Key Points
- A crypto bridge holds a large pool of locked tokens so it can issue matching tokens on another chain. That pool is the target.
- Bridge hacks took about $2 billion in 2022 alone, roughly 69% of all crypto stolen that year up to August, according to Chainalysis.
- The five cases in this guide fall into a few failure types: too few keys guarding the funds, a coding flaw in how messages are checked, a bad upgrade, and one person controlling everything.
- Three of the five weaknesses were visible before the hack to anyone who checked who controls the bridge and how many signatures it needs.
- Funds lost in a bridge hack are not covered by UK or US deposit protection schemes, and recovery is rare.
Quick Answer
Crypto bridges get hacked because they hold huge pools of locked tokens behind a small number of controls. In the largest cases, attackers took over the keys that approve withdrawals (Ronin, Harmony), found a flaw in the code that checks messages (Wormhole), exploited a faulty upgrade (Nomad), or the bridge depended on one person who was then detained (Multichain). The common misread is that a hack means the blockchain itself was broken. In each of these cases the chains worked as designed; the weak point was the bridge sitting between them.
Bridge hacks at a glance
Five hacks, four ways bridges fail
RoninToo few keys
Attackers controlled 5 of 9 validator keys: four through one company's systems, one through an old permission left switched on. Unnoticed for six days.
Which check would have flagged it?
Who controls the signers. Four of the nine keys sat with one organisation.
WormholeCode flaw
A way around the signature check let the attacker create 120,000 wrapped ETH with no real ETH behind it. Replacement ETH was later found.
Which check would have flagged it?
Hard to spot as a user. This is why audits matter, and why they are not enough on their own.
Harmony HorizonToo few keys
A 2 of 5 multi-signature wallet guarded the funds. Two keys were enough to move everything.
Which check would have flagged it?
The signing threshold. Two signatures for a pool this size was visible in advance.
NomadBad upgrade
An upgrade made the bridge accept unverified messages. Once one wallet showed how, many others copied the same transaction.
Which check would have flagged it?
Upgrade controls. A delay before upgrades take effect gives time to catch mistakes.
MultichainOne point of control
Keys, servers and funds were under one person's control. When that person was detained, the bridge could no longer run.
Which check would have flagged it?
Who holds the keys. If the team cannot say, treat that as the answer.
Sources: Chainalysis via Decrypt, TechCrunch, The Block, TRM Labs, Halborn, DL News. Amounts are at the time of each hack. Full list under Sources below.
What makes a crypto bridge a target?
A bridge lets you move value from one blockchain to another. The common design locks your tokens in a contract on the first chain and issues a matching "wrapped" token on the second. Every wrapped token in circulation is only worth something because the locked tokens are still sitting in that contract.
That creates one very large, very public pot of money. If an attacker can convince the bridge that a withdrawal is valid when it is not, they can drain the pot, and every wrapped token on the other side loses its backing at the same time. For the basics of how bridging works and how to do it safely, see our beginner guide to bridging crypto safely.
How much has been lost to bridge hacks?
Chainalysis estimated in August 2022 that about $2 billion had been stolen through cross-chain bridge hacks that year, making bridges the single largest source of stolen crypto in 2022. The five cases below account for well over $1.3 billion between them.
What happened in the Ronin bridge hack?
On 23 March 2022, attackers took about $625 million (173,600 ETH and 25.5 million USDC) from the Ronin bridge, which served the game Axie Infinity.
Ronin needed signatures from 5 of its 9 validators to approve a withdrawal. Attackers got into the systems of the company behind Ronin through a fake job offer sent to a senior engineer as a PDF. That gave them four validator keys. The fifth came from an old permission that let a separate group sign on the company's behalf; it had been granted temporarily in late 2021 and was not switched off afterwards.
The theft went unnoticed for six days, until a user reported that they could not withdraw 5,000 ETH. The FBI later attributed the attack to the Lazarus Group, linked to North Korea.
The lesson: 5 of 9 sounds like a lot of signatures, but four of them sat with one organisation. Count who controls the keys, not just how many keys there are.
What happened in the Wormhole hack?
On 2 February 2022, an attacker created 120,000 wrapped ETH on Solana, worth over $320 million at the time, without depositing any real ETH on Ethereum.
The flaw was in the code that checks whether a deposit message has been properly signed. The attacker found a way around that signature check and told the bridge a deposit had happened when it had not. The bridge then issued wrapped ETH with nothing behind it.
Wormhole secured replacement ETH so that its wrapped tokens were backed one to one again, which is why holders were made whole in this case. That is unusual.
The lesson: audits and large backers reduce risk but do not remove it. One missed check in the code was enough. Our guide to smart contract audits and why audited projects still get hacked covers this in more depth.
What happened in the Harmony Horizon bridge hack?
On 23 June 2022, about $100 million was taken from Harmony's Horizon bridge in ETH, BNB and several stablecoins.
The bridge was controlled by a multi-signature wallet that needed just 2 of 5 signatures to move funds. Once the attacker controlled two keys, the bridge treated their withdrawals as legitimate. How the keys were obtained was not fully set out publicly at the time.
The lesson: a low signing threshold on a large pool of funds is a warning sign you can see in advance.
What happened in the Nomad bridge hack?
In August 2022, about $190 million left the Nomad bridge in a free-for-all.
A routine upgrade set a key value in the contract to zero. Zero was also the default value for messages that had not been verified, so the bridge started accepting unverified messages as valid. Once the first attacker showed how, many other wallets copied the same transaction, swapped in their own address, and joined in. No special skill was needed.
The lesson: upgrades are a risk in their own right. A bridge that can be changed quickly by its team can also be broken quickly by a mistake.
What happened to Multichain?
In July 2023, about $126 million flowed out of Multichain's bridge contracts in transfers the project described as unauthorised. Multichain later said its chief executive had been held by Chinese authorities since May, and that the keys and servers running the bridge, along with the project's operating funds, had been under that one person's control. The project said it could no longer operate.
The lesson: a bridge can be run by many computers and still depend on one person. If the team cannot explain who holds the keys, treat that as the answer.
What do the big bridge hacks have in common?
Looking across the five cases, the failures fall into four types:
- Too few keys, or keys too close together. Ronin and Harmony needed only a handful of signatures, and those keys were not spread across truly independent parties.
- A flaw in message checking. Wormhole's code accepted a message it should have rejected.
- A bad upgrade. Nomad's own change opened the door.
- One point of control. Multichain depended on one person for keys, servers and funds.
Only one of the four needed rare technical skill. The other three were questions of who is trusted and how much.
What should you check before using a bridge?
You cannot audit a bridge yourself, but you can ask the questions these hacks raise:
- Who approves withdrawals, and how many signatures are needed? Look for the number of signers and whether they are independent organisations.
- Can the team upgrade the contracts, and is there a delay? A waiting period before upgrades take effect gives users time to react.
- How much is locked? A small team guarding a very large pool is a bigger target.
- Is it the chain's official bridge? Official bridges for Layer 2 networks generally rely on Ethereum itself for security rather than a separate group of signers. Our Layer 1 vs Layer 2 guide explains why that matters.
- What approvals have you left behind? Old token approvals to a bridge that later fails can still be used against you. See how token approvals work and how to revoke them.
Our free Wallet and Bridging Safety Checklist turns these into a one-page list to run through before every bridge, along with the wallet and signing checks that go with them.
Can you get your money back after a bridge hack?
Usually not. Wormhole's holders were made whole because replacement funds were found, but that is the exception. Bridge losses are not covered by deposit protection: the FDIC states that its insurance does not cover crypto assets, and the FCA warns that people who buy crypto are unlikely to be able to claim from the Financial Services Compensation Scheme if something goes wrong.
If you lose funds in a hack or are targeted by a fake bridge site, report it. In the US, use the FBI's Internet Crime Complaint Center (IC3) and the FTC. In England, Wales and Northern Ireland, use Report Fraud, which replaced Action Fraud in December 2025; in Scotland, call Police Scotland on 101. Be wary of anyone who contacts you offering to recover funds for a fee, as recovery scams often follow large hacks. Our guide to spotting crypto scams covers these.
Frequently Asked Questions
What was the biggest crypto bridge hack?
Ronin, in March 2022, at about $625 million. It was the largest DeFi hack on record at the time.
Are bridges safer now than in 2022?
Bridge designs have changed since 2022, and official Layer 2 bridges reduce reliance on separate signer groups. The underlying risk, a large pool of locked funds, has not gone away, so the checks above still apply.
If a bridge is hacked, are my tokens on the other chain affected?
Often, yes. Wrapped tokens rely on the locked funds behind them. If those funds are drained, the wrapped tokens can lose their backing and their price can fall sharply even if you did not use the bridge yourself.
Does a bridge being audited mean it is safe?
No. An audit reduces the chance of a coding flaw; it does not cover key management, upgrades or who controls the project.
New to some of the terms here? Keep our crypto glossary open in another tab.
The Wallet and Bridging Safety Checklist: the checks to run before you download a wallet, sign a transaction or bridge tokens. One page, free with a TMU account.
Get the free checklistFurther Reading
- How to bridge crypto assets safely: complete beginner guide
- How do you bridge to Base?
- What is DeFi and how is it different from traditional finance?
- What is a smart contract audit and how do you read one?
- What are token approvals and how do you revoke them?
Sources
- Decrypt: Cross-chain bridge hacks hit $2 billion in 2022, Chainalysis (August 2022)
- TechCrunch: Ronin network suffers $625M exploit (March 2022)
- The Block: How a fake job offer took down Ronin (July 2022)
- TechRadar: FBI attributes Ronin theft to Lazarus Group (April 2022)
- TRM Labs: Solana Wormhole compromise, 120k wrapped ETH stolen
- The Block: Harmony's $100 million hacker took control of its multi-signature wallet (June 2022)
- Halborn: Explained, the Nomad hack (August 2022)
- Halborn: Explained, the Multichain hack (July 2023)
- DL News: Multichain halts bridge, saying chief executive arrested (July 2023)
- FDIC: What the public needs to know about deposit insurance and crypto companies
- FCA: Cryptoassets
- Report Fraud: service goes live (December 2025)
- FBI Internet Crime Complaint Center (IC3)
- FTC: ReportFraud
Legal And Risk Notice
This article is for education only and is not financial, investment or legal advice. Crypto assets are high risk and you could lose all the money you put in. Bridges and other DeFi protocols carry technical and counterparty risks, and losses are not covered by deposit protection schemes in the UK or US. Consider independent advice before making decisions.
Discussion