Cross-chain bridge hacks
How do cross-chain bridge hacks work, and how do investigators trace the stolen funds?
A cross-chain bridge lets value move between blockchains, usually by locking assets in one place and issuing matching tokens on another. That locked pool is a rich target. Chainalysis counted about US$2 billion stolen from 13 bridge attacks by August 2022. Investigators follow the money with blockchain analytics, then rely on sanctions listings, exchange and issuer freezes, and seizures, though decentralized bridges have no operator to subpoena.
As of September 2026: The Nomad prosecution is an allegation stage matter: reports in May 2025 described an arrest in Israel on a US extradition request, and the current court status is under review. North Korean attributions come from US government statements. Loss figures are dated estimates and vary with token prices.
What happened?
A cross-chain bridge lets people move value between blockchains that cannot talk to each other. Many bridges lock assets on one chain and issue matching tokens on another. That locked pool is the prize. Chainalysis wrote that bridges are attractive targets because they often keep a central store of funds backing the bridged assets, and by August 2, 2022 it counted 13 bridge attacks worth about US$2 billion, roughly 69% of all crypto stolen that year to that point.
Four 2022 cases show the pattern.
Wormhole, February 2022. An attacker minted 120,000 wrapped ETH on Solana without locking real ETH behind it, worth over US$320 million. Jump Crypto, the backer of Wormhole’s developer, replaced the funds the next day, so the bridge stayed fully backed.
Ronin, March 2022. Attackers took 173,600 ETH and 25.5 million USDC, about US$540 million at the time. Elliptic, citing Ronin’s own postmortem, said the attacker obtained keys for five of nine validator nodes and that the attack was socially engineered. It went unnoticed for six days, until a user’s 5,000 ETH withdrawal failed.
Harmony Horizon, June 2022. About US$100 million was taken on June 24. Elliptic described the bridge as over-centralized and open to social engineering.
Nomad, August 2022. A routine upgrade initialized a trusted value to 0x00, which the contract also read as “untrusted,” so messages were treated as proven. Mandiant said the flaw needed little skill to use, and copycats piled in. Over US$190 million left the bridge, and a bounty offer brought back about US$36 million.
Which techniques did it use?
The theft is only step one. The second step is layering: making the stolen funds hard to follow.
After Ronin, Elliptic reported that the attacker swapped USDC for ETH on decentralized exchanges, apparently to avoid a freeze, then sent about US$80.3 million through the mixer Tornado Cash. Treasury later said Tornado Cash had laundered more than US$96 million from the Harmony theft and at least US$7.8 million from Nomad. That is chain-hopping plus mixing: change assets, change ledgers, blend with other deposits. See the chain-hopping technique and the Tornado Cash case.
When Tornado Cash was sanctioned, Harmony’s thieves adapted. Elliptic reported that from January 2023 they sent funds through Railgun, another privacy protocol. Elliptic estimated that about 70% of the ether passing through Railgun at that time came from this one hack, which made the mixing far less effective. The funds then went to exchanges.
How was it found?
This is how a bridge investigation typically works, based on published Chainalysis, Elliptic, TRM and government material.
- Publish the addresses. The victim or an analytics firm publishes the attacker’s addresses. Every address becomes a starting point on a public ledger.
- Follow the funds. Blockchain analytics tools cluster addresses, follow transfers, and read the bridge’s own events, since a deposit on one chain has a matching release on another. That is how analysts keep a trail across chains.
- Attribute. Firms compare wallet behavior and laundering habits with earlier cases. Elliptic had attributed the Harmony theft to Lazarus before the FBI confirmed it. OFAC listed the Ronin attacker’s Ethereum address on April 14, 2022, and the FBI confirmed Lazarus for Harmony on January 23, 2023, later publishing wallet addresses.
- Screen and freeze. Published addresses let exchanges and other providers block deposits. Chainalysis credited tracing to cash-out points plus quick contact with law enforcement and industry for the Ronin freezes. Binance and Huobi said they blocked and seized part of the Harmony funds.
- Seize. Once funds are frozen at a regulated service, authorities can pursue forfeiture.
The limits are real. A decentralized bridge or mixer has no company to subpoena. Funds can cross several chains in hours. And attribution to a state does not produce an arrest.
What was the outcome?
Recoveries were partial. Chainalysis reported on September 8, 2022 that over US$30 million of the Ronin funds, roughly 10%, had been seized, the first time crypto stolen by a North Korean group was seized. Harmony’s funds were partly blocked by exchanges, and the rest was laundered. Wormhole’s users were made whole by a private backer, which is a business decision, not an enforcement result. Nomad recovered about US$36 million through its bounty.
Prosecutions have been rare. For Nomad, TRM Labs reported in May 2025 that a Russian-Israeli man charged in the United States with fraud and money laundering had been arrested in Israel on a US request. Those are allegations and the case has not ended in a verdict.
What were the warning signs?
Bridge operators and compliance teams look for:
- A very large withdrawal that does not match the bridge’s normal flow
- Newly created addresses receiving funds from a bridge and forwarding them within minutes
- Stablecoins swapped into assets that cannot be frozen, right after an exploit
- Deposits into mixers and privacy protocols that match the size of a known theft
- One wallet or a small group holding the keys that control a bridge’s funds
What changed afterwards?
Sanctions moved onto the blockchain. OFAC now lists wallet addresses, and the Ronin listing was an early example. The FBI’s habit of publishing wallets tied to stolen funds gives exchanges something concrete to screen against. Analytics firms also built better tracing across chains.
The gaps remain. Bridges still concentrate funds, speed still favors the thief, and privacy protocols can dilute a trail even when they cannot erase it. For how the wider system works and why it sometimes fails, see detection and the reporting page.
Frequently asked questions
What is a cross-chain bridge?
A bridge is software that lets you move value from one blockchain to another. Many lock your coins on the first chain and issue a matching token on the second. Bridges are legitimate tools, but the locked pool of funds behind them makes them attractive to thieves.
Why are bridges targeted so often?
Chainalysis noted that bridges are attractive because they often keep a central store of funds backing the bridged assets on the receiving chain. One flaw, or one stolen set of keys, can expose the whole pool at once.
Can stolen bridge funds be traced?
Usually yes, at least as far as the next service. Public ledgers let analytics firms follow funds through mixers and across chains. The hard part is speed and jurisdiction: funds can move faster than anyone can freeze them, and a decentralized service has nobody to serve a court order on.
Did users get their money back?
It varied. Wormhole's backer replaced all the stolen funds within a day. Nomad recovered about US$36 million through a bounty offer to people who returned funds. For Ronin and Harmony, only a fraction was frozen or seized, and the rest was laundered.
Who was arrested for these hacks?
For the North Korean thefts, no operator has been arrested, because they operate from inside North Korea. For Nomad, US prosecutors charged a man in 2023 who was later arrested in Israel; those are allegations, not convictions.
Techniques used in this case
- Chain hopping and cross-chain bridges · Swapping illicit crypto across blockchains through bridges and no-KYC swap services so that no single chain's analytics tell the whole story.
- Mixers, tumblers, and CoinJoin · Services that pool many users' coins and pay out equivalent amounts from the pool, breaking the on-chain link between where crypto came from and where it went.
- Sanctions evasion · Hiding who really owns or benefits from assets and payments so sanctions do not bite, using many of the same tools as money laundering but often with lawfully earned money.
Related cases
- Lazarus Group · North Korea's state hackers have stolen roughly US$6.75 billion in cryptocurrency and launder it at a speed no other criminal group matches.
- Tornado Cash · The first sanctioned crypto mixer, a court ruling that limited the sanctions, and a developer trial whose outcome will define liability for privacy code.
- ChipMixer Takedown (2023) · A darknet bitcoin mixing service that the US said processed over US$3 billion, seized by US and German police in March 2023 while its alleged operator stayed out of reach.
Glossary
Sources
- U.S. Treasury Sanctions Notorious Virtual Currency Mixer Tornado Cash (US Department of the Treasury, August 8, 2022).
- FBI Confirms Lazarus Group Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft (Federal Bureau of Investigation, January 23, 2023 (updated February 6, 2023)).
- Treasury updates Lazarus Group sanctions with digital currency address linked to Ronin Bridge hack (CyberScoop, April 14, 2022).
- North Korea's Lazarus Group identified as exploiters behind $540 million Ronin bridge heist (Elliptic, April 2022).
- Seizure of crypto stolen in the Ronin Bridge / Axie Infinity DPRK hack (Chainalysis, September 8, 2022).
- FBI confirms North Korea's Lazarus Group as hackers behind $100 million Harmony Horizon Bridge theft (Elliptic, January 2023).
- Cross-Chain Bridge Hacks Emerge as Top Security Risk (Chainalysis, August 2, 2022).
- Dissecting the Nomad bridge hack (Google Cloud (Mandiant), August 2022).
- Key Suspect in $190M Nomad Bridge Exploit Extradited to the United States (TRM Labs, May 15, 2025).
- Jump Crypto Replaces Over $320M of Wormhole Wrapped ETH in DeFi Bailout (The Defiant, February 2022).