New: Explore our latest Web3 innovations.Learn More about Ancilar Web3 services

Cross-Chain Bridge Security: How Bridges Work and Why They Break

Blockchain Security
2025-05-21
Author:Shivank
Cross-Chain Bridge Security: How Bridges Work and Why They Break

Cross-chain bridges lost over $2B since 2021. Audit how lock-and-mint, burn-and-mint, and liquidity bridges work, why they get hacked, and how to secure them.

Frequently Asked Questions

Bridges concentrate value in a single custody contract secured by a small validator set or multisig, making them high-value targets with a narrow attack surface. Signature verification bugs, validator key compromises, and message replay flaws have accounted for over two billion USD in losses since 2021, per Chainalysis (Aug 2022).
Lock-and-mint locks the native asset on the source chain and mints a wrapped representation on the destination. Burn-and-mint destroys tokens on the source and reissues canonical supply on the destination, keeping total supply constant. Lock-and-mint creates honeypot custody contracts; burn-and-mint removes that risk but needs issuer control on both chains.
No bridge is risk-free. Architectures using ZK light clients (Polyhedra, Succinct) or native light-client verification (Cosmos IBC, Chainlink CCIP with the Risk Management Network) carry the smallest trust assumptions. Bridges depending on a small external multisig or bonded validator set remain the highest-risk designs.
On March 23, 2022, attackers tied to the Lazarus Group compromised five of nine validator keys, including one delegated to Axie DAO and never revoked. With the 5-of-9 quorum met, they forged two withdrawals totaling 173,600 ETH and 25.5M USDC, roughly 625 million USD at the time (Halborn, March 2022).
Yes, within limits. Rate limits, circuit breakers, ZK light-client verification, 20+ diverse validators, and independent monitoring layers have measurably reduced exploit frequency since 2023. Bridges still trade some trust for every improvement, so design is a tradeoff, not a solved problem.

Don't Miss What's Next

Subscribe to newsletter

Tags:

cross-chain bridge security

bridge exploit

cross-chain interoperability

Wormhole hack

Ronin bridge

Get in Touch

Our team will get back to you within 24 hours.

A clear proven process, that delivers

End of Scroll. Start of Discovery.

You've seen our ideas - now go deeper.
Discover more insights, tutorials, and innovations shaping Web3.