COVER ยท RISK

Bridge risk

The crossing between two blockchains is the place with the most money

What can happen

Two blockchains know nothing of each other. There is no transfer between them.

What happens instead: you deposit your tokens with a smart contract on the first blockchain. It locks them. On the second blockchain another contract then issues a stand-in - a token that represents the locked ones. The way back is the reverse: redeem the stand-in, release the original.

The decisive question is who tells the second contract that a deposit really was made on the first side. That can be a group of operators, a committee with several keys, or a procedure. Whoever it is holds the power to bring stand-ins into existence.

How that turns into a financial loss

Whoever can forge that message gets tokens for which nothing was deposited - and exchanges them for real ones.

The loss then arises not with them but with everyone else. Because now there are more stand-ins than originals. Whoever redeems first gets their money. Whoever comes later finds an empty contract.

There is a second route as well: if the link breaks without anyone attacking - because the operators fail, say - the originals are not gone but out of reach. The stand-in on the other side then loses its value even though the deposit is still there.

A documented case

DOCUMENTED CASEThe attack on the Ronin bridge, March 2022
On 23 March 2022 attackers gained control of five of the nine keys that had to confirm, for the bridge between the gaming blockchain Ronin and Ethereum, that a withdrawal was legitimate - five was the required majority. With those keys they confirmed their own withdrawals in two transactions and took out 173,600 ether and 25.5 million USDC. It went unnoticed for six days and only came to light on 29 March, when a user could not carry out a withdrawal of 5,000 ether. The bridge’s code worked correctly - it did what properly signed messages told it to do.

The case shows what is peculiar to this risk: the flaw was not in the contract but in the question of whom it believes. Bridges also concentrate unusually large amounts of capital in a single place - every link between two blockchains holds as much as has crossed it. That is why they were for years among the most frequently attacked components.

Can this be the subject of a cover?

In principle yes. The event is visible onchain: the holding contract holds less than the stand-ins claim.

What is difficult here is the delimitation. A bridge consists of at least two contracts on two blockchains and a group in between. A wording that names only one address may cover precisely the side where nothing happened.

THE MOST USEFUL PART

What the wording has to answer

Which side is meant?The holding contract, the issuing one, or both? This question decides more than any other.
Is the group in between covered?The most common sequence begins with the operators’ keys, not in the code. If that is excluded, the product covers the rarest case.
What is the insured value?The original on the outgoing side or the stand-in on the destination side? When it matters those are two different amounts.
Does permanent inaccessibility count too?If nothing has flowed out but nothing can be retrieved any more: is there a loss?
From when does the event count as having occurred?With the first forged withdrawal, with the discovery, or when the bridge stops?
What if part comes back?In several large cases compensation followed afterwards. Does that reduce the payment, and retroactively?
ASSUMED KNOWLEDGE

Terms used here

  • Blockchain

    Why two blockchains fundamentally know nothing of each other.

  • Smart contract

    The component that does the work on both sides.

  • Signature

    Why stolen keys are technically indistinguishable from legitimate ones.

  • Protocol hack

    The same pattern - control rather than a code flaw - in general form.