logo

Cross-Chain Vulnerabilities & Bridge Exploits in 2022

ID: da805ed6-db61-5e93-8a09-9d438da3c676

STIX ID: report--da805ed6-db61-5e93-8a09-9d438da3c676

Feed Name: CertiK Blog

Threat Score
75/100

Date Published: 2022-08-01

Date Updated: 2026-06-11

...
...

TL;DR: In 2022 five major cross-chain bridge attacks led to $1.317B in losses (57% of Web3 losses), including Ronin (suspected Lazarus Group, ~$624M), Wormhole (~$326M), Nomad (~$190M), Harmony (~$97M), and Qubit (~$80M). The report explains that cross-chain bridges combine multiple trust components (custodian, debt issuer, oracle) creating many attack vectors; it details the Nomad initialization bug that allowed message verification bypass and mass withdrawals involving at least 41 wallets, and recommends stronger testing and third-party audits to mitigate similar high-impact exploits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.