Cross-chain bridges remain the most attacked infrastructure layer in crypto, with over $2.8 billion lost to exploits since 2022 and a fresh $3 million hack hitting CrossCurve on February 2, 2026 — using the same class of vulnerability that drained Nomad four years ago. Yet bridges are also the fa...
"I cannot believe nothing has changed in four years." — A security researcher commenting on the CrossCurve bridge exploit, comparing it to Nomad's 2022 hack
Cross-chain bridges remain the most attacked infrastructure layer in crypto, with over $2.8 billion lost to exploits since 2022 and a fresh $3 million hack hitting CrossCurve on February 2, 2026 — using the same class of vulnerability that drained Nomad four years ago. Yet bridges are also the fastest-growing infrastructure category, processing $18.8 billion in monthly volume and underpinning a blockchain interoperability market projected to grow from $910 million in 2025 to $7.8 billion by 2033 at a 25.4% CAGR.
The paradox is structural: the multi-chain world demands bridges, but the dominant bridge architecture — lock-and-mint with validator committees — remains fundamentally brittle. What's changing is the emergence of intent-based bridging, a new paradigm where users declare what they want and competitive relayers race to fill orders, eliminating the need to trust a single validation pathway. ERC-7683, co-authored by Uniswap Labs and Across Protocol, is codifying this approach into an Ethereum standard. Meanwhile, Chainlink's CCIP is positioning as the institutional-grade alternative, and deBridge just launched AI-agent execution across 24 blockchains. The bridge wars have entered a new phase — and the economic stakes are enormous.
Since 2022, cross-chain bridges have accounted for approximately 40% of all Web3 security incidents by dollar value. The damage is staggering: $2 billion stolen in 2022 alone across 13 separate bridge exploits, representing 69% of all crypto funds stolen that year. The pattern has continued through 2023, 2024, and into 2026, with cumulative bridge-related losses exceeding $2.8 billion.
The root cause is architectural. Traditional bridges operate on a lock-and-mint model: assets are locked on the source chain, and corresponding wrapped tokens are minted on the destination chain. Security depends entirely on the bridge's validator set or multi-signature committee correctly attesting that the lock actually occurred. When that validation layer fails — through compromised private keys, spoofed messages, or logic bugs — attackers can mint unbacked tokens and drain liquidity pools.
The attack surface is inherently larger than single-chain protocols because bridges must maintain correct state across two or more independent consensus systems. Every additional chain multiplies the potential failure points. As Chainalysis documented in its seminal 2022 analysis, bridges represent a "systemically important" vulnerability in crypto infrastructure — a single point of failure connecting otherwise independent economic systems.
Despite four years of exploit history, the fundamental vulnerability class persists. The CrossCurve hack in February 2026 proved that lesson remains unlearned.
On February 2, 2026, CrossCurve — a cross-chain DEX built in partnership with Curve Finance, formerly known as EYWA Protocol — was exploited for approximately $3 million across multiple chains. The attack vector was a missing access control check in the protocol's ReceiverAxelar contract that allowed anyone to call the expressExecute function with a spoofed cross-chain message.
The technical details are damning. CrossCurve's smart contract was designed to receive messages routed through Axelar's cross-chain gateway. But the contract failed to verify that incoming messages actually originated from the Axelar gateway. An attacker could simply call the function directly, passing fabricated message data, and the contract would process it as if it were a legitimate cross-chain transfer — triggering unauthorized token unlocks from the PortalV2 contract.
Security firm Halborn, which published a detailed post-mortem, noted the vulnerability was "reminiscent of Nomad's $190 million bridge exploit in 2022." In both cases, the core failure was identical: insufficient validation of cross-chain message authenticity. CrossCurve's CEO Boris Povar identified ten Ethereum addresses that received the stolen funds and offered a 10% bounty for return within 72 hours.
The CrossCurve exploit crystallizes a broader truth: the lock-and-mint bridge model carries inherent risk that no amount of auditing fully eliminates. The attack surface is the validation layer itself — and when that layer depends on a single contract correctly implementing access controls, one developer's oversight can drain millions.
The most significant architectural response to bridge fragility is the rise of intent-based bridging. Rather than routing assets through a single validation pathway, intent-based systems allow users to express what they want — "move 100 USDC from Arbitrum to Base" — and competitive market makers (called "relayers" or "fillers") race to execute the order.
The key innovation is risk transfer. In a traditional bridge, the user bears the risk of the bridge's security model. In an intent-based system, the relayer assumes finality risk by fronting capital on the destination chain before the source-chain transaction is fully confirmed. The relayer is later reimbursed through a settlement layer. If the relayer fills an order incorrectly, they lose their own capital — not the user's.
ERC-7683, co-authored by Uniswap Labs and Across Protocol, is the standard codifying this model for Ethereum. It defines a universal format for expressing cross-chain intents, enabling any compliant application to submit orders that any compliant relayer can fill. The standard has gained significant traction: the Ethereum Foundation launched the Open Intents Framework (OIF) in February 2025, supported by over 30 teams including Arbitrum, Optimism, Polygon, and zkSync.
Across Protocol, the leading intent-based bridge, has processed over $28 billion in cumulative bridged volume with zero security exploits. Its V4 architecture, launched in July 2025, uses zero-knowledge proofs for settlement and can onboard new chains in hours rather than weeks. L2-to-L2 transfers complete in as little as 2-3 seconds.
The economic model is also superior. Traditional bridges charge 0.1-0.3% plus gas fees. Intent-based systems create price competition among relayers, driving fees lower. More importantly, the competitive market structure means no single entity holds all user funds — dramatically reducing the blast radius of any single failure.
Three developments in the past three months are reshaping the bridge landscape:
1. Chainlink CCIP Goes Cross-Ecosystem
In December 2025, Coinbase and Chainlink launched the Base-Solana bridge, the first production deployment connecting an EVM Layer 2 with a non-EVM Layer 1 through CCIP (Cross-Chain Interoperability Protocol). The bridge uses a dual-verification model: Chainlink's decentralized oracle network and Coinbase independently verify all cross-chain messages before execution. This redundant security model addresses the single-point-of-failure problem that plagued CrossCurve and similar protocols.
The significance extends beyond technical architecture. Coinbase selected Chainlink CCIP as its exclusive bridge infrastructure for wrapped asset growth, signaling that institutional players are converging on oracle-secured bridging rather than the validator-committee models that dominated 2022-2024. Apps including Zora, Aerodrome, Virtuals, and Flaunch integrated the bridge at launch.
2. ERC-7683 and the Intents Standard
The standardization of intent-based bridging through ERC-7683 is creating network effects. Uniswap's forthcoming UniswapX platform will use the standard for cross-chain swaps, potentially routing billions in DEX volume through intent-based infrastructure. The Ethereum Foundation's Open Intents Framework, backed by 30+ teams, is building a shared relayer network that any application can tap into.
This matters economically because it transforms bridging from a protocol-specific service into a commoditized infrastructure layer. When any relayer can fill any order from any application, competition drives down costs and the market selects for the most capital-efficient operators.
3. deBridge's AI-Agent Integration
On February 16, 2026, deBridge introduced a Model Context Protocol (MCP) server enabling AI agents to execute cross-chain transactions across 24 blockchains. This is the first production deployment of autonomous AI systems directly interacting with bridge infrastructure — allowing AI agents to bridge assets, execute swaps, and manage multi-step transaction flows without human intervention.
The implications for bridge economics are profound. If AI agents become significant users of cross-chain infrastructure — as the agentic economy thesis suggests — bridge protocols that offer machine-readable interfaces and programmatic execution will capture disproportionate volume. deBridge, which has processed $16.3 billion in cumulative volume with zero security incidents, is positioning itself at this intersection.
The bridge market's economics reveal a familiar Web3 pattern: enormous volume, razor-thin margins, and value capture that accrues to infrastructure providers rather than bridge protocols themselves.
Volume vs. Revenue: Stargate processed $4 billion in bridge volume in July 2025 alone but generated only approximately $1 million in revenue over three months — implying a fee capture rate well below 0.01% of volume. Across Protocol has bridged $28 billion cumulatively. deBridge reports $16.3 billion. Yet none of these protocols generate revenue remotely proportional to their volume.
Fee Compression: Bridge fees have collapsed from 0.3-0.5% in 2022 to 0.06% (Stargate's flat fee) or lower. Intent-based competition is pushing fees even further down. Some bridges like Portal offer fees under $0.01 per transaction. This is healthy for users but creates a sustainability challenge for bridge operators.
The Real Value Layer: The economic value in cross-chain infrastructure is shifting from the bridge protocols themselves to the layers above and below. Below, oracle networks like Chainlink capture value through CCIP verification fees. Above, applications like UniswapX and aggregators capture value by routing users to the cheapest bridge. The bridge itself is becoming commoditized middleware — essential but low-margin.
Market Consolidation: The Wormhole-LayerZero bidding war for Stargate in August 2025, with both protocols offering around $110 million, signals that bridge market share is worth acquiring. Stargate's $345 million in TVL and $4 billion monthly volume represents critical liquidity infrastructure. The consolidation trend suggests that the bridge market will converge toward 3-4 dominant protocols rather than the current fragmented landscape of 30+ competing bridges.
The ultimate vision for cross-chain infrastructure isn't better bridges — it's making bridges invisible. Chain abstraction protocols like Particle Network and NEAR Intents aim to give users a single account and balance across all chains, with cross-chain execution handled automatically in the background.
Particle Network's Universal Accounts grew to 110,900 users by Q1 2025 — a 558% quarter-over-quarter increase — with monthly growth rates exceeding 30%. The protocol's UniversalX Pro, launching in early 2026, aims to make chain-specific interactions completely transparent to end users.
The economic question is whether chain abstraction captures the value that bridge protocols cannot. By controlling the user interface and routing layer, chain abstraction protocols can charge for the convenience of seamless cross-chain execution while shopping among commoditized bridge providers for the cheapest backend execution. This mirrors the aggregator model that succeeded in other crypto verticals: 1inch capturing value above DEXs, Yearn above lending protocols.
If chain abstraction succeeds, today's bridge protocols risk becoming the unseen plumbing — essential but invisible and low-margin. The interoperability market's projected growth from $910 million to $7.8 billion by 2033 will likely accrue primarily to whoever controls the user-facing abstraction layer, not the underlying bridge infrastructure.
Bridge exploits remain systemic: Over $2.8 billion lost since 2022. The February 2026 CrossCurve hack ($3 million) used the same vulnerability class as Nomad's 2022 exploit, proving the traditional lock-and-mint model carries irreducible risk.
Intent-based bridging is the architectural fix: ERC-7683, backed by Uniswap Labs, Across Protocol, and 30+ Ethereum ecosystem teams, shifts risk from users to competitive relayers. Across has processed $28 billion with zero exploits.
Institutional players are choosing oracle-secured bridges: Coinbase's selection of Chainlink CCIP as exclusive bridge infrastructure for the Base-Solana connection signals where institutional capital will flow.
AI agents are entering the bridge market: deBridge's MCP server (launched February 16, 2026) enables autonomous AI execution across 24 chains — a leading indicator of machine-to-machine bridge demand.
Bridge economics are compressing: Fees have fallen from 0.3-0.5% to under 0.06%. Value is migrating to the layers above (chain abstraction, aggregators) and below (oracle networks) the bridge itself.
The market will consolidate: The Wormhole-LayerZero $110 million bid for Stargate and the projected 25.4% CAGR for interoperability suggest 3-4 winners in a market heading toward $7.8 billion by 2033.
Cross-chain bridges sit at the intersection of crypto's greatest need and its deepest vulnerability. The multi-chain world is irreversible — users, capital, and now AI agents need to move across dozens of independent blockchains. But the infrastructure enabling that movement has been responsible for more dollar losses than any other category of smart contract exploit.
The response is a fundamental architectural shift. Intent-based bridging, oracle-secured messaging, and chain abstraction are each attacking the problem from different angles. Intent systems eliminate single points of failure through competitive markets. CCIP-style oracle verification adds redundant security layers. Chain abstraction hides the complexity entirely.
From an economic value perspective, the bridge layer itself is being commoditized. The real value capture opportunity lies in controlling either the user-facing abstraction layer above or the security verification layer below. Bridge protocols that fail to move up or down the stack risk becoming low-margin utilities — processing billions in volume while capturing pennies in revenue.
The winners of the bridge wars won't be the protocols that move the most assets. They'll be the ones that make cross-chain movement so seamless, secure, and cheap that users forget they're using a bridge at all.