Home / History / Scaling Wars / Bridges burn
2021–2022

Bridges burn

Cross-chain bridges become honeypots; exploits reshape risk models.

Scaling Wars

Story beats & cast

Token bridgesMultisigsLight client bridges
Events
  • Wormhole exploit
  • Ronin hack
  • Nomad hack
Actors
  • Jump Crypto — Wormhole backer
  • Sky Mavis — Ronin/Axie team

Bridges burn

How bridges move value

Two main tricks: lock-and-mint, or liquidity hop

Imagine a coat check between chains. In the classic lock-and-mint model, you hand the bridge your ETH on Chain A; it locks it in a vault and hands you an IOU (wrapped ETH) on Chain B. Redeem later, and it burns the IOU and hands your coat back. Simple—until you realize the coat room key is held by a handful of signers.

The alternative is the liquidity hop: the bridge keeps pools of assets on both sides. You deposit on one chain; someone on the other chain releases funds from the pool and takes your deposit. Speedy, but now the bridge operator is a market maker managing inventory and risk. Both designs are balancing acts: speed vs. trust, cost vs. security, convenience vs. blast radius.

Why they became honeypots

Bridges concentrate value. One fat multisig or validator set can unlock hundreds of millions. If an attacker steals keys, bypasses verification, or exploits upgrade paths, the entire vault empties in a single transaction. It’s the digital equivalent of robbing a bank where the vault door is controlled by a Slack channel.

Light-client and zk-based bridges tried to reduce key trust by verifying headers or proofs, but they added complexity and latency. Meanwhile, most traffic flowed through “good enough” multisigs. That gap between theory and practice turned bridges into the softest belly of the multi-chain dream.

Exploit parade and hard lessons

Ronin, Wormhole, Nomad, Harmony

Each hack read like a heist script with a different twist. Ronin: a handful of validator keys phished, $600M gone before lunch. Wormhole: a missing signature check in an upgrade path, nine digits evaporate. Nomad: a botched upgrade turned any message into a valid one; opportunists queued up to drain it like an open bar. Harmony: a multisig so small it was almost a dare. Postmortems like Wormhole’s analysis ↗ became grim reading.

The pattern was brutal: bridges saved pennies on decentralization, assumed “we’ll fix it later,” and attackers collected the IOUs. Victims learned that “audited” is meaningless if ops are sloppy, and “we’ll rotate keys soon” is cold comfort when the vault is empty.

Trust assumptions clarified

Post-mortems forced uncomfortable transparency. Good bridges started publishing trust diagrams: who signs, how many keys, where the keys live (HSM? cloud?), who can pause, and how upgrades work. Users learned new questions: Are you verifying source chain headers or just trusting signers? Can a small group halt withdrawals? Is there rate limiting? If a sequencer dies, do I get stuck forever?

Silence became a red flag. A bridge without docs was assumed guilty until proven robust. “Cross-chain” stopped meaning “magic teleport” and started meaning “here’s the list of ways this could go wrong.”

Hardening the glue

Toward safer designs

The industry’s scar tissue turned into checklists. Light-client and zk bridges reduced reliance on human signers. MPC and HSMs guarded keys. Rate limits and circuit breakers throttled withdrawals so a hack couldn’t drain everything in one block. Monitoring dashboards pinged ops teams when signatures looked odd.

Insurance funds and bug bounties stopped being PR props; they became table stakes. Some ecosystems declared “canonical” bridges to consolidate scrutiny, while modular stacks like Cosmos IBC built bridging into the protocol itself. None of it made bridges invincible, but the days of five-key multisigs guarding billions began to look like medieval medicine.

Canonical rails and standards

To cut down on chaos, some chains blessed official bridges and nudged users away from third-party experiments. Cosmos’ IBC embedded messaging at the protocol layer, reducing the need for ad-hoc multisigs. Standards emerged for proof formats, alerting, disclosures, and even “bridge hygiene” docs. Exchanges and wallets began to steer users toward safer routes by default.

Multi-chain life didn’t end; it got a bit more adult. The scars are still visible, etched in post-mortems and Etherscan comments. But the industry finally learned to treat the glue as critical infrastructure, not a weekend script.