$815K TokenBridge Breach: Off-Chain Flaw Exposed
Alephium's TokenBridge was breached in a seven-minute attack that drained roughly $815,000 from the network. The attackers exploited an off-chain backend flaw to mint 13.76 million unbacked wrapped ALPH tokens, which is more than the bridge's entire prior wrapped supply.
The security firm Blockaid first detected the attack on May 30, and the volunteer response unit SEAL 911 quickly joined the investigation. The attackers pushed fabricated transfer approvals through the TokenBridge on both Ethereum and BNB Chain, draining the reserves and minting fresh tokens.
Alephium initially suspected that stolen guardian keys were to blame for the breach, but later revealed that an off-chain bug in the bridge backend was the actual cause. This reframe of the incident suggests that a similar flaw may exist in other bridges built on the same code.