Back to Blog
EducationUpdated September 16, 2026ยท4 min read

Cross-chain bridges: how they work, why they get hacked, and when a swap is the safer way across

Bridges connect blockchains that cannot talk to each other, and they have lost more money to exploits than any other category in crypto. The four bridge designs and what each trusts, the anatomy of the big failures, what a wrapped token really is, and a rule of thumb for choosing between a bridge, an issuer protocol and an account-free swap for a given move.

The problem bridges solve

Blockchains are closed systems. Ethereum cannot verify a Bitcoin transaction; Solana cannot read Ethereum's state. Yet people hold assets on one chain and want to use them on another. A bridge is any mechanism that makes an asset from chain A usable on chain B. The catch is in the word usable: unless the issuer of the asset mints natively on chain B, what you get on chain B is a representation โ€” a wrapped token โ€” whose value depends on the bridge keeping the original safe.

Four designs, four trust models

DesignHow it worksWhat you trustExamples
Lock-and-mint (custodial or multisig)Asset locked in a contract or custody on A; wrapped token minted on B; burn on B to unlock on AThe keys that control the lock โ€” a company, a multisig, or a validator setWBTC (custodial), many early bridges
Light-client / native verificationChain B runs a light client of chain A and verifies A's block headers itselfThe two chains' own consensus โ€” the strongest model, but expensive and rareIBC (Cosmos), some rollup bridges
Liquidity networkPools of the native asset on both chains; you deposit on A and a relayer pays you from the pool on B, settled laterThe relayer's solvency and the protocol's settlementAcross, Stargate, Hop
Messaging layerA general message-passing network carries "burn on A, mint on B" instructions; verification by a set of oracles/verifiersThe verifier set and its configurationLayerZero, Wormhole, Axelar; CCTP uses Circle as the sole attester

The important pattern: every design except native verification introduces a party that must be honest and competent โ€” a key-holder, a relayer, a verifier set. That is where the failures happen.

Anatomy of the failures

  • Ronin (2022, ~$620M): a validator set of nine, five signatures needed; an attacker obtained five keys through social engineering of one operator with too much control.
  • Wormhole (2022, ~$320M): a signature-verification bug let the attacker mint wrapped ETH on Solana with no deposit.
  • Nomad (2022, ~$190M): an initialisation error made any message "proven"; hundreds of users copy-pasted the exploit.
  • Multichain (2023, ~$125M+): the operator's keys were held by a single team; when the CEO was detained, funds moved and the bridge collapsed. Users holding Multichain-wrapped assets on dozens of chains were left with unbacked tokens.

Three lessons: key concentration is the dominant risk; a bug in verification is instantly catastrophic because minting is unlimited; and when a bridge fails, everyone holding its wrapped tokens on the far side loses, whether or not they used the bridge that day.

What a wrapped token is

A wrapped token is an IOU issued by the bridge. WBTC is a claim on Bitcoin held by a custodian; a bridge's "USDC.e" is a claim on USDC locked in the bridge's contract. It trades at par as long as the market believes the backing is intact. It is not the asset, and if the backing is compromised it goes to zero regardless of the underlying asset's price. Holding a wrapped token is holding a bridge's credit risk.

Interoperability that does not need a bridge

Some cross-chain moves have a mechanism that avoids the wrapped-token problem entirely:

  • Issuer-native minting. USDC via CCTP and USDT via USDT0 burn on one chain and mint native tokens on the other; the stablecoin infrastructure guide covers both.
  • Account-free instant swaps. You send the native asset on chain A; you receive the native asset on chain B from liquidity already there. No lock contract, no wrapped token, no verifier set โ€” the swap service carries the cross-chain step and the on-chain part is two ordinary transfers. This is the only mechanism that also works for Bitcoin and Monero, which no bridge reaches natively: BTC โ†’ ETH, ETH โ†’ USDT (TRC-20), USDT (ERC-20) โ†’ USDT (TRC-20).

The trade-off of a swap is a spread and a custody window of minutes, versus a bridge's contract risk and a wrapped output. For anyone who is not a protocol developer needing a specific bridged asset, the swap is usually the safer instrument.

A rule of thumb

You wantUse
The native asset on the other chain, no account, any pairInstant swap
Native USDC between chains Circle serves, at sizeCCTP (via a wallet or app that integrates it)
A specific wrapped asset for a specific protocol (WBTC in a DeFi position)The canonical bridge for that asset โ€” and size the position to the bridge's risk
Bitcoin or Monero on any other chainNot natively possible โ€” swap to the asset you actually want instead

Frequently asked questions

Is WBTC safe? It is a custodial claim on Bitcoin, well established, with a public custodian. It is safe to the extent you trust the custodian and its governance, which changed in 2024. It is not Bitcoin.

Are rollup bridges different? Ethereum rollups' canonical bridges inherit Ethereum security for withdrawals, but withdrawals from optimistic rollups take about a week; that is why liquidity-network bridges exist for them.

What is the safest bridge? The one you do not need. If a native route exists โ€” issuer minting or an instant swap โ€” it removes the bridge's risk entirely.

Does an instant swap have counterparty risk? During the minutes between your deposit confirming and the payout, yes โ€” the service holds the funds. It is a much smaller window than a bridge's indefinite custody of locked assets.

How do I know if a token is wrapped? Check the contract address against the issuer's official list. Anything else is a derivative.

Ready to swap privately?

No account required. Start in seconds.

Start swapping โ†’