What to Learn From Recent Cross-Chain Bridge Attacks
ID: cece6b12-d360-5370-b53d-555057b18c87
STIX ID: report--cece6b12-d360-5370-b53d-555057b18c87
Feed Name: CertiK Blog
This report reviews three major 2022 cross-chain bridge attacks (Qubit, Meter.io, Wormhole) in which attackers forged or spoofed proofs and bypassed verification to withdraw tokens on target chains. Root causes include shared proof events for ETH/ERC-20 deposits, failure to handle edge cases (such as ERC20 deposit paths producing ETH withdrawal proofs), and improper verification of injected sysvar accounts. The report provides mitigation lessons (separate ETH vs ERC20 flows, validate user-injected inputs, audit core bridge contracts) and actionable incident response recommendations (pause relays, notify partners, triage and fix vulnerabilities, transparent communication).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
