Bridge Config Trust
Single-key concentration in bridge trust configs; cross-chain message origin forgery.
BonkDAO: about $4M bought the votes to drain a $20M treasury
the contracts worked exactly as designed
Wanchain
a non-injective signed-message encoding let one legitimate signature be reused for a vastly larger withdrawal
Verus-Ethereum bridge
the same entry path was hit again two months later, paying out $7.54M without backing
AFX Trade
compromised validator keys met the two-thirds quorum "validly" and released $24.15M
Ostium
one compromised oracle signer key let "future prices" be accepted as validly signed, draining $18M
Aptos: a Move VM type confusion could let one on-chain resource be treated as another (reproduced in a ~$3,000 test environment)
The blockchain security firm Hexens disclosed a critical vulnerability in Aptos's Move VM (the execution environment that processes every sm…
Secret Network: Deposits From a Forged Channel Went Unverified, Letting Unbacked Wrapped Tokens Be Minted Without Limit
On the IBC bridge connecting Secret Network and Axelar, about $4.67 million in assets was withdrawn despite there being no corresponding bac…
SecondFi: Audited Signing Code Was Replaced by an Unaudited SDK, Letting Private Keys Be Reconstructed From Public Data on Every Signature
Users of the Cardano wallet SecondFi (formerly Yoroi, of the EMURGO lineage) lost about 16M ADA (about $2.4M) to consecutive drains on June …
Bybit: a "legitimate" multisig approval signed by trusting the UI drained a supposedly secure Ethereum wallet
JavaScript injected into the Safe{Wallet} frontend left signers no way to verify what they were signing (Bybit / Mandiant)
Taiko Bridge: Forged Withdrawals Passed as Valid After a Prover Signing Key Leaked
a prover signing key leaked to a public repo, splitting a proof's formal validity from independent verification of prover identity (BlockSec / Blockaid)
Syscoin Bridge: an invalid SPV proof was read as "valid" and minted 5B SYS with no burn
a parsing flaw in SPV proof verification
When One Laptop Meets the Multisig Threshold
Distributed Approval Collapses to a Single Custody Point (Humanity Protocol)
The Alephium TokenBridge Exploit ($815K)
Guardian Keys Intact, But No Verification of the Provenance of the Events They Signed
The Verus-Ethereum Bridge Hack ($11.58M)
A Valid Merkle Proof, But No Verification That the Source Amount Matched the Payout
KelpDAO / rsETH Unauthorized Unlock
RPC Manipulation Attack on the DVN Observation Layer
Stake DAO vsdCRV Unauthorized Mint
LayerZero v2 Trust Source Rewriting via Deployer Key