ucit.lol

How a bridge smart contract exploit can drain wrapped token collateral

A cross-chain bridge is only as safe as its weakest piece of code. When that code breaks, the wrapped tokens on the receiving chain stop being backed by real collateral, and holders discover they own a claim on empty vaults. The mechanisms that cause that failure fall into a few distinct categories.

Infinite mint exploits

Some bridges let users mint wrapped tokens after verifying that the corresponding native tokens have been locked on the source chain. If the verification logic has a bug, an attacker can bypass it. They mint wrapped tokens out of thin air, with no deposit ever made.

The Wormhole bridge exploit in February 2022 followed this pattern. An attacker called a function that should have required validator signatures. The signature verification contained a bug that could be tricked into passing any forged input. The result was 120,000 wrapped Ether minted on Solana with no locked ETH to back it. The total value was roughly 320 million dollars at the time.

After an infinite mint, the supply of wrapped tokens exceeds the collateral. Redemption is mathematically impossible for all holders. The last ones to sell might get something; everyone else holds a token that can never be unwrapped.

Collateral pool drain

A different attack focuses on the lock contract itself. The smart contract that holds the native collateral has a withdrawal function, meant to release funds only when a legitimate burn-and-release event occurs. If the contract has a logic flaw or a hidden backdoor, an attacker can call the withdrawal function directly and empty the pool of locked assets.

Wrapped token holders suffer the same outcome as in an infinite mint: their tokens are now unbacked. The difference is that the supply of wrapped tokens remains correct. The backing simply vanished.

Upgrade-key takeover

Many bridge contracts use a proxy pattern. The contract logic lives in a separate implementation contract, and a proxy admin key controls which implementation the bridge uses. That admin key is a single point of failure.

If an attacker gains control of the admin key, they can point the proxy at a malicious implementation. The malicious contract can mint unlimited wrapped tokens, drain the collateral pool, or brick the bridge entirely. The attacker does not need to find a bug in the bridge logic. They just need the key.

This happened to the Ronin bridge in March 2022. Five of nine validators' private keys were compromised, just enough to approve withdrawals. The attacker took 173,000 wrapped Ether and 25.5 million USDC from the bridge, a total loss of around 620 million dollars. The compromise was not a smart contract bug; it was a key management failure.

What happens to wrapped token holders

After any of these exploits, the wrapped token loses its peg to the original asset. The price on decentralized exchanges crashes toward zero. The token becomes unreedemable because the bridge no longer holds the backing required to burn it and release native funds.

A small number of cases saw a full bailout. The Wormhole exploit was repaid by Jump Crypto and other backers; the stolen funds were restored. That was an exception. Most bridge hacks end with holders absorbing the loss, and the wrapped token either becomes worthless or trades at a steep, permanent discount.

Holding wrapped tokens means trusting the bridge's code, its key management, and the willingness of its backers to make victims whole after a failure. That last part is not written in any contract. It is a guess.

Not financial advice. ucit.lol publishes market data and general information about UCIT. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.

Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.

Back to wrapped assets