logo

What to Learn From Recent Cross-Chain Bridge Attacks

ID: cece6b12-d360-5370-b53d-555057b18c87

STIX ID: report--cece6b12-d360-5370-b53d-555057b18c87

Feed Name: CertiK Blog

Threat Score
80/100

Date Published: 2022-02-11

Date Updated: 2026-06-11

...
...

This report reviews three major 2022 cross-chain bridge attacks (Qubit, Meter.io, Wormhole) in which attackers forged or spoofed proofs and bypassed verification to withdraw tokens on target chains. Root causes include shared proof events for ETH/ERC-20 deposits, failure to handle edge cases (such as ERC20 deposit paths producing ETH withdrawal proofs), and improper verification of injected sysvar accounts. The report provides mitigation lessons (separate ETH vs ERC20 flows, validate user-injected inputs, audit core bridge contracts) and actionable incident response recommendations (pause relays, notify partners, triage and fix vulnerabilities, transparent communication).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.