A cross-chain bridge takes an asset you hold on one blockchain and makes an equivalent available on another, usually by locking the original in a contract and minting a wrapped version elsewhere, or by drawing on liquidity pools stationed on both chains, according to Presto Research (June 3, 2024). Bridges keep failing because that hand-off depends on a small number of trust points – who validates the message, what the contract’s code actually checks, and how the system is configured – and a flaw in any one of them lets an attacker mint or release funds without a real deposit.
In a lock-and-mint bridge, depositing an asset on the source chain locks it in a smart contract; the bridge’s validators confirm the lock, and a wrapped token is minted on the destination chain, redeemable later by burning the wrapped token and unlocking the original, per Presto Research. A liquidity-pool bridge skips minting altogether: the user’s deposit goes into a pool on the source chain, and a matching pool on the destination chain pays out the equivalent amount from its own reserves, per the same source. Both designs share one property Chainalysis flagged in its August 2, 2022 post: they concentrate funds at a single storage point, whether that is a smart contract or a validator set, and that concentration is what makes bridges attractive targets.
If a bridge relies on a small set of external validators to approve transfers, controlling a majority of that set is enough to approve fraudulent ones. Presto Research describes the Ronin bridge exploit of March 2022 this way: Ronin ran a proof-of-authority model secured by nine validators, and compromising five of them let an attacker approve a transfer of 173,600 ETH and 25.5M USDC to an address that held no legitimate wrapped ETH on the chain – a loss Presto Research puts at approximately $625M across two transactions.
A second pattern is a flaw in the bridge’s own deposit-verification code, letting an attacker trigger a mint on the destination chain without ever depositing a real asset on the source chain – what Presto Research calls a false deposit. Its example is Qubit Finance’s Ethereum-BSC bridge in January 2022: because the contract used custom code rather than a standard library, an attacker found that submitting the null address as the token contract in the deposit function bypassed validation entirely, letting them mint roughly $185M worth of qXETH on BSC while depositing 0 ETH, for a total loss Presto Research puts at approximately $80M once the minted tokens were exchanged.
Modern bridges often use a messaging layer – Axelar, LayerZero and similar protocols – to tell the destination chain that a deposit really happened on the source chain. If the receiving contract doesn’t check that message rigorously enough, an attacker can forge one. Halborn’s account of the CrossCurve hack, posted February 9, 2026, describes exactly this: CrossCurve’s ReceiverAxelar contract had weak access controls, letting an attacker craft messages that appeared to come from Axelar and instructed the PortalV2 contract to release funds across multiple chains, for a loss Halborn estimates at approximately $3 million. The same mechanism, at far larger scale, is how KuCoin’s source (citing PeckShield data through mid-May 2026) describes the Kelp DAO exploit of April 18-19, 2026: attackers forged a cross-chain message on Kelp’s LayerZero-powered bridge and released around 116,500 rsETH, roughly 18% of that token’s circulating supply, a loss KuCoin’s source puts at approximately $292 million. 1inch, citing a TechRadar report, puts the same incident at approximately $290 mln – the two figures are not reconciled in the evidence available to this desk. Downstream lending platform Aave froze rsETH markets in response, according to KuCoin’s source; 1inch, for its part, says only that it took part alongside other protocols in efforts to help recover assets affected by the incident on Aave, and does not itself describe a freeze. A smaller instance of the same failure mode hit Hyperbridge in April, per 1inch: a forged message let an attacker mint 1 billion bridged DOT tokens and sell them into available liquidity, with initial losses reported at about $237,000 and a later assessment putting realized losses closer to $2.5 mln. And in May, per 1inch’s citation of a Cointelegraph report, security firms Blockaid and PeckShield flagged an exploit of Verus Protocol’s Ethereum bridge on May 18, in which the issue was, in Blockaid’s account, not an ECDSA bypass, not a notary key compromise, and not a parser bug, but missing source-amount validation – letting an attacker drain assets worth roughly $11.6 mln, later converted to about 5,402 ETH.
Even a sound messaging protocol can be undermined by how a specific project sets it up. Per 1inch, LayerZero said the Kelp DAO exploit traced to Kelp’s configuration choices, including its use of a single decentralized verifier network (DVN) rather than several independent ones; Kelp disputed that account. Neither party’s own statement is in the evidence reviewed for this page, so the dispute is unresolved here – it illustrates, though, that a messaging protocol’s security depends partly on choices the bridge operator makes on top of it.
Chainalysis’s August 2, 2022 estimate of $2 billion stolen across 13 bridge hacks, accounting for 69% of all crypto stolen that year, and its estimate that North Korea-linked hackers had taken about $1 billion from bridges and other DeFi protocols in 2022, describe a specific calendar year using Chainalysis’s own tracing methodology. KuCoin’s source, citing PeckShield data, describes a different window – eight bridge attacks from February to mid-May 2026 totalling approximately $328.6-329 million – using a dataset this desk has not seen directly, only KuCoin’s summary of it. The two numbers cover different years, different incident counts and undisclosed methodologies; adding them or reading a trend line between them is not something the evidence supports. Separately, KuCoin’s source reports total 2026 DeFi-related losses surpassing $750 million through mid-April, a figure that folds in incidents beyond bridges – including Drift Protocol’s approximately $285 million loss on April 1, 2026, which per that same source involved months of social engineering, a whitelisted low-value token used as fake collateral, and privileged administrative access, not a flaw in any bridge’s contract or messaging layer. Reporting that groups Drift Protocol into a “bridge hacks” roundup is describing an operational-trust compromise, not the mechanism this page covers.
This page cannot tell you whether bridge security is improving or worsening over time. The only two aggregate figures in evidence – Chainalysis’s $2 billion tally through August 2022 and KuCoin’s PeckShield-sourced $328.6-329 million tally for a few months of 2026 – use different time windows, different scopes, and methodologies that neither source discloses in full, so they cannot be compared as a trend. Where two outlets give different numbers for the same incident, as with Kelp DAO’s $292 million (KuCoin’s source, citing PeckShield) against $290 mln (1inch, citing TechRadar), this page states both rather than picking one, because neither source shows its underlying calculation. Several 2026 figures here rely on secondary reporting – this desk has not seen a primary post-mortem, audit report, or on-chain forensic writeup from Kelp DAO, Drift Protocol or Verus Protocol, and cannot independently confirm attacker attribution, including claims linking incidents to North Korea-linked groups, beyond what each outlet reports. Early loss estimates can also change: Hyperbridge’s initial figure of about $237,000 was later revised by 1inch to roughly $2.5 mln, and a number reported in the hours after an exploit should not be treated as the final one.
Every fact above is attributed to one of these reports. Where they disagree, the article says so.
Bitcoin ETF Outflow Totals Disputed: $4.4B vs $6.4B
Ethereum Whale Reports Disagree on ETH Staked Amount
August 19, 2026
August 19, 2026
August 19, 2026
We measure how many people read this site. That is all it is used for — there is no ad network, no advertising cookie, and nothing sold to anyone. Decline and the site works exactly the same. What we collect