{"investigation":{"slug":"binance-bridge","entity_name":"Binance Bridge","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":0.92,"status":"published","content_type":"investigation","summary":"Binance Bridge (BSC Token Hub) was the official cross-chain bridge connecting the BNB Beacon Chain (BEP2) and BNB Smart Chain (BEP20), operated by Binance. On October 6-7, 2022, an attacker exploited a critical flaw in the bridge's IAVL Merkle proof verification logic inherited from Cosmos SDK, forging deposit proofs to mint 2 million BNB (approximately $586 million at time of exploit). Although the BNB Chain was halted by validators to contain the damage — trapping roughly $430 million on-chain — approximately $110–137 million escaped to other networks before the halt took effect.","sections":[{"content":"Binance Bridge, formally known as BSC Token Hub, served as the native cross-chain bridge between the BNB Beacon Chain (formerly Binance Chain, using BEP2 token standard) and BNB Smart Chain (BSC, using BEP20 token standard). Binance launched the bridge infrastructure in 2019 as part of its multi-chain ecosystem strategy, later expanding to support cross-chain transfers with Ethereum and other EVM-compatible networks. The bridge functioned as a vault mechanism: users would lock assets on one chain and receive pegged equivalents on the other. The BSC Token Hub smart contract was the on-chain settlement layer for these transfers, using a relay-based architecture where registered Relayers submitted cross-chain transaction proofs for verification. The bridge used a Merkle proof system derived from Cosmos SDK's IAVL (Immutable AVL tree) implementation to verify the authenticity of cross-chain messages. BNB Smart Chain launched on September 1, 2020, and the BSC Token Hub became foundational infrastructure for the BNB DeFi ecosystem. At the time of the October 2022 exploit, the bridge held billions of dollars in locked assets.","heading":"Background","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-bnb-chain-hack-october-2022","name":"","type":"other","credibility":3},{"url":"https://en.wikipedia.org/wiki/BNB_Smart_Chain_(blockchain_platform)","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On October 6, 2022, beginning at approximately 18:26 UTC, an unknown attacker executed a critical exploit against the BSC Token Hub cross-chain bridge. The attacker had previously registered as a Relayer for the BSC Cross-Chain Bridge, a prerequisite for submitting cross-chain proofs. The root cause was a flaw in the IAVL Merkle proof verification logic. The BSC Token Hub relied on a Cosmos SDK library that implemented IAVL, a binary Merkle tree structure. The verification logic contained a critical error: when validating inner nodes in the proof chain, the hash function did not incorporate the right-child leaf when the left-child leaf was populated. This meant that an attacker could craft a proof with a malicious payload in the right-child field that would nonetheless pass root-hash validation. The attacker forged proofs claiming to originate from block 110217401 — a legitimate block confirmed approximately two years prior in August 2020. Using these forged proofs, the attacker submitted falsified deposit messages to the BSC Token Hub and minted BNB directly to their wallet. The exploit was executed in two transactions: the first at 18:26 UTC minting 1 million BNB (transaction hash: 0xebf83628ba893d35b496121fb8201666b8e09f3cbadf0e269162baa72efe3b8b) and the second at 20:43 UTC minting a further 1 million BNB (transaction hash: 0x05356fd06ce56a9ec5b4eaf9c075abd740cae4c21eab1676440ab5cd2fe5c57a), totaling 2 million BNB worth approximately $586 million at the prevailing price of roughly $293 per BNB. The same class of vulnerability was later identified as the 'Dragonberry' advisory by Cosmos engineers, who determined that the flaw affected all Cosmos IBC-enabled chains using ICS-23 proof verification — though BSC Token Hub was the only bridge exploited before patches were deployed.","heading":"The $586M Exploit","sources":[{"url":"https://rekt.news/bnb-bridge-rekt","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-bnb-chain-hack-october-2022","name":"","type":"other","credibility":3},{"url":"https://medium.com/immunefi/hack-analysis-binance-bridge-october-2022-2876d39247c1","name":"","type":"other","credibility":3},{"url":"https://swarm.ptsecurity.com/binance-smart-chain-token-bridge-hack/","name":"","type":"other","credibility":3},{"url":"https://forum.cosmos.network/t/cosmos-sdk-ibc-vulnerability-retrospective-security-advisories-dragonberry-and-elderflower-october-2022/8735","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"The primary attacker wallet identified by on-chain analysts is 0x489A8756C18C0b8B24EC2a2b9FF3D4d447F79BEc on BscScan, which received both batches of minted BNB and is labeled 'BNB Bridge Exploiter' in public block explorer records. Blockchain forensics firms including Elliptic and Merkle Science traced the attacker's post-exploit fund movements in detail. Initial funding for the attacker's wallet originated from ChangeNOW exchange. After minting 2 million BNB, the attacker deposited approximately 900,000 BNB as collateral on Venus Protocol, a BNB Chain DeFi lending market, and borrowed approximately $147.5 million in stablecoins (spread across USDT, USDC, and BUSD) against that collateral position. The borrowed stablecoins were then routed across multiple EVM-compatible chains using third-party bridges including Stargate Finance and Multichain, transferred in incremental amounts of $400,000–$5 million per transaction to reduce detectability. Funds were distributed to Ethereum ($53 million), Fantom ($57 million, representing over 10% of Fantom's total value locked at the time), Avalanche, Polygon ($400,000), Optimism, and Arbitrum. The attacker also held ETH and wrapped ETH (wETH) totalling approximately $45 million in censorship-resistant assets on Ethereum that could not be frozen by issuers. Elliptic forensics noted that the attacker's post-exploit fund movement lacked the sophistication typical of professional money laundering operations, suggesting the scale of the exploit may have exceeded original expectations.","heading":"On-Chain Evidence","sources":[{"url":"https://bscscan.com/address/0x489a8756c18c0b8b24ec2a2b9ff3d4d447f79bec","name":"","type":"other","credibility":3},{"url":"https://www.elliptic.co/blog/analysis/attack-mints-569-million-worth-of-bnb-tokens-in-bsc-bridge-exploit","name":"","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-the-bnb-smart-chain-exploit","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Approximately 90 minutes after the second minting transaction, BNB Chain validators took coordinated action to halt the entire BNB Smart Chain network at around 21:35 UTC on October 6, 2022 (approximately 9:35 PM EDT). All 44 active validators were contacted and asked to temporarily suspend BSC operations. The chain remained halted for approximately 8 hours. The halt was effective at preventing the attacker from moving the 2 million BNB held within BSC, trapping approximately $430 million in assets. Binance CEO Changpeng Zhao (CZ) publicly confirmed the halt and estimated exploit in early October 7, 2022 UTC time. The chain halt was a significant event in its own right: it demonstrated that BNB Smart Chain, unlike truly decentralized networks, could be halted through coordinated action among its 44 validators — a concentration of control that attracted substantial criticism regarding the network's decentralization properties. Critics noted that the ability to halt a chain in an emergency, while pragmatically useful, reflected centralization that contrasts with public blockchain ideals. BNB Chain came back online after validators applied a hotfix release (v1.1.15) that patched the IAVL vulnerability. Separately, BNB Chain implemented a 'Moran Hardfork' on October 12, 2022, which included permanent fixes for the IAVL hash-check vulnerability.","heading":"BSC Chain Halt","sources":[{"url":"https://cointelegraph.com/news/bnb-chain-confirms-bsc-halt-due-to-potential-exploit","name":"","type":"other","credibility":3},{"url":"https://fortune.com/crypto/2022/10/06/binance-smart-chain-halts-after-exploit/","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/10/06/binance-linked-bnb-price-falls-close-to-4-on-hack-rumors","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Immediate containment actions were taken by multiple parties. Stablecoin issuers Tether and Circle froze a combined $33.5 million in USDT and USDC held by the exploiter's wallets across chains. The BNB Chain halt itself effectively froze approximately $430 million of the 2 million BNB that had not yet been bridged out. The net result was that the attacker escaped with an estimated $110–137 million in assets across various chains, with the remainder inaccessible. Binance restored cross-chain bridge operations after applying the hotfix. The Venus Protocol collateral position representing approximately 630,240 BNB remained locked in the DeFi protocol, serving as a focal point for longer-term recovery discussions. More than a year after the exploit, BNB Chain Core proposed a governance plan to force-liquidate the exploiter's collateral position on Venus Protocol, seizing the BNB collateral to repay outstanding USDT and USDC debt without resorting to open-market BNB liquidation that could depress the token price. The forced liquidation of 100% of the exploiter's USDT and USDC positions was subsequently executed. The approximately $45 million in ETH and wETH that the attacker moved to Ethereum remained outside the reach of any recovery mechanism, as these are censorship-resistant assets on a network with no administrative controls. No individual or group has been publicly identified or charged in connection with the exploit as of mid-2026.","heading":"Recovery","sources":[{"url":"https://www.elliptic.co/blog/analysis/attack-mints-569-million-worth-of-bnb-tokens-in-bsc-bridge-exploit","name":"","type":"other","credibility":3},{"url":"https://www.bankinfosecurity.com/binance-restores-cross-chain-bridge-after-569m-attack-a-20227","name":"","type":"other","credibility":3},{"url":"https://www.binance.com/en/feed/post/1452535182522","name":"","type":"other","credibility":3},{"url":"https://cryptoslate.com/binance-resumes-bsc-bridge-operation-after-2m-bnb-exploit/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"The Binance Bridge exploit is among the largest single smart contract exploits in crypto history, second only to the Ronin Bridge hack ($624 million, March 2022) in terms of gross value minted. The incident exposed several compounding risk factors. First, the IAVL verification bug represented a critical logic error in security-sensitive proof validation code that had existed in the Cosmos SDK library for an extended period without detection, demonstrating the risks of integrating external cryptographic libraries without independent audit. Second, the chain halt response, while pragmatically effective in limiting losses, revealed the centralized validator control inherent to BNB Smart Chain's 21-validator consensus architecture. This control structure allowed containment of losses but simultaneously demonstrated that the network does not provide the censorship-resistance guarantees typical of larger proof-of-work blockchains. Third, the attacker's ability to move approximately $110–137 million across multiple chains in under 90 minutes highlighted the speed at which cross-chain exploiters can disperse funds. The exploit was part of a broader pattern: cross-chain bridges collectively lost approximately $1.4 billion to exploits in 2022 alone (including Ronin, Wormhole, Nomad, and Harmony Horizon). The Dragonberry advisory indicated the IAVL flaw potentially affected all Cosmos IBC-enabled chains, though no other chain was exploited before patches were applied. The BSC Token Hub has since been patched and the bridge resumed operations; however, cross-chain bridges continue to represent the highest-risk surface area in blockchain infrastructure due to complexity of proof verification and the high-value assets they hold in custody.","heading":"Risk Assessment","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-bnb-chain-hack-october-2022","name":"","type":"other","credibility":3},{"url":"https://www.cnbc.com/2022/10/07/more-than-100-million-worth-of-binances-bnb-token-stolen-in-another-major-crypto-hack.html","name":"","type":"other","credibility":3},{"url":"https://techcrunch.com/2022/10/07/blockchain-bridge-hack/","name":"","type":"other","credibility":3},{"url":"https://forum.cosmos.network/t/cosmos-sdk-ibc-vulnerability-retrospective-security-advisories-dragonberry-and-elderflower-october-2022/8735","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2019","event":"Binance launches bridge infrastructure connecting Binance Chain and BNB Smart Chain ecosystems.","source":"","date_original":"2019-01-01"},{"date":"2020-09","event":"BNB Smart Chain (BSC) launches; BSC Token Hub becomes primary cross-chain bridge for the BNB ecosystem.","source":"","date_original":"2020-09-01"},{"date":"2022-10-06","event":"At 18:26 UTC, attacker mints first 1 million BNB via forged IAVL Merkle proof from block 110217401 to address 0x489A8756C18C0b8B24EC2a2b9FF3D4d447F79BEc. Transaction hash: 0xebf83628ba893d35b496121fb8201666b8e09f3cbadf0e269162baa72efe3b8b.","source":""},{"date":"2022-10-06","event":"At 20:43 UTC, attacker mints second 1 million BNB via second forged proof. Transaction hash: 0x05356fd06ce56a9ec5b4eaf9c075abd740cae4c21eab1676440ab5cd2fe5c57a. Total minted: 2 million BNB (~$586M).","source":""},{"date":"2022-10-06","event":"Attacker deposits 900,000 BNB as collateral on Venus Protocol and borrows approximately $147.5M in stablecoins (USDT, USDC, BUSD).","source":""},{"date":"2022-10-06","event":"Attacker bridges stolen stablecoins to Ethereum (~$53M), Fantom (~$57M), Polygon (~$400K), Avalanche, Optimism, and Arbitrum via Stargate Finance and Multichain.","source":""},{"date":"2022-10-06","event":"At approximately 21:35 UTC, all 44 BNB Smart Chain validators coordinate to halt BSC, trapping ~$430M in assets on-chain. Chain halted for approximately 8 hours.","source":""},{"date":"2022-10-07","event":"Binance CEO Changpeng Zhao (CZ) publicly confirms the exploit and chain halt. Tether and Circle freeze combined $33.5M in USDT and USDC held by the attacker.","source":""},{"date":"2022-10-07","event":"Binance restores cross-chain bridge operations after validators apply hotfix release v1.1.15 patching the IAVL verification flaw.","source":""},{"date":"2022-10-08","event":"Cosmos engineers begin intensive security review of ICS-23 implementation in response to the BSC incident, identifying the broader 'Dragonberry' vulnerability affecting all IBC-enabled Cosmos chains.","source":""},{"date":"2022-10-12","event":"BNB Chain implements Moran Hardfork with permanent IAVL hash-check vulnerability fix.","source":""},{"date":"2023-11","event":"BNB Chain Core proposes forced liquidation of exploiter's Venus Protocol collateral position. USDT and USDC positions force-liquidated to recover partial funds without open-market BNB sell-off.","source":"","date_original":"2023-11-01"}],"sources_used":[{"url":"https://www.halborn.com/blog/post/explained-the-bnb-chain-hack-october-2022","name":"","type":"other","archive_url":"http://web.archive.org/web/20260726145315/https://www.halborn.com/blog/post/explained-the-bnb-chain-hack-october-2022","credibility":3,"archive_timestamp":"2026-07-26T14:53:15+00:00"},{"url":"https://en.wikipedia.org/wiki/BNB_Smart_Chain_(blockchain_platform)","name":"","type":"other","archive_url":"http://web.archive.org/web/20260825023040/https://en.wikipedia.org/wiki/BNB_Smart_Chain_(blockchain_platform)","credibility":3,"archive_timestamp":"2026-08-25T02:30:40+00:00"},{"url":"https://rekt.news/bnb-bridge-rekt","name":"","type":"other","archive_url":"http://web.archive.org/web/20260513163534/https://rekt.news/bnb-bridge-rekt","credibility":3,"archive_timestamp":"2026-05-13T16:35:34+00:00"},{"url":"https://medium.com/immunefi/hack-analysis-binance-bridge-october-2022-2876d39247c1","name":"","type":"other","archive_url":"http://web.archive.org/web/20251126142243/https://medium.com/immunefi/hack-analysis-binance-bridge-october-2022-2876d39247c1","credibility":3,"archive_timestamp":"2025-11-26T14:22:43+00:00"},{"url":"https://swarm.ptsecurity.com/binance-smart-chain-token-bridge-hack/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260309062809/https://swarm.ptsecurity.com/binance-smart-chain-token-bridge-hack/","credibility":3,"archive_timestamp":"2026-03-09T06:28:09+00:00"},{"url":"https://forum.cosmos.network/t/cosmos-sdk-ibc-vulnerability-retrospective-security-advisories-dragonberry-and-elderflower-october-2022/8735","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829133839/https://forum.cosmos.network/t/cosmos-sdk-ibc-vulnerability-retrospective-security-advisories-dragonberry-and-elderflower-october-2022/8735","credibility":3,"archive_timestamp":"2026-08-29T13:38:39+00:00"},{"url":"https://bscscan.com/address/0x489a8756c18c0b8b24ec2a2b9ff3d4d447f79bec","name":"","type":"other","archive_url":"http://web.archive.org/web/20251016174857/https://bscscan.com/address/0x489a8756c18c0b8b24ec2a2b9ff3d4d447f79bec","credibility":3,"archive_timestamp":"2025-10-16T17:48:57+00:00"},{"url":"https://www.elliptic.co/blog/analysis/attack-mints-569-million-worth-of-bnb-tokens-in-bsc-bridge-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260511093103/https://www.elliptic.co/blog/analysis/attack-mints-569-million-worth-of-bnb-tokens-in-bsc-bridge-exploit","credibility":3,"archive_timestamp":"2026-05-11T09:31:03+00:00"},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-the-bnb-smart-chain-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260511053831/https://www.merklescience.com/blog/hack-track-analysis-of-the-bnb-smart-chain-exploit","credibility":3,"archive_timestamp":"2026-05-11T05:38:31+00:00"},{"url":"https://cointelegraph.com/news/bnb-chain-confirms-bsc-halt-due-to-potential-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20250914203235/https://cointelegraph.com/news/bnb-chain-confirms-bsc-halt-due-to-potential-exploit","credibility":3,"archive_timestamp":"2025-09-14T20:32:35+00:00"},{"url":"https://fortune.com/crypto/2022/10/06/binance-smart-chain-halts-after-exploit/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260417210415/https://fortune.com/crypto/2022/10/06/binance-smart-chain-halts-after-exploit/","credibility":3,"archive_timestamp":"2026-04-17T21:04:15+00:00"},{"url":"https://www.coindesk.com/business/2022/10/06/binance-linked-bnb-price-falls-close-to-4-on-hack-rumors","name":"","type":"other","archive_url":"http://web.archive.org/web/20260719162230/https://www.coindesk.com/business/2022/10/06/binance-linked-bnb-price-falls-close-to-4-on-hack-rumors","credibility":3,"archive_timestamp":"2026-07-19T16:22:30+00:00"},{"url":"https://www.bankinfosecurity.com/binance-restores-cross-chain-bridge-after-569m-attack-a-20227","name":"","type":"other","archive_url":"http://web.archive.org/web/20260829185041/https://www.bankinfosecurity.com/binance-restores-cross-chain-bridge-after-569m-attack-a-20227","credibility":3,"archive_timestamp":"2026-08-29T18:50:41+00:00"},{"url":"https://www.binance.com/en/feed/post/1452535182522","name":"","type":"other","archive_url":"http://web.archive.org/web/20260829144006/https://www.binance.com/en/feed/post/1452535182522","credibility":3,"archive_timestamp":"2026-08-29T14:40:06+00:00"},{"url":"https://cryptoslate.com/binance-resumes-bsc-bridge-operation-after-2m-bnb-exploit/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251113142539/https://cryptoslate.com/binance-resumes-bsc-bridge-operation-after-2m-bnb-exploit/","credibility":3,"archive_timestamp":"2025-11-13T14:25:39+00:00"},{"url":"https://www.cnbc.com/2022/10/07/more-than-100-million-worth-of-binances-bnb-token-stolen-in-another-major-crypto-hack.html","name":"","type":"other","archive_url":"http://web.archive.org/web/20260716065123/https://www.cnbc.com/2022/10/07/more-than-100-million-worth-of-binances-bnb-token-stolen-in-another-major-crypto-hack.html","credibility":3,"archive_timestamp":"2026-07-16T06:51:23+00:00"},{"url":"https://techcrunch.com/2022/10/07/blockchain-bridge-hack/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829142133/https://techcrunch.com/2022/10/07/blockchain-bridge-hack/","credibility":3,"archive_timestamp":"2026-08-29T14:21:33+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-5","created_at":"2026-05-04T02:54:47.704371+00:00","updated_at":"2026-08-30T01:16:32.890625+00:00"}}