Tuesday, August 18, 2026 Today's news About Live prices →
£ PoundToken
Crypto, covered properly · Est. 2026
DeFi

Cross-chain bridge hacks near $4bn as scrutiny of DeFi’s weakest link grows

Losses from cross-chain bridge exploits have reached roughly $4bn, exposing a structural verification gap regulators are only beginning to address.

By Freya Macdonald · ·3 min read
Cross-chain bridge hacks near $4bn as scrutiny of DeFi’s weakest link grows

Roughly $4bn has been drained from cross-chain bridges since the technology emerged, according to an analysis published by crypto.news, underlining a persistent structural weakness in the infrastructure that lets assets move between otherwise incompatible blockchains such as Ethereum, Solana, Arbitrum and Avalanche.

The figure reflects the cumulative toll of exploits targeting the verification mechanisms bridges rely on, rather than a single incident. It comes as institutional allocators increasingly move capital across chains and as questions grow over whether bridge operators’ stated security guarantees match what their code actually enforces.

A verification problem, not a transfer problem

Blockchains are designed to be self-contained: Ethereum has no native means of reading Solana’s ledger, and each network enforces its own consensus and finality rules. Bridges exist to work around that isolation, allowing a user to deposit an asset on one chain and receive an equivalent on another.

The dominant model, known as lock-and-mint, works by locking tokens in a smart contract on the source chain while a set of validators, relayers or an oracle attests that the deposit occurred, triggering a synthetic version of the token to be minted on the destination chain. Reversing the process requires burning the synthetic token so the original can be unlocked.

That architecture depends entirely on the integrity of the attestation step. If an attacker can convince the destination chain that a deposit took place when it did not, unbacked synthetic tokens can be minted at will — precisely the failure pattern behind the largest bridge exploits to date.

Why bridge failures trigger bank runs

Lock-and-mint bridges must maintain a strict one-to-one ratio between locked originals and minted synthetics. Once that ratio breaks, some wrapped tokens are no longer backed by real assets held in reserve, and only holders who redeem first will retrieve genuine funds once the shortfall becomes public.

This produces a dynamic familiar from traditional finance: as soon as an exploit is disclosed, holders of the affected synthetic token rush to redeem simultaneously, emptying the vault for anyone left behind. An analysis by Coinbase cited in the crypto.news report found that bridge security failures consistently stem “from the gap between the trust assumptions a bridge claims and the trust assumptions it actually enforces.”

Implications for institutional flows

For European and UK institutions weighing exposure to multi-chain DeFi strategies, the persistence of bridge risk sits awkwardly alongside growing regulatory interest in digital asset custody standards. Supervisors examining crypto market infrastructure have so far focused chiefly on exchanges and stablecoin issuers; bridge protocols, which sit outside conventional licensing regimes in most jurisdictions, have received comparatively little formal scrutiny despite concentrating billions of dollars in locked collateral.

An alternative design, burn-and-mint, attempts to remove the wrapped-token vulnerability altogether by permanently destroying the original token on the source chain rather than locking it, though it too depends on validators correctly verifying that a burn has occurred before a new token is issued elsewhere.

Until interoperability standards mature, industry participants argue that the choice of bridge — and the transparency of its validator set and attestation process — remains as consequential to institutional risk management as the choice of custodian or exchange.

Read more: Coldcard drain nears $89m, reviving debate over Bitcoin self-custody risk

Sources

More DeFi