Cross-Chain Bridges Expose Blockchain Networks to New Risks
Cross-chain bridges have become the go-to solution for enabling asset transfer and information exchange between different blockchain networks. However, this increased connectivity has also introduced new attack vectors that monolithic systems do not present.
In 2026, there were 250 attacks on DeFi protocols, resulting in losses of $1.4 billion, a reduction from the $2.7 billion lost in 146 incidents during 2025. Notably, at least eight security incidents occurred against cross-chain bridges between February and May 2026, with total stolen amounts totaling $328.6 million.
The Kelp DAO case exemplifies this risk. On April 18, an attacker exploited a bridge built on LayerZero by exploiting a deficient configuration of the verification mechanism, draining approximately 116,500 rsETH valued at $293 million. This attack vector was not a vulnerability in the smart contract code but rather a single point of failure due to inadequate key management and permission configuration.
The Gravity Bridge suffered an attack on May 30, resulting in the theft of approximately $5.4 million. Post-incident analysis revealed that this was a compromise of the validator signing key, not an exploitation of the contract itself. The attacker reduced the active validator set from 58 to 34 members and then proceeded to withdraw funds via authorized submitBatch calls.