On March 23, 2022, roughly $625 million in ETH and stablecoins walked out of the Ronin bridge — the largest DeFi theft on record at the time. Nobody's monitoring system caught it. No alert fired. It was noticed six days later by a user who tried to withdraw 5,000 ETH and couldn't, because the bridge, in any meaningful sense, no longer existed. Six days of silence between the theft and its discovery. That's not a process failure. That's a diagnosis of what cross-chain bridges actually are.

Blockchains can't talk to each other. Ethereum has no idea what's happening on Solana; Solana knows nothing about Ronin. A bridge is a crutch bolted over that silence — a program that locks your coins on one chain and mints a "wrapped" copy of them on another, in your name. And it's this crutch, not the blockchains themselves, that has leaked billions of dollars since 2021.

A bridge isn't a blockchain — it's somebody's server holding keys

The magic of a blockchain is that you don't have to trust a person: every transaction's correctness is checked by the whole network against the same rules. A bridge doesn't inherit that magic. It severs it.

When you move ETH across a bridge, no real coins fly anywhere. They get locked in a contract on Ethereum, and on the other side some group — validators, oracles, relayers, whatever you call them — attests that the lock happened, and mints you an IOU copy in their own name. All the trust in the transaction now sits not on consensus math but on that group: on their keys being honest, their signature-verification code being clean, and their admin not having slipped up. A bridge takes the decentralized guarantees of two blockchains and stitches them together with one centralized thread. The three largest hacks in DeFi history snapped that thread three different ways — and not one of them was a bug in the underlying blockchain.

Ronin: when what gets hacked is a person, not code

The Ronin bridge, which served the game Axie Infinity, confirmed transactions with signatures from 9 validators; 5 signatures were enough to approve a transfer. The attackers — later attributed by the FBI to North Korea's Lazarus Group — weren't hunting for a hole in the contract. They sent an employee of Sky Mavis, the game's developer, a fake job offer over LinkedIn, complete with a "test assignment" PDF loaded with spyware. Once inside the company's systems, they got hold of the keys to four of the nine validators Sky Mavis itself controlled.

That wasn't enough — they needed a fifth signature. And it turned up somewhere nobody was watching anymore: months before the attack, during a spike in network load, the Axie DAO had temporarily delegated Sky Mavis the right to sign transactions on its behalf, to help ease the strain on infrastructure. The access was supposed to be revoked. It wasn't. The attackers got their fifth signature for free — simply because a door someone forgot to lock had been standing open the whole time.

Nothing was "hacked" in the cryptographic sense. The signatures were real. The transaction passed every check the contract ran. What got stolen wasn't code — it was trust that people had handed to each other and forgotten to take back.

Wormhole: the line of verification nobody wrote

Less than a month later, on February 2, 2022, the Wormhole bridge between Solana and Ethereum lost roughly $325 million a different way — no keys were stolen here. The attacker found a flaw in the smart-contract code itself on Solana: the program meant to verify a "guardian" signature confirming a deposit on the Ethereum side, under specific conditions, accepted a forged signature account instead of the real system one. The check technically ran — it just checked the wrong thing.

Exploiting that hole, the attacker minted 120,000 "wrapped" ETH on Solana — with zero real ETH locked on Ethereum backing it. The gap between "collateral exists on paper" and "no collateral actually exists" is exactly the crack the money leaked through. Part of the minted tokens got swapped and moved out before the hole was patched. Wormhole's parent company, Jump Crypto, filled the reserve gap out of its own pocket within a day — not because it was obligated to, but to stop the wrapped-ETH peg from collapsing and dragging the rest of the protocol down with it.

Nomad: the zero that meant "yes"

August 2022 supplied a third kind of cause — not a human failure, not a forgotten door, but a routine upgrade that broke a single check. The Nomad bridge verified cross-chain messages using a Merkle tree: every valid message needed a path up to a known "trusted root." During a contract upgrade, that trusted root got mistakenly initialized to zero — and the code interpreted zero not as "unknown" but as "already proven."

The result: any message — including a fully arbitrary one, with no real signature behind it at all — passed verification as legitimate. One person found the hole and pulled out the first funds. What happened next is something close to unique in hacking history: the attacker's transaction sat visible in the public mempool, its code copy-pasteable, its recipient address swappable for anyone's own. Within hours, hundreds of different wallets — seasoned bug hunters alongside people who had never written a smart contract in their life — tore out roughly $190 million in a spontaneous digital free-for-all. Some participants later returned funds voluntarily, calling themselves "white hats"; most didn't.

Our record: the true guide between worlds is the one who weighs each soul individually at the Scales, no exceptions, no rush. A bridge, which is supposed to be exactly that kind of guide between chains, does the opposite the instant it breaks: it lets everything through without discrimination — a stolen signature, a forged account, a zero root — because it has stopped weighing anything at all. This is the Shadow Anubis in its purest form: not a refusal to guide, but a false, premature "yes" at the gate, where silence was owed until something was actually checked.

The pattern underneath three different causes

Ronin got stolen through people, Wormhole through a bug in signature verification, Nomad through a configuration error. Three different causes. One and the same structural flaw: a bridge is a point where a staggering sum of other people's money depends on a narrow set of keys, one function of code, or one initialization variable that some single party once set up correctly — or didn't. According to the analytics firm Chainalysis, in 2022 cross-chain bridges accounted for the large majority of all funds stolen from DeFi that year, on the order of two billion dollars — and that's without counting earlier or later incidents like Poly Network (roughly $611 million, August 2021, almost entirely returned by the hacker afterward) or the Harmony Horizon bridge (roughly $100 million, June 2022, a 2-of-5 multisig compromise).

A wrapped token on another chain isn't money. It's an IOU worth exactly as much as the honesty and security of whatever system issued it. As long as you're holding that IOU, you're not a user of a decentralized network — you're a creditor to that small handful of keys, a fact the wallet interface never mentions.

Before you move anything across a bridge that you couldn't afford to lose without pain, ask the one question people rarely ask: who, exactly — how many people, with what keys, running what code — decides that your transfer is real. If the answer is unknown or vague, that vagueness is the answer. Choosing a bridge isn't a technical detail on the way to another chain. It's a choice of exactly whose judgment you're handing the power to decide what's real.