← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[COMPARATIVE ANALYSIS] Cross-Chain Bridges Bleed $2.8B as Exploits Accelerate

Zephyra|July 21, 2026|BPF
EXECUTIVE SUMMARY

Cross-chain bridge exploits have drained an estimated $2.8 billion since 2022, accounting for roughly 40% of all Web3 security losses. The problem is accelerating: in the first seven months of 2026 alone, bridge-related incidents have exceeded $340 million, led by the $292 million Kelp DAO exploi...

"The entire drain took about 12 minutes." — Chainalysis, post-mortem analysis of the Drift Protocol exploit (April 2026)

Executive Summary

Cross-chain bridge exploits have drained an estimated $2.8 billion since 2022, accounting for roughly 40% of all Web3 security losses. The problem is accelerating: in the first seven months of 2026 alone, bridge-related incidents have exceeded $340 million, led by the $292 million Kelp DAO exploit and the $285 million Drift Protocol drain. Two more exploits landed in the past 72 hours — a $10 million Wanchain-Cardano bridge breach and a $1.65 million Allbridge Core flash loan attack — demonstrating that the attack surface remains wide open despite years of post-mortems.

Bridge TVL stood at $21.94 billion as of March 2026, per DefiLlama. That figure represents a concentrated honeypot: bridges hold large pools of assets in single-chain smart contracts to back transfers across blockchains, and any pricing or verification flaw is immediately exploitable at scale. In May 2026, bridges accounted for 42% of the month's total exploit losses ($28.6 million of $70 million) while representing fewer than 5% of monitored DeFi protocols by count, according to Immunefi data.

The attack vectors are evolving. The two largest incidents of 2026 did not rely on smart contract bugs. They exploited off-chain infrastructure — compromised RPC nodes, social engineering of key holders, and single-point-of-failure verification setups. This pattern suggests the industry's security model, which remains focused on contract-level audits, is misaligned with the actual threat surface.

Table of Contents

  1. 72 Hours, Two Bridges Down
  2. 2026 Bridge Exploit Ledger
  3. Attack Vector Taxonomy
  4. The Economic Arithmetic of Bridge Security
  5. Emerging Defenses: ZK Proofs and Intent-Based Architectures
  6. Key Takeaways
  7. Conclusion
  8. Sources & References

72 Hours, Two Bridges Down

Wanchain-Cardano Bridge — July 20, 2026: An attacker exploited a signed-message encoding flaw in the TreasuryCheck validator to drain 515.2 million NIGHT tokens (approximately $9–10 million) from the Wanchain bridge connecting Cardano to BNB Chain. The vulnerability stemmed from raw concatenation of 14 variable-length redemption fields without delimiters, allowing different field combinations to produce identical byte strings and reuse the same hash and signature. The attack executed in four transactions over eight minutes, between 14:46 UTC and 14:55 UTC. The attacker liquidated approximately 90% of stolen tokens through DEX swaps before seven exchanges — Binance, OKX, Kraken, KuCoin, Bybit, Gate, and MEXC — froze remaining funds. NIGHT's price dropped 30–35% in the hours following the incident. The Midnight Foundation confirmed the core Midnight network was unaffected, attributing the breach entirely to third-party bridge infrastructure.

Allbridge Core — July 19, 2026: A hacker used a $1.12 million USDC flash loan from Kamino to manipulate Allbridge Core's Solana stablecoin pool, distorting USDC/USDT ratios through rapid swaps before withdrawing liquidity at inflated values. Total drain: approximately $1.65 million. The stolen funds were routed through privacy protocols. This was Allbridge Core's second flash loan exploit — the first occurred in April 2023 on BNB Chain ($573,000). According to TechTimes, the fix Allbridge applied after 2023 addressed BNB Chain pools but missed Solana, leaving the same attack vector open for over three years. The protocol was paused, and Allbridge asked traders who profited from the imbalance to return funds.

2026 Bridge Exploit Ledger

The following table compiles the major bridge-related exploits reported in 2026 through July 21, based on data from PeckShield, Chainalysis, and on-chain tracking.

| Date | Protocol | Loss | Attack Method | Chain(s) | |------|----------|------|---------------|----------| | Apr 19 | Kelp DAO (LayerZero) | $292M | RPC node compromise, single-verifier bypass | Multi-chain (20+) | | Apr 1 | Drift Protocol | $285M | Social engineering, governance exploit | Solana | | May 18 | Verus-Ethereum Bridge | $11.58M | Forged Merkle proof, validation gap | Ethereum | | Jul 20 | Wanchain-Cardano | ~$10M | Signature encoding flaw | Cardano/BNB Chain | | Feb 21 | IoTeX ioTube | $4.4M | Bridge private key compromise | Ethereum | | Feb | CrossCurve | $3M | Bridge validation failure | Multi-chain | | Feb | Hyperbridge | $2.5M | Bridge exploit | Multi-chain | | Jul 19 | Allbridge Core | $1.65M | Flash loan pool manipulation | Solana |

Cumulative 2026 bridge losses through July 21: approximately $610 million.

For context: PeckShield tracked eight major bridge exploits through May alone, totaling $328.6 million. The July incidents push the running total past $340 million even excluding the Kelp DAO and Drift incidents, which some analysts classify as protocol-level rather than pure bridge exploits.

Attack Vector Taxonomy

The 2026 data reveals a shift in how bridges are attacked. Traditional smart contract vulnerabilities are no longer the primary vector.

1. Off-Chain Infrastructure Compromise The two largest exploits of 2026 targeted off-chain systems, not on-chain contracts. In the Kelp DAO incident, attackers compromised internal RPC nodes and DDoS'd external nodes to feed false data to a single-verifier DVN (Decentralized Verification Network) setup. LayerZero's post-mortem attributed the attack "with preliminary confidence" to North Korea's Lazarus Group. In the Drift Protocol attack, TRM Labs reported that Lazarus-linked operatives spent approximately six months building relationships with the Drift team, then used Solana's "durable nonces" feature to get Security Council members to unknowingly pre-sign transactions granting admin control.

2. Message Encoding and Validation Flaws The Wanchain-Cardano exploit exemplifies a class of vulnerability where bridge message formats lack structural integrity. The raw concatenation of variable-length fields without delimiters or length prefixes is a known anti-pattern in protocol design. The Verus-Ethereum hack followed a similar pattern: both sides of the bridge performed validation, but neither validated that the input amount on Verus matched the payout amount on Ethereum. According to Halborn's post-mortem, the attacker forged a Merkle proof to drain 1,625 ETH, 147,659 USDC, and 103.57 tBTC.

3. Flash Loan and Liquidity Manipulation The Allbridge Core exploit demonstrates that older attack vectors remain viable when fixes are applied inconsistently across chains. The protocol patched its BNB Chain pools after a 2023 exploit but left identical Solana pools vulnerable for over three years.

4. Private Key Compromise IoTeX's ioTube bridge lost $4.4 million through compromised private keys in February. This vector has been persistent since the Ronin Bridge's $624 million loss in 2022, where attackers obtained five of nine validator keys.

The Economic Arithmetic of Bridge Security

Bridge security fails a basic economic test. IC3 researchers have documented that bridge validator systems become economically insecure when the cost of corrupting the validator set falls below the value of assets the bridge secures. A 19-of-21 multisig securing $500 million with only $5 million in slashable stake is, by this measure, less secure than a 3-of-5 multisig securing $1 million with $10 million per validator.

The numbers are stark:

  • Bridge TVL (March 2026): $21.94 billion across all protocols, per DefiLlama
  • Monthly bridge flows: regularly exceed $10 billion across major corridors
  • Attack concentration: bridges represent fewer than 5% of monitored DeFi protocols but account for 40% of cumulative losses since 2022
  • Bug bounty ceiling: Wormhole and LayerZero offer up to $2.5 million for critical vulnerabilities — less than 1% of the $292 million drained from Kelp DAO alone
  • Detection gap: Ronin's $624 million exploit went undetected for five days in 2022; Kelp DAO's $292 million drain ran for 46 minutes before emergency pause

The Kelp DAO incident exposed a specific structural risk. LayerZero disputed responsibility, stating Kelp used a 1-of-1 DVN configuration that went against its recommended multi-verifier model. Kelp countered that it followed LayerZero's documentation and default configurations, and that the single-verifier setup was widely used across the ecosystem. Following the incident, $6 billion in TVL was withdrawn from Aave, according to Phemex data — collateral damage extending well beyond the directly exploited protocol. Kelp subsequently announced plans to switch to Chainlink for bridge verification, per Yahoo Finance reporting.

Emerging Defenses: ZK Proofs and Intent-Based Architectures

Two architectural alternatives are in various stages of deployment.

Zero-Knowledge Bridges replace trusted intermediaries with cryptographic proofs. The destination chain verifies source chain state through validity proofs (zk-SNARKs or zk-STARKs) without trusting any relay, oracle, or validator set. The economic argument: ZK proofs eliminate the "corruptible validator" attack surface entirely. In 2025, ZK proof generation costs fell by 45x, according to Ingonyama research. If a similar cost trajectory continues, proof generation could fall below $0.001 per proof in 2026, making trust-minimized bridging economically viable at scale. However, ZK bridges remain largely experimental. No ZK bridge currently secures assets at the scale of Wormhole or LayerZero.

Intent-Based Bridging inverts the bridge model. Users declare a desired outcome ("swap X for Y across chains"), and a solver network executes the transfer. ZK proofs verify the solver completed the intent correctly. This design eliminates the large custodial pools that make traditional bridges attractive targets. However, an academic paper from Cornell (arXiv: 2602.17805) documented "liquidity exhaustion attacks" against intent-based bridges, suggesting the model introduces its own class of economic vulnerabilities.

Neither solution has been tested at the scale where the largest exploits occur ($100M+). The transition from lock-and-mint architectures to trust-minimized alternatives remains a multi-year project.

Key Takeaways

  • $2.8 billion in cumulative bridge exploit losses since 2022. Bridges account for ~40% of all Web3 security losses while representing <5% of protocols.
  • Two exploits in 72 hours (Wanchain, $10M; Allbridge, $1.65M) landed in July 2026, bringing 2026 bridge losses past $340 million (excluding Kelp DAO and Drift, which some classify differently).
  • Off-chain infrastructure is the primary attack surface in 2026. The two largest exploits ($292M and $285M) bypassed smart contracts entirely through RPC compromise and social engineering.
  • Bug bounties are structurally misaligned: maximum payouts ($2.5M) represent <1% of the assets at risk, providing insufficient economic incentive for white-hat disclosure relative to exploit value.
  • The validator economics problem remains unsolved. Most bridges secure hundreds of millions of dollars with validator stakes orders of magnitude smaller than the assets they protect.
  • ZK bridges and intent-based architectures offer theoretical fixes but have not been deployed at the scale ($100M+ TVL) where the largest attacks occur.
  • State-sponsored actors (Lazarus Group) are attributed to at least two of the three largest incidents ($292M Kelp DAO, $285M Drift), per TRM Labs and LayerZero post-mortems.

Conclusion

Cross-chain bridges occupy an unusual position in DeFi infrastructure: they are simultaneously among the most economically critical protocols (enabling multi-chain capital flow) and the most consistently exploited. The data shows no sustained improvement in the loss trajectory. Annual losses have fluctuated between $1.7 billion and $3.8 billion since 2022, and 2026 is tracking toward the upper end of that range.

The industry's defensive posture — focused on smart contract audits, bug bounties, and post-incident multisig freezes — is mismatched with the actual attack surface. The Kelp DAO, Drift, and Wanchain incidents exploited off-chain infrastructure, social engineering, and message encoding flaws that fall outside the scope of standard contract audits. Until bridge security budgets, bounty programs, and architectural designs are calibrated to the $21.94 billion in TVL these protocols secure, the exploit trajectory is unlikely to change.

Sources & References

  1. Wanchain Cardano Bridge Exploited, Hackers Stole $10M in NIGHT Tokens — CryptoTimes, July 21, 2026
  2. Allbridge Core pauses protocol after $1.65 million flash loan exploit — The Block, July 2026
  3. Allbridge Core Loses $1.65M to Flash Loan Again After Its Single-Pool Fix Missed Solana — TechTimes, July 20, 2026
  4. Kelp DAO Bridge Exploit Drains $292 Million in rsETH Across 20+ Chains — Technology.org, April 21, 2026
  5. LayerZero Links $292 Million Kelp DAO Bridge Exploit to North Korea's Lazarus Group — Unchained, 2026
  6. LayerZero Details Single-Verifier Flaw Behind $292M KelpDAO Exploit — CryptoTimes, May 20, 2026
  7. Kelp Blames LayerZero for $292 Million Hack, Plans Switch to Chainlink — Yahoo Finance, 2026
  8. North Korean Hackers Attack Drift Protocol In USD 285 Million Heist — TRM Labs, 2026
  9. Drift Protocol Hack: How Privileged Access Led to a $285M Loss — Chainalysis, 2026
  10. Verus-Ethereum bridge loses $11 million — CoinDesk, May 18, 2026
  11. Explained: The Verus-Ethereum Bridge Hack (May 2026) — Halborn, May 2026
  12. PeckShield: Eight Cross-Chain Bridge Exploits Drained $328.6M in May 2026 — BingX/PeckShield, May 2026
  13. Cross-Chain Bridges Keep Getting Drained — Yellow Network Research, 2026
  14. Every Major DeFi Hack in 2026 So Far — Phemex, 2026
  15. Exploiting Liquidity Exhaustion Attacks in Intent-Based Cross-Chain Bridges — Cornell/arXiv, February 2026
  16. Inside the KelpDAO Bridge Exploit — Chainalysis, April 2026