CriticalSecurity

Another bridge, another validator set, another eight-figure loss

The failure mode was not novel. It was a small multisig with excessive authority, which is the same finding as most bridge incidents since 2021.

Hiroshi Tanaka
5 min read
Cracked red chain link glowing over streams of cyan binary code
Cracked red chain link glowing over streams of cyan binary code

A cross-chain bridge was drained this week after attackers obtained sufficient signing keys to authorise fraudulent withdrawals. Funds moved through a mixer within hours, following the pattern forensic teams now expect.

The failure was governance, not cryptography

The contracts did what they were written to do. A small set of signers held authority to release assets, and compromising a subset of them was enough. Every serious bridge post-mortem since 2021 has landed on some version of this finding.

What better looks like

Larger and more diverse signer sets with hardware isolation, withdrawal rate limits that cap the damage of any single authorisation, mandatory delays on large transfers, and monitoring that halts the bridge automatically on anomalous outflow. None of this is research; it is operational discipline.

Users can check whether a bridge publishes its signer topology and rate limits before routing size through it. Most that do not, cannot.

Locking assets on one chain and minting claims on another creates a single honeypot with multiple trust assumptions layered on top.

Designs that minimise custodied value, or settle through shared security, reduce the prize. Adoption of those designs is still slower than the attacks.

Sources & references

Hiroshi Tanaka
Security & On-Chain Forensics

Hiroshi investigates exchange breaches, protocol exploits and laundering flows using on-chain forensic tooling.

More from CryptoxInsights