Cross-Chain Bridge Drained of $120 Million in Validator Key Exploit
A mid-tier cross-chain bridge lost $120 million after attackers compromised enough validator signing keys to clear its multisig threshold, reigniting the debate over custodial bridge design.
A cross-chain bridge has been drained of roughly $120 million after attackers compromised a sufficient number of validator signing keys to clear the multisig threshold guarding its asset reserves, according to on-chain data reviewed in the hours after the exploit. The bridge, used to move assets between a mid-tier layer-1 network and Ethereum, halted withdrawals within the hour but not before the attacker had moved the bulk of the stolen funds through a series of decentralised exchanges and into privacy-preserving mixers.
How the multisig failed
The bridge in question operated on a nine-of-fourteen validator signature scheme, a design meant to ensure that no single compromised party could authorise a fraudulent withdrawal. Early forensic analysis suggests the attacker did not need to breach nine separate infrastructures independently. Instead, several validator nodes appear to have shared underlying cloud infrastructure and key-management tooling provided by a single third-party operator, meaning one point of failure in that shared stack could plausibly have exposed multiple signing keys at once. If confirmed, that would mean the nominal security of a nine-of-fourteen threshold was, in practice, closer to a two-of-three.
This is not a new failure mode. It is a near-exact echo of bridge exploits going back years, in which a validator set that is decentralised on paper turns out to be operationally centralised in the infrastructure it depends on. Auditors have flagged this class of risk repeatedly; bridges have kept shipping anyway, because building genuinely independent validator infrastructure is expensive and slow, and because the commercial pressure to launch a bridge quickly rarely rewards the operator who takes the cautious route.
The recurring argument against custodial bridges
The attack has revived a familiar argument among infrastructure engineers: that lock-and-mint bridges secured by a validator multisig are fundamentally a trusted custodian wearing a decentralised costume, and that the industry should be moving toward native interoperability standards that rely on the security of the underlying chains themselves rather than an intermediary committee. Light-client-based bridges and shared-security models have existed as proposals for years, but they are harder to build, slower to finalise, and less flexible for supporting new chains quickly — which is exactly why the custodial model remains dominant despite its now well-documented failure pattern.
Bridges of this design have collectively lost several billion dollars to exploits since 2021, a figure that dwarfs losses from smart-contract bugs elsewhere in DeFi. The asymmetry is telling: a bridge holds a large, centralised pool of assets behind a comparatively small set of signing keys, which makes it a far more efficient target than picking off individual protocols one exploit at a time.
What happens next
The bridge's team has offered the attacker a bounty in exchange for returning the bulk of the funds, a now-standard negotiating tactic that occasionally works when the attacker judges the legal exposure of cashing out to outweigh the reward for keeping it. Given the speed with which funds were routed through mixers, that outcome looks unlikely here. For users, the practical lesson has not changed in three years of near-identical headlines: bridge risk is custodial risk dressed up in decentralised language, and the size of the validator set printed in a project's documentation says very little about how independent those validators actually are underneath.



