Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

When a blockchain bridge fails, the asset may not have moved between chains at all: the bridge may have locked it, issued a token representing it elsewhere, or relied on liquidity and cross-chain messages. A failure can let attackers withdraw or mint assets without authorization, leave withdrawals stuck, or undermine confidence that wrapped tokens are backed. Users can lose money directly; whether operators, signers, or sponsors must reimburse them depends on the incident and applicable law.

What a blockchain bridge does—and what can fail

A bridge coordinates assets or messages between separate blockchains. Its design determines who is trusted to confirm a transfer and who can authorize the corresponding action on the destination chain. The original asset does not literally travel from one blockchain to another in every design.

In a lock-and-mint design, for example, the bridge may lock an asset on its source chain and mint a representation on the destination chain. The representation depends on the bridge recognizing valid deposits and keeping the locked assets secure. Other designs burn and mint tokens, use pools of liquidity, or rely on contracts and relayers to verify and transmit messages. A failure in any of those mechanisms can have different consequences.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bridge designs concentrate different kinds of trust

Design or mechanism What users rely on Possible failure
Centrally operated bridge An operator and its systems to control assets or transfer data correctly Compromised control, censorship, collusion, custody failures, or transaction errors
Lock-and-mint bridge Correct validation of deposits and messages, plus secure custody of locked assets Unauthorized release or minting can leave destination tokens without adequate backing
Contract- or algorithm-based bridge Correct contract logic, validation, upgrades, and user actions A code or algorithm defect, unsafe upgrade, or user mistake can disrupt transfers or put assets at risk
Liquidity-based bridge Available liquidity and the mechanism that accounts for assets across chains Insufficient liquidity can delay or prevent a transfer even without an exploit

These categories can overlap. The European Blockchain Observatory and Forum describes centrally operated bridges as relying on a central system for asset and data transfers, while contract- and algorithm-based designs remove a central operator from some actions. Neither “trusted” nor “trustless” is a security guarantee: each label describes assumptions, not a verdict on a particular bridge.

How bridges fail

Keys, signers, or validators are compromised

If an attacker gains control of a key or enough members of a signer or validator group, the bridge may accept an unauthorized message or withdrawal. A small group with broad authority can make decisions quickly, but it also concentrates power and the consequences of a compromise.

Message verification accepts something invalid

A bridge must decide whether an event on one chain really authorizes an action on another. A faulty proof check, validation rule, or interaction between on-chain contracts and off-chain relayers can let a fabricated message pass. If that message authorizes a release or mint, the bridge may send assets without a valid underlying transfer.

Contract logic or business rules are flawed

Code can mishandle an initialization state, an unusual input, or a change in how messages are processed. A bridge may also have business-logic errors in the way it accounts for deposits, withdrawals, or destination-chain tokens. An audit can help identify defects, but neither an audit nor the number of audits guarantees that every failure path has been found.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A connected chain, liquidity source, or operation fails

A vulnerability in an underlying blockchain can affect a bridge that depends on it. Separately, a bridge can become unusable because liquidity is inadequate, a relayer or verifier is unavailable, or transactions are delayed or blocked. These operational failures may strand funds without an attacker stealing them.

A user makes an irreversible mistake

Sending an asset through the wrong route, choosing an unsupported token, or making another irreversible transaction error can cause a loss even when the bridge’s security controls work as intended. Not every failed transfer is a hack, and not every loss has the same cause.

What bridge failure looks like to users

  • Assets are released without authorization: the bridge’s custody or withdrawal controls have failed, and the pool of assets available to users may be depleted.
  • A wrapped token loses confidence in its backing: destination-chain tokens may remain transferable, but users may doubt whether they can be redeemed for the assets the bridge was meant to hold.
  • Withdrawals or transfers are stuck: users may be unable to move assets while a verifier, relayer, contract, or liquidity source is unavailable or the bridge pauses activity.
  • Access is suspended: an operator or protocol may freeze or restrict activity during an incident. Whether a user can later recover funds depends on what remains available and on any recovery process.

A destination blockchain can continue operating normally while a bridge connected to it is unsafe or unavailable. The security of either chain alone does not establish that the bridge’s messages, custody, or backing are secure.

Nomad: when a verification defect enabled an asset drain

Nomad’s 2022 incident illustrates how a message-validation failure can become a loss of bridge-held assets. In an engineering analysis published Aug. 9, 2022, Peter Kacherginsky and Heidi Wilder of Coinbase described a system with on-chain contracts and off-chain agents that relayed and verified messages. A zero entry was left accepted as a trusted root during contract initialization. After a later change to message processing, a fraudulent message with a missing or null entry could pass the check. Attackers then submitted messages that caused the bridge to send stored tokens.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Coinbase reported that more than $186 million in ERC-20 assets was stolen from Aug. 1, 2022, at 21:32 UTC through Aug. 2 at 05:49 UTC. The figure describes that historical incident, not a current bridge-loss total. Coinbase’s authors also wrote that, as of Aug. 9, 2022, 17% of the amount stolen from the Nomad Bridge contract had been returned, including partial returns. That dated figure does not show that all affected users were made whole or establish a typical recovery rate.

How large have bridge losses been?

Historical totals depend on which incidents a publisher counts and how it defines a bridge exploit. They should not be read as a live 2026 tally.

  • Beosin’s Global Web3 Security Report 2022, published in 2023, counted 12 cross-chain bridge security incidents causing approximately $1.89 billion in losses in 2022. It identified validation issues, blockchain vulnerabilities, and business-logic or function-design issues among leading causes.
  • The European Blockchain Observatory and Forum’s 2023 report, The current state of interoperability between blockchain networks, put cumulative losses through bridge vulnerabilities at more than USD 2.5 billion at the time of the report. It included selected incidents such as Ronin, Wormhole, Nomad, and Binance.
  • A 2024 survey by Notland, Li, Nowostawski, and Haro examined 60 bridges and 34 exploits from 2021–2023. It identified 13 architectural components and linked them to eight vulnerability types. Those figures describe the survey’s sample and taxonomy, not every bridge or incident.

The totals differ in scope and method. The survey’s authors note that incident counts vary with definitions of bridge exploits and reporting boundaries, so figures from separate reports are not necessarily directly comparable.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Who loses when a bridge is hacked or fails?

Users may bear the direct financial loss

Users can lose assets held by a bridge, find that a wrapped token no longer has dependable backing, or be unable to access funds while transfers are suspended. A user’s practical exposure depends on the bridge’s design, the assets and route involved, and what remains after the incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Operators and signers may face consequences, but reimbursement is not automatic

Bridge operators and signers may face operational and reputational consequences, and potentially legal ones. The outcome depends on the incident’s facts and governing law. A third party may return or reimburse some assets, as happened in part after Nomad, but that event does not establish a general obligation to compensate users.

The U.S. Treasury’s Oct. 3, 2022 release about the Financial Stability Oversight Council report addresses broader digital-asset financial-stability risks and regulatory gaps. It does not establish a bridge-specific liability rule or a universal entitlement to recovery. Who is legally responsible in a particular case is a jurisdiction- and fact-specific question.

What to check before using a bridge

Assess the specific controls that govern the route you plan to use, rather than relying on a “trusted,” “trustless,” or audited label alone.

  • Withdrawal authority: Who can authorize a release or message? How many independent signers or validators must agree?
  • Verification method: Does the bridge use source-chain proofs, a validator quorum, a multisignature arrangement, or another mechanism? What happens if verification is wrong or unavailable?
  • Custody and emergency powers: Who holds locked assets? Can an operator freeze, censor, upgrade, or redirect activity?
  • Upgrade controls: Which contracts can change, who can change them, and what delay or emergency process applies?
  • Monitoring and recovery: What incident monitoring, response procedures, and recovery arrangements are documented?
  • Backing and liquidity: What assets back destination-chain representations, and how would a shortfall or liquidity problem become visible?

These checks do not predict whether a bridge will fail. They help identify where authority and exposure sit, and distinguish bridge security from the security of the connected blockchains.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.