Advanced

Designing Bridges — Key concepts

Understand cross-chain architecture.

Developer Advanced
4/8 — Designing Bridges — Key concepts

DomainsAlways scope messages to source/target chain IDs.

Trusted third parties are security holes.
— Nick Szabo
Bridge message ID
id = keccak256(sourceChain || targetChain || nonce || recipient || amount || token)
Domain separation prevents cross-chain replay.

Replay protectionTrack consumed message IDs; reject duplicates.

VerificationStart with a trusted verifier set (multi-sig or operator). Light clients/zk proofs are better but out of scope here.

Key points
  • Domain separation:Include source/target chain IDs and nonce in every message hash.
  • Replay guards:Mark message IDs as used before transferring out.
  • Verifier set:Require a trusted signer/multi-sig; rotateable and pausible.
  • Lock vs mint:Lock + release for existing token, or mint/burn wrapped IOUs on the target.
  • Expiry:Proofs should expire; stale proofs are dangerous.
← Previous section
Next section →