Bridge risk
The crossing between two blockchains is the place with the most money
What can happen
Two blockchains know nothing of each other. There is no transfer between them.
What happens instead: you deposit your tokens with a smart contract on the first blockchain. It locks them. On the second blockchain another contract then issues a stand-in - a token that represents the locked ones. The way back is the reverse: redeem the stand-in, release the original.
The decisive question is who tells the second contract that a deposit really was made on the first side. That can be a group of operators, a committee with several keys, or a procedure. Whoever it is holds the power to bring stand-ins into existence.
How that turns into a financial loss
Whoever can forge that message gets tokens for which nothing was deposited - and exchanges them for real ones.
The loss then arises not with them but with everyone else. Because now there are more stand-ins than originals. Whoever redeems first gets their money. Whoever comes later finds an empty contract.
There is a second route as well: if the link breaks without anyone attacking - because the operators fail, say - the originals are not gone but out of reach. The stand-in on the other side then loses its value even though the deposit is still there.
A documented case
DOCUMENTED CASEThe attack on the Ronin bridge, March 2022
The case shows what is peculiar to this risk: the flaw was not in the contract but in the question of whom it believes. Bridges also concentrate unusually large amounts of capital in a single place - every link between two blockchains holds as much as has crossed it. That is why they were for years among the most frequently attacked components.
Can this be the subject of a cover?
In principle yes. The event is visible onchain: the holding contract holds less than the stand-ins claim.
What is difficult here is the delimitation. A bridge consists of at least two contracts on two blockchains and a group in between. A wording that names only one address may cover precisely the side where nothing happened.
What the wording has to answer
| Which side is meant? | The holding contract, the issuing one, or both? This question decides more than any other. |
|---|---|
| Is the group in between covered? | The most common sequence begins with the operators’ keys, not in the code. If that is excluded, the product covers the rarest case. |
| What is the insured value? | The original on the outgoing side or the stand-in on the destination side? When it matters those are two different amounts. |
| Does permanent inaccessibility count too? | If nothing has flowed out but nothing can be retrieved any more: is there a loss? |
| From when does the event count as having occurred? | With the first forged withdrawal, with the discovery, or when the bridge stops? |
| What if part comes back? | In several large cases compensation followed afterwards. Does that reduce the payment, and retroactively? |
Terms used here
-
Why two blockchains fundamentally know nothing of each other.
-
The component that does the work on both sides.
-
Why stolen keys are technically indistinguishable from legitimate ones.
-
The same pattern - control rather than a code flaw - in general form.