Cross-chain bridge protocols have hemorrhaged more than $400 million to exploits in the first seven months of 2026, according to data compiled from PeckShield, Immunefi, and Chainalysis incident trackers. The figure includes at least 16 distinct bridge-targeting attacks — the highest count in any...
"The root cause was that, while both sides of the cross-chain bridge performed validation, neither was required to validate a crucial field." — Halborn Security, Post-mortem of the Verus-Ethereum Bridge Hack (May 2026)
Cross-chain bridge protocols have hemorrhaged more than $400 million to exploits in the first seven months of 2026, according to data compiled from PeckShield, Immunefi, and Chainalysis incident trackers. The figure includes at least 16 distinct bridge-targeting attacks — the highest count in any comparable period since bridges emerged as critical DeFi infrastructure in 2021. Bridges now account for approximately 42% of all crypto exploit losses in 2026, despite holding a small fraction of total DeFi value locked.
The concentration of losses is striking. Two incidents alone — the $292 million Kelp DAO LayerZero bridge exploit on April 18 and the $285 million Drift Protocol breach on April 1 — account for roughly 72% of the year's bridge-related damage. Both attacks were attributed to North Korea's Lazarus Group by Chainalysis and LayerZero's post-mortem teams. July 2026 has added another $97 million in hack losses across 14 separate incidents, with bridge exploits at AFX Trade ($24.15 million), Verus ($7.54 million), Wanchain ($10 million), and Allbridge ($1.66 million) contributing a significant share.
The pattern is clear: bridges remain the highest-value, lowest-security targets in the DeFi stack. The economic dynamics are straightforward — bridges pool large reserves of liquid assets on one chain to back wrapped representations on another, creating honeypots that are orders of magnitude more attractive than individual lending pools or DEX contracts.
The following table catalogues the major bridge-targeting exploits recorded in 2026, in chronological order:
| Date | Protocol | Loss | Attack Vector | |------|----------|------|--------------| | Apr 1 | Drift Protocol (Solana) | $285M | Governance/vault exploit | | Apr 18 | Kelp DAO / LayerZero | $292M | Off-chain RPC node compromise | | May 17 | Verus-Ethereum Bridge | $11.6M | Input validation failure | | May 30 | Gravity Bridge (Cosmos-ETH) | $5.4M | Signing key compromise | | Jun 2026 | Multiple (PeckShield aggregate) | $328.6M cumulative by month-end | Various | | Jul 6 | Summer.fi (Lazy Summer vaults) | $6M | Flash loan accounting manipulation | | Jul 17 | Across Protocol (Solana deployment) | $0 (relayer loss only) | Spoofed deposit signals | | Jul 19 | Allbridge Core | $1.66M | Flash loan swap logic exploit | | Jul 21 | Wanchain Cardano Bridge | $10M | Bridge exploit, DEX liquidation | | Jul 22 | AFX Trade (Arbitrum) | $24.15M | Validator private key compromise | | Jul 23 | Verus-Ethereum Bridge (2nd exploit) | $7.54M | Same vulnerability as May |
Cumulative bridge-related losses through late July 2026 exceed $400 million. The broader DeFi hack total — including non-bridge exploits — reached $972 million across 207 incidents in H1 2026 alone, according to Immunefi. That is the highest incident count ever recorded for a six-month period, though the dollar total remains below the $1 billion mark and under half the H1 2025 figure.
The Kelp DAO exploit stands as 2026's single largest DeFi loss. The attack targeted Kelp's rsETH (re-staked ETH) cross-chain bridge built on LayerZero's messaging infrastructure. The attacker did not exploit a smart contract bug. Instead, the operation compromised Kelp's internal RPC nodes while simultaneously DDoS-attacking external nodes, feeding false data to a single-point-of-failure verification network.
According to Chainalysis, the attacker's mixer usage patterns and fund-dispersal methodology matched the operational fingerprint of North Korea's Lazarus Group, specifically its TraderTraitor subunit. Attribution was completed within three days of the breach.
The root cause, per LayerZero's post-mortem, was Kelp's decision to deploy a 1-of-1 DVN (Decentralized Verifier Network) configuration — effectively trusting a single verification endpoint. LayerZero stated it had previously warned Kelp to adopt a multi-verifier setup. Kelp's emergency multisig paused core contracts 46 minutes after the drain began. By then, 116,500 unbacked rsETH had been minted and converted.
The exploit triggered $13 billion in withdrawals from connected protocols over two days. Aave launched "DeFi United," an inter-protocol relief fund — the first of its kind at that scale.
Drift's breach on Solana drained approximately $285 million from its vaults in twelve minutes. This attack exploited governance structures around the DeFi application rather than a direct code vulnerability. Chainalysis attributed the attack to North Korean threat actors.
Combined, these two Lazarus-linked incidents represent $577 million — more than the entirety of bridge exploit losses in any previous calendar year except 2022.
Between July 19 and July 23, four separate bridge protocols were exploited for a combined $43.35 million:
Allbridge Core (July 19): $1.66 million drained via a flash loan attack that exploited swap logic in the protocol's Solana liquidity pools.
Wanchain Cardano Bridge (July 21): $10 million in NIGHT tokens extracted. The attacker funneled stolen tokens into a primary Cardano wallet and aggressively liquidated roughly 90% through DEX swaps.
AFX Trade (July 22): $24.15 million in USDC drained from the protocol's Arbitrum custodial bridge. According to security firm Blockaid, hackers obtained private keys from five of AFX's bridge validators, reaching the signing quorum needed to authorize withdrawals. The funds were converted into approximately 12,467.5 ETH and consolidated in a single wallet. AFX offered the attacker a 30% bounty for return of funds — a practice that has become standard in post-exploit negotiations.
Verus-Ethereum Bridge (July 23): $7.54 million stolen in what was the protocol's second exploit in 66 days. According to analysis by Halborn, the attacker used the same contract, the same entry path, and the same vulnerability class as the May 17 exploit, which had drained $11.6 million. A different attacker operated from a new wallet. Verus's total bridge losses in 2026 now stand at $19.1 million.
The Verus case is notable for demonstrating that patching a bridge exploit does not guarantee the underlying vulnerability class has been eliminated. The May exploit succeeded because neither side of the bridge validated a crucial field — the input amount on Verus was not checked against the payout amount on Ethereum, allowing an attacker to submit $0.01 in inputs and receive millions in outputs. The July attacker exploited the same import path, suggesting the fix addressed symptoms rather than the root cause.
Bridge protocols concentrate risk in three structural ways:
1. Honeypot Economics. Bridges must hold or have access to pooled reserves backing wrapped tokens across multiple chains. A successful exploit can drain the entire reserve in a single transaction. This makes bridges the highest-value targets in DeFi — they represented 42% of all crypto exploit losses in 2026 despite holding a fraction of total TVL, according to PeckShield data from May 2026.
2. Off-Chain Attack Surface. The Kelp DAO exploit was not a smart contract hack. It targeted RPC nodes, DDoS infrastructure, and a misconfigured verification network. Traditional smart contract audits do not cover these vectors. The Gravity Bridge exploit in May involved signing key compromise. AFX Trade in July involved validator private key theft. These are infrastructure-level failures that exist outside the auditability boundary of on-chain code.
3. Cross-Domain Validation Gaps. Bridges must verify state across two or more independent consensus systems. The Verus exploit exploited the gap between what the Verus chain validated and what the Ethereum contract accepted. The Across Protocol attack on Solana in July exploited gaps in Solana's event system to spoof deposit signals. Each chain boundary creates a new surface where assumptions on one side may not hold on the other.
Bridge TVL stood at approximately $45 billion in mid-2026 before declining below that threshold following the June-July incident cluster, according to DefiLlama. Intent-based bridges like Across and deBridge operate with near-zero TVL by design — operators front funds without custody — representing an architectural response to the honeypot problem, though they introduce different risk vectors around relayer solvency.
The bridge security market has stratified into distinct tiers based on verification architecture:
Tier 1: Decentralized Oracle Networks. Chainlink's CCIP uses a defense-in-depth model with decentralized oracle networks, multiple independent risk management networks, and built-in rate limiting. No core protocol exploit to date. Enterprise deployments include ANZ Bank, BNY Mellon, and BlackRock. Kraken adopted CCIP as its cross-chain standard in May 2026, replacing LayerZero, citing security prioritization. CCIP supports more than 25 chains and processes tens of millions in daily cross-chain value.
Tier 2: Configurable Verifier Models. LayerZero offers a modular model where each application selects its own DVN set and security threshold. This provides flexibility but shifts security responsibility to deployers. The Kelp DAO exploit was caused by a 1-of-1 DVN configuration that LayerZero had warned against. The core protocol has not been exploited, but application-level misconfiguration has produced the year's largest single loss.
Tier 3: Fixed Validator Committees. Wormhole and similar designs rely on fixed sets of guardians. Wormhole has processed more than $65 billion in lifetime volume but carries the legacy of its $326 million exploit in 2022. Recent integrations have focused on Solana ecosystem depth.
Tier 4: Emerging ZK-Based Verification. Zero-knowledge proof bridges aim to verify source-chain state cryptographically on the destination chain, eliminating trust in intermediaries. Polyhedra's zkBridge and similar projects are in development, but computational bottlenecks — particularly large circuit sizes — have limited production deployment. Hardware acceleration and SNARK-specific optimizations are the primary research vectors.
Of the $400 million-plus lost to bridge exploits in 2026, recovery rates remain poor. The structural barriers are well-documented:
Stolen funds from the Kelp DAO exploit were dispersed through mixers matching Lazarus Group's known methodology. The Gravity Bridge attacker moved $2.1 million through Tornado Cash and routed additional funds through ChangeNow and Binance. The AFX Trade attacker consolidated 12,467.5 ETH in a single wallet but laundering operations typically begin within hours.
Law enforcement faces jurisdictional complexity. Bridge validator operators span multiple countries. Decentralized governance structures mean no single entity controls the exploited contracts. Four exchanges froze accounts linked to a separate $127 million bridge exploit in June 2026, recovering approximately $8 million — a 6.3% recovery rate.
Immunefi's bug bounty platform paid researchers $13.45 million in H1 2026 to surface 837 valid bugs before exploitation. The economic comparison is stark: the industry spent $13.45 million on pre-exploit defense while losing $972 million to successful attacks — a ratio of roughly 1:72.
Cross-chain bridge exploits have exceeded $400 million in losses through July 2026, driven by two Lazarus Group-attributed attacks totaling $577 million combined (Kelp DAO: $292M, Drift: $285M).
Bridges account for 42% of all crypto exploit losses while holding a fraction of DeFi TVL, confirming their status as disproportionately targeted infrastructure.
July 2026 alone has seen $97 million in total crypto hack losses across 14 incidents, with four bridge exploits in a ten-day span contributing $43.35 million.
The Verus-Ethereum bridge was exploited twice in 66 days using the same vulnerability class, demonstrating that post-exploit patches do not always address root causes.
Immunefi recorded 207 hack incidents in H1 2026 — the highest six-month count on record — though total dollar losses ($972M) remained below H1 2025 levels, indicating attacks are more frequent but individually smaller.
Smart contract audits are insufficient; the year's largest exploits targeted off-chain infrastructure (RPC nodes, validator keys, governance mechanisms) that sits outside traditional audit scope.
Bug bounty spending ($13.45M in H1 2026) remains at roughly 1:72 ratio to actual exploit losses ($972M), suggesting systematic underinvestment in pre-exploit defense.
Intent-based bridge designs (Across, deBridge) eliminate the pooled-reserve honeypot but introduce relayer solvency risk — a trade-off, not a solution.
The data from 2026 confirms that cross-chain bridges remain the most economically significant vulnerability in DeFi infrastructure. The problem is structural, not incidental. Bridges concentrate large pools of liquid assets, introduce cross-domain validation gaps that are difficult to audit, and present off-chain attack surfaces that traditional security reviews do not cover.
The market is responding through architectural stratification. Enterprise-grade deployments are consolidating around oracle-network models (CCIP) with defense-in-depth. Configurable models (LayerZero) offer flexibility but create risk when deployers choose weak configurations. ZK-based bridges promise cryptographic verification but remain computationally constrained for production use.
The economic incentives remain misaligned. Bridge TVL creates concentrated targets worth hundreds of millions. Security spending through bug bounties covers a fraction of the loss surface. And the fund recovery infrastructure — spanning jurisdictional boundaries, mixer services, and decentralized governance — recovers single-digit percentages of stolen assets.
Until the bridge security stack catches up with the value it secures, the exploit pattern documented in this report will continue. The question is not whether more bridges will be exploited, but which verification architecture minimizes the blast radius when they are.