Wormhole is the main route between Solana, Sui, Aptos and the EVM world, and its coverage of non-EVM chains is the broadest available. It is also the site of one of the largest exploits in crypto history.
What happened in 2022
A flaw in signature verification allowed an attacker to mint 120,000 wETH on Solana without depositing anything, worth around $325m at the time. Jump Crypto, a major backer, replaced the funds within days to prevent a cascade through Solana DeFi. Users were made whole because a well-capitalised backer chose to cover it, not because the protocol had a mechanism to.
The guardian model
Nineteen entities observe events on connected chains and sign attestations; a supermajority is required for a message to be accepted. These are known, reputable organisations, which makes collusion unlikely and makes the model a permissioned committee rather than cryptographic verification. Compromising a supermajority of guardian keys remains the theoretical attack.
Since then
Substantial investment in audits, formal verification and a large bug bounty, with no comparable incident in four years. The protocol has expanded into governance messaging, native token transfers and queries.
Who should use it
Users needing routes between non-EVM chains that nothing else covers, at sizes proportionate to a guardian-set trust assumption. For EVM-to-EVM transfers, Across or CCTP are structurally safer.