ucit.lol

Why a bridge having high TVL does not mean it is safe to use

If a bridge holds billions of dollars, it must be secure. That is the assumption many people make. It is wrong.

Total value locked (TVL) measures how much capital a bridge custodies. It does not measure how well it protects that capital. A high TVL can attract more attackers, and it can also disguise fundamental weaknesses until the moment they fail.

The Multichain collapse is the clearest example. In early 2023, Multichain was one of the largest cross-chain bridges, regularly reporting TVL above $1 billion. It used a multi-party computation (MPC) architecture, a system that splits custody across multiple parties, and that sounds robust. But the actual security depended on who controlled the MPC keys. In practice, a single person - the founder - held disproportionate control. When the founder disappeared and the keys moved elsewhere, the protocol became a target. Over $1.3 billion in user funds was drained. High TVL meant a bigger prize, not a stronger vault.

TVL and security measure different things. DefiLlama tracks TVL. It tells you how much value is deposited. L2Beat evaluates risk profiles, examining contract upgradeability, permissioned roles, and data availability. Both tools are useful, but using only one is like checking a car’s fuel gauge to decide if the brakes work.

What matters for bridge security is the custody model. Does the bridge use a wrapped-assets/smart-contract-custodian-bridge/">smart contract custodian, a multisig, an MPC system, or a federation? Each has different failure modes. A multisig with seven signers spread across different jurisdictions is harder to compromise than one where all signers work for the same company. An MPC system with independent node operators is stronger than one where a single entity generates and stores key shares. Ask who holds the power to move funds. If that answer is vague, the bridge is vague.

Key management is the next question. How are keys generated? Where are they stored? Are they rotated? Are there backup procedures? Multichain’s keys were handled in ways that critics flagged years before the collapse. Key management is not glamorous, but it is the line between custody and theft.

Upgrade controls matter. A bridge with an upgradeable contract is not automatically unsafe. But if a single address can modify the contract without a timelock, the bridge can change its rules in seconds. That is a lever an attacker can pull. Check whether upgrades require a vote. Check the timelock duration. Two days gives users time to withdraw if something smells wrong. Zero gives them nothing.

Audit quality and recency matter, but be sceptical. An audit checks the code that was deployed the day it was reviewed. If months have passed, if the code changed, if a new version deployed, that audit is stale. Also look at what the auditor found. Some bridges have passed audits with known centralisation risks noted. An auditor may flag “owner can withdraw all funds” as a design choice, not a vulnerability. It is a vulnerability if you do not trust the owner.

Incident history matters. Has this bridge ever been paused? Has it ever halted withdrawals? Has it suffered any exploit, even a small one? How was it handled? A bridge that has never had a problem may simply not have been tested. A bridge that survived a minor hack and repaid users shows some operational resilience. Silence can be deceptive.

Insurance funds matter. Some bridges back deposits with a separate insurance pool that covers losses from exploits. This does not prevent theft, but it changes what happens after. If the answer is “we are working on it”, assume there is none.

The tools exist to evaluate these factors. L2Beat breaks down bridge risk categories: staked assets, upgradeability, proposer controls, and sequencer failure. DefiLlama shows which bridges hold value on which chains. Cross-referencing them gives a more complete picture than TVL alone.

TVL is not safety. It is a target the size of which determines how many eyes are on the prize. When the next bridge fails, look back and see if the warning signs were visible. They usually were. You just had to look beyond the number.

Not financial advice. ucit.lol publishes market data and general information about UCIT. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.

Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.

Back to wrapped assets