">Nomad Bridge Hack: Root Cause Analysis | by Nomad | Nomad | Aug, 2022 | Medium<\/a><br><a href=\"https:\/\/halborn.com\/explained-the-nomad-hack-august-2022\/\">Explained: The Nomad Hack (August 2022)<\/a><br><a href=\"https:\/\/www.maplabs.io\/blog\/nomad-bridge-hack-explained\/\">Nomad Bridge Hack Explained &#8211; Map Protocol Blog<\/a><br><a href=\"https:\/\/techcrunch.com\/2022\/08\/02\/nomad-chaotic-exploit-crypto\/\">Hackers abuse &#8216;chaotic&#8217; Nomad exploit to drain almost $200M in crypto | TechCrunch<\/a><br><a href=\"https:\/\/www.coindesk.com\/business\/2022\/08\/03\/hackers-send-back-9m-to-nomad-bridge-after-190m-exploit\/\">Hackers Return $9M to Nomad Bridge After $190M Exploit<\/a><br><a href=\"https:\/\/hub.elliptic.co\/analysis\/nomad-loses-156-million-in-seventh-major-crypto-bridge-exploit-of-2022\/\">Nomad Loses $156 Million in Fourth Major Crypto Bridge Exploit of 2022 | Elliptic | Elliptic Connect<\/a><br><a href=\"https:\/\/www.cnbc.com\/2022\/08\/05\/crypto-startup-nomad-offers-10percent-bounty-after-190-million-hack.html\">Crypto startup Nomad offers 10% bounty after $190 million hack<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>From the conception of Bitcoin in 2009 to the multi-chain environment we observe today, the crypto space has come a long way, and as the industry developed, so did the spectrum of means to exploit it. Every so often, the industry has suffered from major attacks draining the ecosystem of millions of dollars, and in <a class=\"read-more\" href=\"https:\/\/mapleblock.capital\/blog\/september-2022-bridge-attacks\/\"> <\/a><\/p>\n","protected":false},"author":1,"featured_media":756,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"hide_page_title":"","_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","footnotes":""},"categories":[5],"tags":[],"class_list":["post-746","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"formatted_date":"October 25, 2022","_links":{"self":[{"href":"https:\/\/mapleblock.capital\/blog\/wp-json\/wp\/v2\/posts\/746","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mapleblock.capital\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mapleblock.capital\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mapleblock.capital\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mapleblock.capital\/blog\/wp-json\/wp\/v2\/comments?post=746"}],"version-history":[{"count":11,"href":"https:\/\/mapleblock.capital\/blog\/wp-json\/wp\/v2\/posts\/746\/revisions"}],"predecessor-version":[{"id":931,"href":"https:\/\/mapleblock.capital\/blog\/wp-json\/wp\/v2\/posts\/746\/revisions\/931"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mapleblock.capital\/blog\/wp-json\/wp\/v2\/media\/756"}],"wp:attachment":[{"href":"https:\/\/mapleblock.capital\/blog\/wp-json\/wp\/v2\/media?parent=746"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mapleblock.capital\/blog\/wp-json\/wp\/v2\/categories?post=746"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mapleblock.capital\/blog\/wp-json\/wp\/v2\/tags?post=746"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}