Advanced
Designing Bridges — Key concepts
Understand cross-chain architecture.
Developer Advanced
4/8 — Designing Bridges — Key concepts
DomainsAlways scope messages to source/target chain IDs.
Trusted third parties are security holes.
Bridge message ID
id = keccak256(sourceChain || targetChain || nonce || recipient || amount || token)
Domain separation prevents cross-chain replay.
Replay protectionTrack consumed message IDs; reject duplicates.
VerificationStart with a trusted verifier set (multi-sig or operator). Light clients/zk proofs are better but out of scope here.
Key points
- Domain separation:Include source/target chain IDs and nonce in every message hash.
- Replay guards:Mark message IDs as used before transferring out.
- Verifier set:Require a trusted signer/multi-sig; rotateable and pausible.
- Lock vs mint:Lock + release for existing token, or mint/burn wrapped IOUs on the target.
- Expiry:Proofs should expire; stale proofs are dangerous.