Cross-chain Bridge Thefts Top $1B in 2022

The lost funds illuminate a systemic lack of security among bridge protocols

article-image

Blockworks exclusive art by axel Rangel

share

key takeaways

  • Few DeFi companies employ dedicated security personnel
  • Industry experts believe bridges will become more secure as DeFi matures

As investment in cryptocurrency grows, so does the incentive for criminal actors to exploit the DeFi (decentralized finance) space. Cross-chain bridge hacks have been the weapon of choice for crypto thieves in 2022. Bridge hacks have accounted for more than a billion dollars in stolen funds this year, according to research from blockchain analytics and compliance firm Elliptic.

Cross-chain bridges allow assets to be moved between different blockchain protocols, meaning the networks contain a large concentration of crypto assets. The recent string of bridge attacks has caused some industry leaders to question whether the benefits of bridges outweigh their risks. A top analyst at Elliptic believes bridge hacks are just growing pains that DeFi will eventually surmount.

Harmony, Sky Mavis, and Wormhole all suffered blockchain exploits exceeding $100 million this year. Mudit Gupta, Chief Information Security Officer at Polygon, believes bridge insecurity is an industry-wide problem.

“Most of the hacks are happening due to companies not having proper security experts and not knowing what to do themselves,” Gupta said in a Twitter DM. “There are very few DeFi companies with [dedicated] security personnel.”

DeFi protocols have proliferated rapidly in the past six years, but security infrastructure has not kept up with the now over-$900 billion industry. For this reason, hacks totaling in the hundreds of millions are not surprising. 

On April 1, a trader tweeted their concern that a major Harmony Horizon Bridge exploit would only require a hacker to obtain two of the protocol’s five validator keys. In June, that exact scenario occurred — and Harmony was ransacked for $100 million.

Loading Tweet..

Vitalik Buterin, co-founder of Ethereum, believes cross-chain bridges are inherently prone to security breaches.

“The fundamental security limits of bridges are actually a key reason why…I am pessimistic about cross-chain applications,” Buterin wrote in a lengthy January Reddit post. The influential founder went on to express his belief that assets should be held in the same blockchain ecosystem, rather than shuffled between chains.

Tara Annison, Head of Technical Crypto Advisory at the crypto research firm Elliptic, disagrees.

“We’re not going to live in a single chain world,” Annison said. It will always be necessary to move assets between blockchains, so “we shouldn’t characterize bridges in general as bad just because some have been hacked.”

Annison believes bridge hacks are caused by the concentration of value within cross-chain bridges, not by the bridges themselves.

“If you think of wars, you try to bomb bridges to stop goods and services moving across,” Annison said. Recent cross-chain bridge hacks are not happening “because bridges are inherently weak infrastructure, it’s because they have a concentration of value.”

Annison believes that all crypto assets come with risk, and bridges are just the risk “flavor of the month” following stablecoins in May and NFTs before that. Bridges should become more secure as protocols become more technologically mature.

It remains to be seen if market participants agree.

Sky Mavis’ Ronin Bridge, which was compromised for $625 million in April, reopened this morning. Close to $9 million in assets have already left the chain, according to Messari.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Explore the growing intersection between crypto, macroeconomics, policy and finance with Ben Strack, Casey Wagner and Felix Jauvin. Subscribe to the On the Margin newsletter.

The Lightspeed newsletter is all things Solana, in your inbox, every day. Subscribe to daily Solana news from Jack Kubinec and Jeff Albus.

Tags

Upcoming Events

Salt Lake City, UT

MON - TUES, OCT. 7 - 8, 2024

Blockworks and Bankless in collaboration with buidlbox are excited to announce the second installment of the Permissionless Hackathon – taking place October 7-8 in Salt Lake City, Utah. We’ve partnered with buidlbox to bring together the brightest minds in crypto for […]

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Permissionless is a conference for founders, application developers, and users. Come meet the next generation of people building and using crypto.

recent research

Research Report Templates (1).png

Research

Solana Mobile is a highly ambitious foray into the mobile consumer hardware market, seeking to open up a crypto-native distribution channel for mobile-first applications. The market for Solana Mobile devices has demonstrated a phenomenon whereby external market actors (e.g. Solana-native projects) continuously underwrite subsidies to Mobile consumers. The value of these subsidies, coming in the form of airdrops, trial programs, and exclusive NFT mints, have consistently covered the cost of the phone and generated positive returns for consumers. Given this trend in subsidies, the unit economics in the market for Mobile devices, and the initial growth rate and trajectory of sales, it should be expected that Solana mobile can clear 1M to 10M units over the coming years. As more devices circulate amongst users, Solana Mobile presents a promising venue for the emergence of killer-applications uniquely enabled by this mobile-first, crypto-native distribution channel.

article-image

Mt. Gox has made decent headway with repayments, but they could ramp up from here

article-image

Firm known for crypto hardware wallets set to bring another touchscreen option to consumers

article-image

Plus, BlackRock’s BUIDL is paying out steady yield — and those dividends are growing

article-image

Solana’s biggest liquid staking provider takes a meaningful step towards restaking

article-image

BLAST token skids as Season 2 points plan earns mixed reviews

article-image

Plus, a look at the top asset-gathering ETH ETFs after two days of trading