{"investigation":{"slug":"bnb-chain-bridge","entity_name":"BNB Chain Bridge","trust_score":16,"severity_base":null,"score_modifier":-12,"confidence":0.88,"status":"published","content_type":"investigation","summary":"The BSC Token Hub, BNB Chain's cross-chain bridge connecting BNB Beacon Chain and BNB Smart Chain, was exploited on October 6, 2022 via a forged IAVL Merkle proof that allowed an attacker to mint approximately 2 million BNB valued at roughly $566–570 million. Rapid validator coordination halted the chain and froze most funds on BSC, limiting the attacker's realized gain to an estimated $137 million, though the incident exposed deep structural centralization concerns about BNB Smart Chain's 21-validator Proof of Staked Authority model.","sections":[{"content":"On October 6, 2022, an attacker exploited a critical vulnerability in the IAVL Merkle proof verification logic used by the BSC Token Hub cross-chain bridge. The root cause was a flaw in the Cosmos SDK IAVL tree implementation: the range proof validation code failed to enforce that internal nodes in the binary tree could only have a left child. By placing malicious data in the right-child field of a node alongside legitimate left-child data, the attacker crafted a forged proof that appeared valid without altering the computed root hash. This allowed the attacker to fabricate proof for a specific historical block (block 110217401, confirmed approximately two years earlier) and instruct the bridge to mint BNB directly to their wallet. The attack was executed in two separate transactions of 1 million BNB each, generating approximately 2 million BNB in total — valued at roughly $566–570 million at the time. The vulnerability traced to Cosmos SDK code and affected any IBC-enabled chain using the same IAVL library, prompting Cosmos to later release coordinated disclosures for the 'Dragonfruit' and related 'Dragonberry' bugs.","heading":"The Exploit: Forged Merkle Proof","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-bnb-chain-hack-october-2022","name":"halborn.com","type":"other","credibility":3},{"url":"https://medium.com/immunefi/hack-analysis-binance-bridge-october-2022-2876d39247c1","name":"medium.com","type":"other","credibility":3},{"url":"https://sanebow.me/bnb-hack-iavl-explained","name":"sanebow.me","type":"other","credibility":3},{"url":"https://www.elliptic.co/blog/analysis/attack-mints-569-million-worth-of-bnb-tokens-in-bsc-bridge-exploit","name":"elliptic.co","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the mint, the attacker began converting and bridging the stolen BNB across multiple chains and DeFi protocols to launder and extract value. On-chain analysis shows the attacker deposited 900,000 BNB and 8 million USDT as collateral into lending protocols including Venus Protocol on BSC and Banker Joe on Avalanche, and bridged assets to Ethereum, Polygon, Fantom, Avalanche, Optimism, and Arbitrum. After BNB Chain validators halted block production, the attacker's ability to move funds off BSC was severely curtailed. Approximately $137 million was successfully moved to other chains before the halt took effect. The remaining approximately $430 million in BNB remained frozen on BSC and became inaccessible to the attacker. Stablecoin issuers Tether (USDT) and Circle (USDC) separately blacklisted the attacker's addresses, freezing a combined $33.5 million of the funds that had escaped to other chains. Of the approximately $45 million in ETH and wETH that had reached the Ethereum blockchain, a significant portion was held in censorship-resistant assets that could not be frozen by issuers.","heading":"Fund Movement and Losses","sources":[{"url":"https://www.elliptic.co/blog/analysis/attack-mints-569-million-worth-of-bnb-tokens-in-bsc-bridge-exploit","name":"elliptic.co","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-the-bnb-smart-chain-exploit","name":"merklescience.com","type":"other","credibility":3},{"url":"https://www.cnbc.com/2022/10/07/more-than-100-million-worth-of-binances-bnb-token-stolen-in-another-major-crypto-hack.html","name":"cnbc.com","type":"other","credibility":3},{"url":"https://www.nansen.ai/research/bnb-chains-cross-chain-bridge-exploit-explained","name":"nansen.ai","type":"other","credibility":3}],"severity":"medium"},{"content":"Within hours of the exploit, BNB Chain coordinated all 44 active validators to suspend block production on BNB Smart Chain — an act that effectively paused the blockchain entirely and prevented the attacker from bridging additional funds off-chain. Binance CEO Changpeng Zhao (CZ) publicly confirmed the incident on Twitter, stating 'An exploit on a cross-chain bridge, BSC Token Hub, resulted in extra BNB' and that 'The issue is contained now.' The ability to halt the chain through validator coordination drew significant industry commentary. Critics argued the episode demonstrated that BNB Smart Chain is structurally centralized: its Proof of Staked Authority (PoSA) consensus at the time relied on just 21 active validators, a set small enough to be coordinated in real time via direct communication channels rather than on-chain governance. In contrast, Ethereum operates with over one million validator nodes. Binance and BNB Chain representatives argued the small validator set was a feature rather than a flaw, enabling the rapid response that limited losses. Industry analysts noted that the incident exposed a fundamental tension: chains must either be fully decentralized (and thus incapable of halting in emergencies) or explicitly centralized with designated response authority — but cannot claim both properties simultaneously.","heading":"Validator Halt and Centralization Debate","sources":[{"url":"https://cointelegraph.com/news/bnb-chain-confirms-bsc-halt-due-to-potential-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/10/10/binance-exec-bnb-smart-chain-hack-could-have-been-worse-if-validators-hadnt-sprung-into-action","name":"coindesk.com","type":"other","credibility":3},{"url":"https://fortune.com/crypto/2022/10/06/binance-smart-chain-halts-after-exploit/","name":"fortune.com","type":"other","credibility":3},{"url":"https://blockworks.com/news/after-bnb-chain-hack-operators-must-face-question-of-decentralization","name":"blockworks.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On October 12, 2022, at 08:00 UTC, BNB Chain executed a hard fork deploying a hotfix (client v1.1.15) that patched the IAVL proof verification vulnerability and re-enabled the cross-chain bridge. The hard fork was described by the team as a 'temporary urgent patch' to restore cross-chain functionality safely. BNB Chain subsequently proposed BEP-171 — a broader security enhancement for the cross-chain module — which introduced several permanent protections: upgrading IAVL proof verification to the ICS23 specification, applying time-locks on large cross-chain transfers, enabling automatic channel pausing on detection of forged proofs, and allowing any single validator to pause cross-chain channels in an emergency. The Cosmos SDK upstream also released patches addressing the 'Dragonfruit' and 'Dragonberry' vulnerabilities for all IBC-enabled chains relying on the same IAVL library. On-chain governance proposal 12 later expanded the active validator set from 21 to 26 as part of broader decentralization efforts.","heading":"Post-Exploit Remediation and Hard Fork","sources":[{"url":"https://www.coindesk.com/business/2022/10/11/bnb-smart-chain-to-perform-hard-fork-as-fix-for-100m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.bnbchain.org/en/blog/technology-update-of-bnb-chain-in-october-2022/","name":"bnbchain.org","type":"other","credibility":3},{"url":"https://github.com/bnb-chain/BEPs/pull/171","name":"github.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/bnb-beacon-chain-hard-fork-adds-panic-feature-that-can-halt-blockchain","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The BNB Chain bridge exploit was one of the largest bridge hacks in crypto history, following the $625 million Ronin Network exploit (March 2022) and the $320 million Wormhole exploit (February 2022). Cross-chain bridges aggregate large amounts of locked value and present a high-value attack surface because they rely on complex cryptographic verification logic that must work correctly across heterogeneous chain environments. The BSC Token Hub's use of a library-level Merkle proof implementation from the Cosmos SDK, without adequate independent security review of the integration, created a latent vulnerability that went undetected for at least two years. Security researchers noted that the attacker constructed the forged proof from a legitimate historical proof, implying pre-exploitation reconnaissance and technical sophistication. The incident reinforced industry consensus that bridge smart contracts and proof verification systems require formal verification and rigorous third-party audits before handling significant user funds.","heading":"Systemic Risk: Cross-Chain Bridge Architecture","sources":[{"url":"https://www.quillaudits.com/blog/hack-analysis/bsc-token-hub-bridge-hack","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://medium.com/@sharkteam/causes-of-merkle-tree-vulnerability-and-tracking-of-on-chain-funds-analysis-of-bnbchain-9aa802323754","name":"medium.com","type":"other","credibility":3},{"url":"https://arxiv.org/html/2501.03423v1","name":"arxiv.org","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-the-bnb-smart-chain-exploit","name":"merklescience.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2022-10-06","event":"Attacker executes two transactions of 1 million BNB each via a forged IAVL Merkle proof on the BSC Token Hub bridge, minting approximately 2 million BNB (~$566–570 million).","source":""},{"date":"2022-10-06","event":"BNB Chain contacts all 44 active validators and requests they suspend block production on BNB Smart Chain to prevent further fund movement.","source":""},{"date":"2022-10-06","event":"Binance CEO Changpeng Zhao publicly confirms the exploit on Twitter, states the issue is contained and user funds are safe.","source":""},{"date":"2022-10-07","event":"BNB Smart Chain resumes operations with a hotfix. Tether and Circle blacklist the attacker's addresses, freezing $33.5 million combined in USDT and USDC.","source":""},{"date":"2022-10-07","event":"Post-incident analysis confirms approximately $137 million was moved to other chains before the halt, with roughly $430 million remaining frozen on BSC.","source":""},{"date":"2022-10-11","event":"BNB Chain announces a scheduled hard fork for October 12 to permanently patch the cross-chain bridge vulnerability.","source":""},{"date":"2022-10-12","event":"BNB Chain hard fork (client v1.1.15) executed at 08:00 UTC, patching the IAVL proof verification flaw and re-enabling the cross-chain bridge.","source":""},{"date":"2022-10-13","event":"Cosmos SDK releases coordinated security disclosures for the 'Dragonfruit' and 'Dragonberry' bugs affecting all IBC-enabled chains using the same IAVL library.","source":""},{"date":"2023-02-06","event":"BNB Chain's Planck hard fork implements BEP-171, introducing permanent security enhancements including ICS23 proof verification, transfer time-locks, and emergency channel-pause mechanisms.","source":""}],"sources_used":[{"url":"https://www.halborn.com/blog/post/explained-the-bnb-chain-hack-october-2022","name":"halborn.com","type":"other","credibility":3},{"url":"https://medium.com/immunefi/hack-analysis-binance-bridge-october-2022-2876d39247c1","name":"medium.com","type":"other","credibility":3},{"url":"https://sanebow.me/bnb-hack-iavl-explained","name":"sanebow.me","type":"other","credibility":3},{"url":"https://www.elliptic.co/blog/analysis/attack-mints-569-million-worth-of-bnb-tokens-in-bsc-bridge-exploit","name":"elliptic.co","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-the-bnb-smart-chain-exploit","name":"merklescience.com","type":"other","credibility":3},{"url":"https://www.cnbc.com/2022/10/07/more-than-100-million-worth-of-binances-bnb-token-stolen-in-another-major-crypto-hack.html","name":"cnbc.com","type":"other","credibility":3},{"url":"https://www.nansen.ai/research/bnb-chains-cross-chain-bridge-exploit-explained","name":"nansen.ai","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/bnb-chain-confirms-bsc-halt-due-to-potential-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/10/10/binance-exec-bnb-smart-chain-hack-could-have-been-worse-if-validators-hadnt-sprung-into-action","name":"coindesk.com","type":"other","credibility":3},{"url":"https://fortune.com/crypto/2022/10/06/binance-smart-chain-halts-after-exploit/","name":"fortune.com","type":"other","credibility":3},{"url":"https://blockworks.com/news/after-bnb-chain-hack-operators-must-face-question-of-decentralization","name":"blockworks.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/10/11/bnb-smart-chain-to-perform-hard-fork-as-fix-for-100m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.bnbchain.org/en/blog/technology-update-of-bnb-chain-in-october-2022/","name":"bnbchain.org","type":"other","credibility":3},{"url":"https://github.com/bnb-chain/BEPs/pull/171","name":"github.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/bnb-beacon-chain-hard-fork-adds-panic-feature-that-can-halt-blockchain","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/bsc-token-hub-bridge-hack","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://medium.com/@sharkteam/causes-of-merkle-tree-vulnerability-and-tracking-of-on-chain-funds-analysis-of-bnbchain-9aa802323754","name":"medium.com","type":"other","credibility":3},{"url":"https://arxiv.org/html/2501.03423v1","name":"arxiv.org","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T18:25:01.378535+00:00","updated_at":"2026-08-29T01:35:23.575+00:00"}}