Blog Crypto Basics Cross-Chain Bridges Explained: How They Work, Why They're Hacked, and How to Stay Safe
Crypto Basics

Cross-Chain Bridges Explained: How They Work, Why They're Hacked, and How to Stay Safe

D
DennTech Team
August 31, 2026
Updated Aug 31, 2026
0 comments

The Billions Lost to Bridge Hacks: Why Cross-Chain Infrastructure Is Crypto's Most Dangerous Layer

No category of crypto infrastructure has suffered more catastrophic security failures than cross-chain bridges. The Ronin bridge hack ($625M, 2022), the Wormhole exploit ($320M, 2022), the Nomad bridge incident ($190M, 2022), the Harmony Horizon bridge attack ($100M, 2022), and the Kelp bridge exploit ($292M, 2026) represent a pattern of concentrated losses that stands in stark contrast to the relatively resilient security record of the layer-1 blockchains themselves. Understanding why bridges are so uniquely vulnerable, how different bridge architectures manage risk differently, and how to evaluate bridge security before using one is essential knowledge for any DeFi user who needs to move assets across chains.

Why Bridges Are Inherently Difficult to Secure

The fundamental security challenge of a cross-chain bridge is that it must maintain state consistency across two independent blockchains with different security models, consensus mechanisms, and finality guarantees. Doing so requires a trust assumption somewhere in the system — either a group of validators who attest to the state of the source chain on the destination chain, a multi-signature committee that approves withdrawals, or a cryptographic proof system that verifies source chain state trustlessly on the destination. Each approach has different security properties and attack surfaces.

Multi-signature bridges — where a committee of n validators must agree on withdrawal approvals — are the most common and the most vulnerable. If an attacker can compromise m-of-n validators' private keys (where m is the signature threshold), they can unilaterally approve fraudulent withdrawals. The Ronin bridge used a 5-of-9 multi-signature design; the attacker compromised 5 keys and emptied the bridge treasury. The Harmony bridge used a 2-of-5 design; the attacker compromised 2 keys. These were not bugs in smart contract logic — they were fundamental key management failures in a trust model that concentrated enormous value in a small number of cryptographic secrets.

IBC: Trust-Minimised Cross-Chain Communication

The Cosmos IBC protocol represents the most rigorous approach to trust-minimised cross-chain communication in production today. Rather than relying on a committee of trusted validators, IBC maintains light clients of each connected chain on both sides of the connection — continuously verifying that the state updates it receives are cryptographically consistent with the source chain's consensus. An attack on an IBC connection requires attacking the consensus of the source blockchain itself, not just compromising a committee of bridge operators. The security guarantee is therefore anchored to the security of the source blockchain rather than to the operational security practices of bridge operators. The Cosmos ecosystem's multi-year track record with IBC — handling billions in cross-chain transfers without a security incident — validates this approach empirically.

LayerZero and the Oracle-Relayer Model

LayerZero takes a different approach: it uses two independent parties — an oracle and a relayer — who must both agree on the state of a source-chain transaction for a cross-chain message to be delivered on the destination chain. The security assumption is that the oracle and relayer do not collude; given that they are typically economically independent parties with no incentive alignment for collusion, this assumption has proven robust in practice. The BitGo WBTC migration to a LayerZero-to-Chainlink oracle structure, announced August 4, 2026, pushed $14.5 billion in assets through LayerZero's architecture — a significant live endorsement of its security model. See our Cosmos IBC guide for the full comparison of bridge security models.

Practical Bridge Safety: How to Evaluate and Use Bridges

  • Audit history: Does the bridge have multiple independent security audits from reputable firms? Bridges handling hundreds of millions in assets with single audits or outdated audits carry unacceptable risk.
  • TVL and track record: Large TVL with no security incidents is a meaningful (though not conclusive) signal of security. Very new bridges with rapidly growing TVL warrant additional scrutiny.
  • Withdrawal limits and rate limiting: Does the bridge implement withdrawal limits or rate limiting that would constrain the damage from a single exploit? Bridges with no such limits allow attackers to drain the full treasury in a single transaction.
  • Trust model transparency: Is the bridge's trust model clearly documented? Multi-signature bridges should disclose the identity and security practices of their signers; oracle-based bridges should disclose oracle provider independence.

For users who must regularly bridge assets, using the canonical bridges of major L2 networks (Arbitrum Bridge, Optimism Bridge, Base Bridge) for large amounts — accepting slower withdrawal times — and reserving third-party bridges for smaller amounts or time-sensitive transfers provides a reasonable risk-managed approach. Our crypto tools monitor bridge TVL and security status, and our DeFi risk management guide frames bridge risk within the broader DeFi risk hierarchy.

0 Comments

No comments yet — be the first to share your thoughts.

Leave a Comment

Your email won't be published. After submitting, you'll receive a quick verification email — click the link to publish your comment.

Used only to verify your comment — never shown publicly.

0 / 2000

Free Newsletter

Get weekly crypto trading insights

New guides, tool updates, and market analysis — straight to your inbox. No spam, unsubscribe anytime.