h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● DeFi & On-chain

The Unaudited Bridge: Where Cross-Chain Security Breaks in 2026

A bridge's smart contract is the one part that gets audited, and in 2026 it is almost never where the money leaves. This is a tour of the off-chain layer that actually breaks.

Bitcoin spent the first week of October trading in the low $80,000s, hovering around $83,000 per coin after a choppy end to September, according to CoinGecko. The price is almost beside the point for anyone who has ever moved a token from one chain to another. Their question is older and simpler: is the bridge going to hold?

Cross-chain bridges are still the most dangerous plumbing in crypto, and they are still where the largest single losses happen. What changed in 2026 is not that bridges stopped breaking. It is where they break. The thing most people picture when they hear the word bridge, a smart contract that locks your tokens on one side and releases them on the other, is the smallest and best-defended part of the whole system. It gets audited, re-audited, formally verified, fuzzed, and picked over by bug-bounty hunters. And in 2026 it is almost never where the money actually left.

The money left through everything around the contract: the keys that signers hold, the servers that relayers and verifiers run on, the data a bridge trusts to tell it what happened on the other chain, and the administrative controls that let a few people rewrite the rules after the audit is signed. TRM Labs counted 207 separate hacks in the first half of 2026 that stole about $972 million between them. Smart-contract exploits were the majority of those incidents by count. But infrastructure and operational compromise, the off-chain layer, accounted for roughly 76 percent of the stolen value while making up only about 15 percent of incidents. In plain terms: the small, frequent thefts come from code, and the enormous ones come from everything else.

This piece is a tour of that everything else. Call it the unaudited bridge: the operational layer that sits underneath the contract, holds the real power, and does not appear in the report you were handed when you decided the bridge was safe to use.

The three machines behind every bridge

A bridge is not one program. It is three systems bolted together, and only one of them lives entirely on a blockchain.

  • The on-chain contracts. These lock, mint, burn, and release tokens. They sit on each chain, their code is public, and they are the part that gets audited.
  • The off-chain messaging layer. Something has to watch chain A, notice that you deposited, and tell chain B to release your funds. That something is a set of relayers, oracles, or verifiers running on ordinary servers. No blockchain’s consensus protects them.
  • The human and key layer. Someone holds the keys that authorize releases, runs the servers, and controls the admin functions that can upgrade or pause the contracts. These are people, companies, and foundations, with laptops, cloud accounts, and all the ordinary ways those get compromised.

The reason this split matters is structural. Each blockchain is its own sovereign system with its own validators and its own rules. A bridge is the connective tissue in the gap between them, and nothing in that gap is secured by either chain’s consensus. Vitalik Buterin, Ethereum’s co-founder, made the point back in 2022, warning that “there are fundamental limits to the security of bridges that hop across multiple zones of sovereignty,” as Cointelegraph reported at the time. Four years on, the industry has not repealed that limit. It has gotten very good at drawing a tidy box around the one-third of the system that is easy to inspect and calling the box the bridge.

The code got safer, and the bridges emptied anyway

Here is the uncomfortable result of a decade of audits: the contracts improved, and the losses did not stop. DeFi protocols lost at least $1.3 billion to exploits in the first eight months of 2026, and for the first time on record, compromised keys and operational failures, not smart-contract bugs, drove the majority of the value stolen, as Forbes reported from CertiK’s mid-year data. TRM’s numbers show the same shape from a different angle: the median hack cost about $219,000, while the average reached $4.7 million, a twentyfold gap that exists because a handful of giant, off-chain compromises drag the average up.

The historical record tells the story if you sort it the right way. Early bridge disasters were mostly code. Chainalysis catalogued about $2 billion stolen from 13 bridge hacks in 2022 alone, roughly 69 percent of all crypto stolen that year, and several of those were contract bugs that an audit could, in principle, have caught. The industry audited harder. It did not get safer in proportion, because the attackers simply walked around the contract. Sort the landmark failures by where they actually broke, and the on-chain contract is only one column among several.

IncidentWhenReported lossWhere it actually broke
Ronin NetworkMar 2022~$625M5 of 9 validator signing keys stolen
WormholeFeb 2022~$325MSignature-verification bug (code)
BNB Chain BridgeOct 2022~$570MForged proof the contract accepted (code)
NomadAug 2022~$190MMisconfiguration made any message valid (code)
Harmony HorizonJun 2022~$100M2 of 5 multisig signing keys
MultichainJul 2023~$130M+MPC keys held by one person
KelpDAO (via LayerZero)Apr 2026~$292MCompromised off-chain verifier nodes
Liquid NetworkSep 2026~$320MConsensus bug; federation signed a forged proof

Three of the four largest crypto thefts of the current era were not even bridges in the strict sense, and they fit the same pattern. Bybit lost about $1.5 billion in early 2025 when attackers compromised the infrastructure used to sign transactions, not the contract logic. The Drift protocol lost around $285 million in April 2026 to a socially engineered administrative key. Poly Network lost hundreds of millions of dollars in 2021 to a contract flaw, then returned most of it after a hacker who called himself Mr. White Hat chose to give it back. The lesson that runs through all of it is that the contract is the part you can see, and the part you can see is increasingly not the part that fails.

Layer one: the keys that sign the releases

The oldest bridge failure mode is also still the most expensive. Most bridges keep a pile of real assets locked on one side and let a set of signers authorize releases on the other. Whoever controls enough of those signing keys controls the pile. The threshold looks reassuring on a slide, 5 of 9 here, 11 of 15 there, but a threshold only describes how many keys an attacker needs, not how hard those keys are to take.

Ronin, still the largest bridge theft on record, came down to five keys. Attackers linked to North Korea’s Lazarus Group took over four validator keys controlled by the bridge’s operator and a fifth that had been delegated months earlier, cleared the 5-of-9 bar, and left with about $625 million. Harmony’s Horizon bridge used a 2-of-5 multisig, so two compromised keys were enough for a roughly $100 million loss. In neither case did the contract misbehave. It released funds against signatures that were, by its own rules, completely valid.

The real question is never the threshold. It is where the keys live and who can reach them. Signing keys sit on servers, in cloud accounts, inside hardware security modules, and, far too often, on laptops that also read email. That is why the most effective key thefts of the past two years did not break cryptography at all; they broke the humans and machines around it. Bybit’s roughly $1.5 billion loss in 2025 is the clearest example. Attackers compromised a developer workstation at the third-party wallet platform Bybit relied on, injected malicious code that quietly rewrote the details of a routine transfer, and let Bybit’s own executives approve it, as the Wilson Center reconstructed. The signers were real, the keys were real, and the transaction they blind-signed was simply not the one they believed they were approving.

A quieter version of the same attack runs constantly against ordinary users and small teams: malware that reads keys and session tokens straight off an infected device. HOGE Wire has covered how that infostealer epidemic now accounts for a large share of stolen crypto, precisely because it skips the hard math and goes directly for the file where the key is stored. A bridge whose signers are only as safe as their worst-patched laptop has a security model that no contract audit will ever describe.

Layer two: the verifiers that report reality

A contract on one chain cannot see another chain. It has no eyes. When you deposit on Ethereum and expect tokens on Arbitrum, something off-chain has to watch the deposit and tell the destination contract it happened. That reporter goes by different names, relayer, oracle, validator set, decentralized verifier network, but its job is always the same: turn an event on one chain into a message the other chain will act on. Corrupt the reporter and you do not need to break the contract. The contract will do exactly what it was designed to do, correctly, with your money, because it was told something it had no way to check.

The $292 million KelpDAO exploit of April 2026 is the cleanest illustration of the decade. KelpDAO’s restaked-ether token, rsETH, used the LayerZero messaging protocol to move between chains, and its deployment ran on a 1-of-1 verifier configuration: a single decentralized verifier network, operated by LayerZero Labs, had to attest that a cross-chain message was genuine, and Kelp has said that one-of-one was the default shipped for new deployments at the time. Attackers tied to Lazarus, specifically the subgroup Chainalysis calls TraderTraitor, went straight for that single verifier’s infrastructure. They compromised two internal RPC nodes run by LayerZero Labs, swapped in malicious software engineered to self-destruct and erase its own logs once the attack window closed, and at the same time hit an external RPC provider with a denial-of-service attack so the verifier had no choice but to lean on the two poisoned nodes. Those nodes reported an rsETH burn on Unichain that never happened. The bridge, trusting its only source of truth, released 116,500 rsETH.

Ben Fisch, the chief executive of Espresso Systems, gave CoinDesk the uncomfortable summary: “The bridge worked as designed.” It did. It was fed false data by an infrastructure layer that no audit of the Kelp contracts would ever have examined. A second attempt to drain another 40,000 rsETH, worth roughly $95 million, failed only because KelpDAO managed to pause its contracts in time, and Arbitrum’s Security Council froze 30,766 ETH belonging to the attacker within hours.

The configuration is the whole lesson. LayerZero’s own documentation now tells builders in plain language that “production deployments should explicitly configure their security stack with at least one required DVN that is not operated by LayerZero Labs,” and warns that default settings “may include only a single DVN” and can change without notice. The protocol lets each application pick a threshold it calls X-of-Y-of-N: how many independent verifiers, out of how many optional and how many total, must agree before a message is accepted. KelpDAO’s 1-of-1 was the weakest possible reading of that system, one verifier, one point of failure, one infrastructure compromise away from disaster. The guidance is in LayerZero’s security-stack documentation, and it exists because the default is not good enough on its own.

Smaller versions of believe-the-report happen all year. In January 2026 the cross-chain protocol CrossCurve lost about $3 million when its receiver contract accepted spoofed cross-chain messages it never properly validated, letting an attacker trigger token releases with forged instructions. Different size, same category: the money leaves through the gap between what a bridge is told and what actually happened on the other side.

Layer three: the federation and the lone operator

Suppose the signers are honest and there are plenty of them. They can still be defeated two ways, and 2026 produced a textbook example of each.

The first is when the protocol itself is wrong and the signers faithfully approve a forgery. Liquid Network, Blockstream’s long-running federated Bitcoin sidechain, is secured by a group of 15 functionaries that needs 11 signatures to move funds, exactly the kind of high, reputable threshold that is supposed to make a system boring and safe. In September 2026 attackers found a caching flaw in the Elements software that verifies transactions: validation results were cached to save time, and a flaw in how those cached checks were identified meant new, invalid data could be mistaken for data that had already been approved. By submitting invalid data that pointed at a cached valid result, the attackers minted unbacked L-BTC and pegged out roughly 4,000 of the 4,200 BTC backing the chain, about $320 million. The federation signed the peg-out. It had no reason not to: as far as the consensus rules were concerned, the transaction was valid. Eleven honest functionaries cannot catch a bug in the very thing they are checking. The attackers, calling themselves white hats, later returned 3,400 BTC and kept around 600, worth roughly $47 million, as a self-declared bounty; Blockstream called the episode theft, not disclosure.

Liquid is a useful reminder that a bridge or a peg is only ever as trustworthy as the weakest assumption underneath it, which is close to the argument HOGE Wire made that the real dividend of Bitcoin’s 2026 shakeout was self-custody: coins you hold yourself are not exposed to someone else’s federation signing the wrong thing.

The second way is the opposite problem: too few hands on the keys. Multichain, once one of the busiest bridges in crypto, routed its funds through a multi-party computation setup whose keys were effectively controlled by a single person, the chief executive. When he was reportedly detained by Chinese authorities in mid-2023, roughly $130 million drained out of bridge contracts on Fantom, Moonriver, and Dogechain, and the protocol never recovered. Chainalysis suspected an inside job. Whatever the precise cause, the structural lesson is blunt: a bridge with one true point of human control is not a decentralized protocol, it is a company whose single owner can vanish, and you cannot sue a vanished company for your tokens back.

Layer four: the admin keys that can rewrite the deal

Here is the layer that quietly undoes the entire premise of auditing. Almost every serious bridge contract is upgradeable. A privileged address, usually a multisig or a governance process, can swap out the implementation code, change parameters, whitelist a new token, or adjust who is allowed to do what. Upgradeability is not a flaw in itself; it is how teams ship fixes, including the patch Blockstream pushed for Liquid. But it means there is an address somewhere with the power to change the contract after the audit, and whoever holds that address can, in effect, become the protocol.

Ronghui Gu, the co-founder of the audit firm CertiK, put it to Forbes with no hedging: “A protocol can pass a flawless code audit and still lose millions because of a compromised admin key.” That is not a hypothetical. The Drift protocol was drained of around $285 million in April 2026 without a single line of its contracts being broken. Attackers spent months socially engineering their way to an administrative key, then used it to whitelist a worthless token as collateral and borrow against it, pulling funds out across 31 transactions in a little over two minutes. HOGE Wire walked through that minutes-long drain in detail; the short version is that the code did exactly what an authorized admin told it to do, and the admin was the attacker.

This is why a clean audit report can be dangerously reassuring. An audit certifies the code as written on a given day. The admin key is the standing authority to rewrite that code tomorrow, and it lives off-chain, in the same servers, cloud accounts, and human inboxes as every other key. Governance can be its own attack surface: where a bridge’s upgrades are decided by a token vote, an attacker who can borrow or buy enough votes for a single block can sometimes push a malicious proposal through outright. The defenses exist, timelocks that force a public delay before an upgrade takes effect, independent security councils that can freeze a contract, and narrow, well-guarded admin roles, and we will come to them. But the first step is admitting that the most powerful key on most bridges is not the one that signs releases. It is the one that can change the rules.

Layer five: the website, the DNS, and the dependencies

There is one more layer, and it is the one ordinary users actually touch: the website. You do not interact with a bridge contract directly. You visit a site, connect a wallet, and approve whatever that site asks you to sign. If an attacker controls the site, they do not need the contract or the keys. They need only change what your wallet is asked to approve.

BadgerDAO learned this in December 2021. Attackers compromised an API key for the project’s Cloudflare account and injected a single malicious script into its front-end. The script quietly asked each visitor’s wallet to grant a token-spending allowance to the attacker’s address, and users clicked approve on what looked like an ordinary transaction. About $120 million walked out, as The Block reported, while the audited smart contracts were never touched. The weak link was a web-hosting account and a wallet pop-up.

The same exposure runs through the software supply chain. A bridge front-end is assembled from dozens of third-party code packages; compromise one popular dependency and you can poison every site that ships it. Domain hijacks, where an attacker seizes a project’s web address and points it at a clone, do the same job from a different angle. None of this appears in a smart-contract audit, because none of it is the smart contract. It is also why blind-signing, approving a transaction your wallet shows you as an unreadable blob, remains one of the most dangerous habits in crypto: if you cannot read what you are signing, you are trusting the website to be honest about it, and the website is exactly the part that keeps getting compromised.

Why an audit stops at the contract

Put the five layers together and the gap is obvious. A smart-contract audit does one job well: it examines the on-chain code, usually at a specific version, and hunts for the classic bug classes, reentrancy, arithmetic overflow, broken access control, logic errors. A good audit is genuinely valuable. It is also, by scope, nearly silent on everything this article has described.

A typical engagement does not inspect the key-management practices of the signers, the security of the relayer and verifier servers, the cloud and DevOps configuration, the admin-key governance, the front-end hosting, or the operational procedures that decide who can push a change and how fast. Those live off-chain, often inside private companies, and they are usually out of scope by definition. That is how a bridge can be audited, re-audited, and still drained: the auditors did their job on the code, and the money left through a door the code never had.

KelpDAO made the point starkly. Its contracts had been audited, and in the exploit they behaved exactly as written; the forgery happened in the verifier infrastructure, which sat entirely outside what any contract review would examine. That is why Fisch’s line, the bridge worked as designed, is less a defense of the bridge than an indictment of the mental model. Designing the contract correctly is necessary and nowhere near sufficient. The other four layers decide whether your funds survive, and only one of the five routinely gets a certificate.

What a hardened bridge looks like in 2026

The better news is that the industry has spent 2026 doing something about all of this, and the fixes map almost one-to-one onto the five layers. The strategy has two halves: make each off-chain layer harder to compromise, and shrink what any single compromise can steal.

At the key layer, serious operators have moved signing into multi-party computation and hardware security modules, spread signers across jurisdictions and devices, and pushed for clear-signing so a human approving a transaction can actually read it. At the verifier layer, the answer is to stop trusting a single reporter. LayerZero’s X-of-Y-of-N model lets an application demand that several independent verifiers agree, and its documentation now urges at least one that LayerZero Labs does not operate. Chainlink’s CCIP takes a belt-and-suspenders approach, pairing the main protocol with a separate Risk Management Network that independently watches for anomalies and can halt transfers, built on deliberately different software so a single bug is less likely to fool both layers at once; Kraken, explaining its own move, pointed to CCIP’s 16 independent nodes and native rate limits.

At the admin layer, the defenses are governance, not code: timelocks that force a public delay before any upgrade takes effect, giving users time to exit; independent security councils that can freeze a contract in an emergency, as Arbitrum’s did when it locked up the KelpDAO attacker’s funds; and a deliberate shrinking of what admin keys are allowed to do in the first place. One of the most important primitives here is the token rate limit. Standards such as xERC-20, proposed as EIP-7281, let a token issuer set a per-bridge cap on how much can be minted in a given window, so even a fully compromised bridge can mint only up to its limit instead of printing the entire supply, which is precisely the failure mode behind Wormhole’s 120,000 fake wETH.

The most radical fix is to delete the honeypot. Circle’s Cross-Chain Transfer Protocol moves native USDC by burning it on one chain and minting it on another, with no locked pool of IOUs sitting in a bridge contract waiting to be drained. A bridge that holds nothing cannot be emptied. And for the aftermath, the Security Alliance’s Safe Harbor framework tries to give genuine white-hats a legal path to intervene and claim a capped bounty, so that rescuing funds does not itself look like theft. None of these defenses touches the contract audit. Every one of them addresses the layer the audit never saw.

Off-chain layerHow it failsHow 2026 bridges harden it
Signing keysStolen or blind-signed (Ronin, Bybit)MPC and HSM custody, distributed signers, clear-signing
Off-chain verifiersCorrupted to report false events (KelpDAO)Several independent verifiers, separate monitoring networks
Federation or operatorSigns a forgery, or one party collapses (Liquid, Multichain)Genuine distribution of control, diverse client software
Admin and upgrade keysCompromised to rewrite the contract (Drift)Timelocks, security councils, minimal admin surface, token rate limits
Front-end and supply chainMalicious script or domain hijack (BadgerDAO)Clear-signing, integrity checks, hardened hosting, monitoring

The market is already repricing off-chain trust

Most users cannot audit a relayer’s server or inspect a federation’s key-management policy. So they are doing the only thing they can: voting with their assets. In the months after the KelpDAO exploit, more than $7.2 billion in assets migrated away from LayerZero toward Chainlink’s CCIP, according to CoinDesk, with the Bitcoin staking protocol Lombard moving more than $1 billion, Solv shifting about $700 million in tokenized Bitcoin, and Kraken making CCIP the exclusive provider for its wrapped Bitcoin. Johann Eid, chief business officer at Chainlink Labs, described it as “a continued flight to safety across the industry.”

Read carefully, that migration is a verdict on the off-chain layer, not on anyone’s contract code. Issuers moved because they judged one messaging stack’s operational and verifier security to be stronger than another’s, which is exactly the judgment an audit cannot make for them. The irony is that a flight to safety creates its own risk. If a large share of cross-chain value ends up riding a single provider, that provider becomes the next great honeypot, and the concentration that feels safe today is the systemic single point of failure tomorrow. Buterin’s warning about zones of sovereignty cuts both ways: you cannot abolish bridge risk, you can only decide who carries it and how widely it is spread.

How to read a bridge’s off-chain security

If the real risk is off-chain and you cannot personally audit a verifier’s servers, what can you actually check before trusting a bridge with your money? More than you might think. The off-chain layer leaves visible fingerprints, and a handful of questions will tell you most of what you need to know.

  • How many independent verifiers must agree, and who runs them? A single verifier, or a default 1-of-1 setup, is the configuration that cost KelpDAO $292 million. You want several, operated by different parties.
  • Who holds the admin and upgrade keys? Look for a timelock that delays upgrades and a security council that can freeze in an emergency. An instant, unilateral upgrade key is a loaded gun.
  • Is there a rate limit? A per-bridge or per-token cap on minting means one bad day cannot drain everything at once.
  • Does it sit on a giant locked pool, or use native issuance? Burn-and-mint designs and small balances are far less tempting targets than a billion-dollar honeypot.
  • What is the incident history? Has the team been hit before, and if so did it pause quickly, disclose honestly, and make users whole, or did it go quiet?
  • Can you confirm the real website and read what you sign? Bookmark the official domain, treat links from direct messages and ads as hostile, and prefer bridges and wallets that support clear-signing over an unreadable blob.

None of these questions appears in an audit summary, and every one of them probes the layer that actually fails. Use them as a rough scorecard.

Green flagsRed flags
Several independent verifiers, at least one not run by the core teamA single verifier or a 1-of-1 default
Upgrade keys behind a timelock and a security councilAn instant upgrade key held by a small or anonymous group
Per-bridge or per-token rate limitsNo cap, so one exploit can mint or drain everything
Native burn-and-mint or small locked balancesA large locked pool backing wrapped IOUs
Public incident history, fast pauses, users made wholeSilence after past incidents, or no disclosure policy
Verifiable official domain, clear-signing supportedBlind-signing required, links arriving via DMs or ads

Why the SEC cannot refund you

When a bridge is drained, the instinct is to ask who will make it right. In traditional finance the answer is a web of insurance and chargebacks: a bank deposit carries federal insurance, a fraudulent card charge gets reversed. Cross-chain crypto has none of that. There is no deposit insurance, no chargeback, and no customer-service line that can claw your tokens back.

The United States market regulator is not a backstop either. The Securities and Exchange Commission polices securities, and in 2026 it and the Commodity Futures Trading Commission jointly signaled that most crypto assets are not securities at all, which narrows rather than widens who has clear jurisdiction over a bridged token. Even when the SEC or the Justice Department does act, it acts after the fact and on behalf of the public, pursuing enforcement and the occasional asset seizure, not issuing refunds to individual victims on request. The agency is also stretched thin: HOGE Wire has written about the two-person SEC operating through a government shutdown, hardly a body positioned to chase down every drained bridge.

In practice, recovery comes from the ecosystem, not the state. KelpDAO’s users were made whole by a coalition of protocols that recapitalized the shortfall; Liquid’s funds came back because the attackers chose to return most of them; the Arbitrum Security Council froze what it could reach. Those are discretionary acts, not legal guarantees. The uncomfortable bottom line is the same one that applies to chasing the wrong token listings: on a bridge, the losses stick, and you are your own backstop. That is reason enough to treat the off-chain questions above as seriously as any advertised yield.

The bottom line

Cross-chain bridges did not become safe in 2026. They became better understood. A decade of audits, formal verification, and bug bounties hardened the one layer everyone could see, the smart contract, and attackers responded by going after everything else: the keys, the verifier servers, the federations, the admin controls, and the websites. TRM’s data is the whole story in a single statistic, roughly 76 percent of stolen value coming from the off-chain layer that makes up only about 15 percent of incidents. The contract is the part with the certificate. It is not the part that fails.

The fixes that matter are the ones aimed at that unaudited layer: several independent verifiers, hardware-backed key custody, timelocks and security councils over admin keys, rate limits that cap the blast radius, and native issuance that deletes the honeypot entirely. The market is already paying up for them. The move left to an individual user is to ask the off-chain questions, because the audit will not ask them for you, and the regulator will not refund you if the answer turns out to be wrong. A bridge is only ever as strong as the weakest machine, and the weakest person, standing behind the contract.

Frequently Asked Questions

Why do crypto bridges keep getting hacked?

Because the part of a bridge that gets attacked is usually not the smart contract, which is audited, but the off-chain layer around it: the signing keys, the relayers and verifiers that report cross-chain events, the admin keys that can change the contract, and the website. In the first half of 2026, infrastructure and operational compromises caused roughly 76 percent of stolen value while being only about 15 percent of incidents, according to TRM Labs.

Does a security audit mean a bridge is safe?

No. An audit certifies the on-chain code at a point in time. It generally does not cover key management, verifier and relayer infrastructure, admin-key governance, or the front-end website, which is where most large bridge losses in 2026 actually happened. A bridge can pass a clean audit and still be drained through the layer the audit never examined.

What was the biggest bridge hack, and how did it happen?

The Ronin Network bridge remains the largest, with about $625 million stolen in 2022 after attackers compromised five of its nine validator signing keys. It was not a contract bug; the bridge released funds against signatures that were valid by its own rules, which is the recurring pattern behind the biggest losses.

Can I get my money back if a bridge I used is hacked?

Usually not through any official channel. There is no deposit insurance or chargeback for cross-chain crypto, and the SEC pursues enforcement rather than refunding individual victims. When funds do come back, it is because a protocol coalition recapitalized the loss, attackers returned funds, or a security council froze assets, all discretionary acts rather than guarantees.

What is the safest way to bridge crypto?

Prefer bridges that use several independent verifiers rather than a single one, that keep admin and upgrade keys behind timelocks and rate limits, and that use native burn-and-mint issuance instead of a large locked pool. Confirm the official website, read what your wallet asks you to sign, and move large amounts in smaller test transactions first.

By Yuki Tanaka, HOGE Wire.

Share 𝕏 Post Telegram