Bridge Compromise
Assets locked on one chain to mint a representation on another are stolen, or the minting authority is subverted, leaving the wrapped tokens unbacked.
작동 방식
A typical bridge locks an asset in a contract or custodial account on the source chain and mints a claim token on the destination chain, so the claim token is worth the underlying only while the lock holds and only while minting is restricted to genuine deposits. Two things can break. The verification can be defeated, as when a flaw lets a forged proof or an uninitialized verifier accept a message that no deposit backs, minting unbacked tokens out of nothing. Or the authority can be captured, as when the external validator set or multisig that signs withdrawals is compromised and simply signs the funds away. Bridges concentrate value from many chains behind one security model, which makes them a standing target.
실제로 관찰 가능한 항목
Determine whether the bridge verifies the source chain with a light client and proofs or trusts an attestation committee, and if it is a committee, how many signers exist, what the threshold is, whether the signers are independent, and whether their keys are in separate custody. Compare the value held against that security model, and check for a timelock or a pause on withdrawal parameter changes. Every major bridge failure has a public post-mortem, and the incident history of the specific design is observable.
선례
In 2022 the Ronin bridge lost custody after attackers obtained control of a majority of the keys in its validator set, and the Wormhole bridge was drained through a signature verification flaw before its backer replaced the missing collateral.
수치의 중요성에 영향을 미치는 요인
Weigh whether verification is cryptographic or social, the signer count and threshold, how independent the signers are, how much value sits behind the design, and whether upgrades pass a timelock.
관련 요소
이 항목이 적용되는 자산
이 팩터가 적용되는 카테고리에서 규모가 가장 큰 자산들. 여기에 포함된다는 것은 해당 팩터가 그 유형의 자산에 관련된다는 의미이며, 실제로 발생했다는 의미가 아니다.