Bridges are where the money actually gets stolen
Moving assets between chains requires trusting something, and that something has been the largest single category of loss.

Chains cannot natively talk to each other. Moving an asset from one to another requires a bridge, and bridges have accounted for an outsized share of total value stolen in the sector.
Why they are vulnerable
A typical bridge locks an asset on chain A and issues a representation on chain B. That lock has to be controlled by something: a multisig, a validator set, or a contract.
Whatever controls it is holding a large pool of assets in one place, with the authority to release them. That is the most attractive target in the system, and the attack surface is the control mechanism rather than the cryptography.
The recurring failures
Compromised keys on a multisig with too few signers. Validator sets small enough to collude or be captured. Verification bugs where a forged proof is accepted, allowing an attacker to mint the representation without locking anything.
The third is the most damaging because it is silent — the bridge mints assets that were never backed, and the discovery comes later.
What reduces the risk
Larger and more independent validator sets, time delays on large withdrawals, and caps on throughput. All of these trade convenience for safety, and users consistently choose the faster bridge.
The practical read
If you bridge, treat the bridge as the risk rather than the destination chain. And do not leave assets sitting in a bridge’s representation longer than the transaction requires.
Not financial advice.
Reported at Decrypt and CoinDesk; analysis ours.
Newsletter
Markets, in five minutes
Get The Block in your inbox. No spam, and one click to leave.
Every weekday · Unsubscribe any time. We never sell or rent your address; read the privacy policy.