Wormhole Bridge Exploit Incident Analysis
ID: 101c2ae2-7fb2-5fed-890f-61e30208d5f6
STIX ID: report--101c2ae2-7fb2-5fed-890f-61e30208d5f6
Feed Name: CertiK Blog
On February 2, 2022, the Wormhole cross-chain bridge on Solana was exploited when an attacker injected a forged sysvar account and abused a deprecated verification function (load_current_index) to produce a malicious VAA and mint 120,000 wETH (~$320M). The report details the transaction chain (including bridging to Ethereum and swaps to USDC/SOL), attacker wallet addresses, the root cause (failure to validate guardian/sysvar accounts), and asset-tracing results, and recommends strict verification of all accounts used in critical verification paths.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
