Intermediate

Cross-Chain Bridges and Their Risks

🕐 9 min read · Updated 2026-10-10 · Not financial advice

Cross-chain bridges exist because different networks cannot talk to each other. They also have a track record of being the single largest attack surface in DeFi, and the reason is structural rather than incidental.

How a bridge works

When you move tokens across networks, one of two things happens.

Either the tokens are locked on the source chain and a wrapped representation is minted on the destination, or the tokens are burned on the source and minted on the destination. Most bridges use the lock-and-mint approach.

The bridge contract holds the locked assets and mints wrapped tokens according to its own rules. That contract is the entire trust assumption, and it is usually the least audited code in the ecosystem.

Where the losses came from

The failures cluster into recognisable categories.

If the contract itself is compromised, the attacker can mint unlimited wrapped tokens and sell them into liquidity. Signature verification bugs have done exactly this.

  • Relayers and oracles are trusted parties; compromising them corrupts minting.
  • Wrapped tokens can be depegged if the backing is not verifiable.
  • Admin keys are a permanent risk, because an upgrade can change the rules at any time.

Why the risk is higher than it looks

A bridge holds a large, visible pool of assets, which makes it worth targeting. The attacker does not need to steal incrementally; a single exploit is worth more than months of fees.

The TVL on bridges is not comparable to the TVL on a lending protocol in risk terms, even though both are quoted the same way.

Reducing the exposure

  • Prefer established, time-tested bridges over new ones offering higher yields.
  • Bridge the amount you need rather than routing your whole balance.
  • Check for an audit and for whether the contract is upgradeable.
  • Use chains where the canonical asset is native, so no wrapped version is needed.
  • After bridging, do not leave large balances sitting idle on the destination chain.

The honest summary

Bridges are usable and are sometimes the only route to a network. They are not the default place to hold value, and the fee discount that a referral gives you does not change the security profile of the contract.

The wrapped asset problem

Even when a bridge functions correctly, the wrapped token on the destination chain is a claim on the bridge's reserves rather than the native asset. If the bridge is compromised, your wrapped balance is the first thing at risk.

Where the destination chain supports the native asset, using that directly removes the exposure.

Tracking official announcements

Every credible bridge publishes security disclosures and has a public channel for them. When an exploit occurs, the response window is often minutes, so knowing where that channel lives is the difference between moving early and moving after the pool is drained.

Follow the bridge's official announcements rather than reacting to social media reposts, which frequently arrive after funds have already moved.

Why the risk is structural

Every bridge concentrates assets in one contract that must be correct. That is a different profile from a lending protocol, where user funds are spread across positions and the code holds no single pool.

Frequently asked questions

Are all bridges equally risky?

No, and the spread is wide. Established bridges with long operating history and public audits have a different risk profile from new ones offering higher yields, which is generally a signal of higher risk rather than an opportunity.

Can I use a bridge and keep my funds there?

You can, but holding a large balance on a bridge is holding a claim on that bridge's contract. If the contract is compromised, the wrapped tokens are worth whatever the attacker leaves behind.

Is bridging necessary for every network?

Often not. Several networks have canonical versions of major assets available natively, so moving the asset itself avoids the bridge entirely. Check for a native version before routing through a wrapped one.

↑ Back to top

Keep reading