{"investigation":{"slug":"bridgelink-crossflow-relay-protocol-june-14-cross-chain-exploit-127m","entity_name":"BridgeLink / CrossFlow / Relay Protocol — June 14 Cross-Chain Exploit ($127M)","trust_score":0,"severity_base":null,"score_modifier":-25,"confidence":0.18,"status":"under_investigation","content_type":"investigation","summary":"BridgeLink, CrossFlow, and Relay Protocol are three DeFi bridge protocols alleged to have been drained of a combined $127 million in a coordinated cross-chain exploit beginning at 03:42 UTC on June 14, 2026. The incident is described as exploiting a signature replay vulnerability combined with premature finality acceptance across Ethereum, Arbitrum, and Polygon. As of June 16, 2026, no Tier 1 or Tier 2 sources — including CoinDesk, The Block, Reuters, or Bloomberg — have published corroborating coverage, and no on-chain transaction hashes or official protocol statements have been publicly produced; the investigation page reflects low source confidence accordingly.","sections":[{"content":"All primary factual claims about this exploit derive exclusively from a single blog post published June 17, 2026 by Nadcab Labs (nadcab.com), a blockchain software development vendor. The Nadcab article does not cite on-chain transaction hashes, does not link to official statements from any affected protocol, does not reference regulatory filings, and explicitly notes that 'specific protocol names are withheld pending forensic completion' — a caveat inconsistent with its own specific loss figures. Two other URLs cited in the investigation request (Phemex and 1inch blog) were fetched directly; neither article contained any reference to BridgeLink, CrossFlow, Relay Protocol, or this exploit. No Tier 1 outlet (Reuters, Bloomberg, WSJ, NYT) and no established Tier 2 crypto outlet (CoinDesk, The Block, Decrypt, Chainalysis) has published coverage of this specific event as of June 21, 2026. DefiLlama's hacks database, which catalogues major DeFi exploits in near-real-time, returned no results for these three protocols. The entirety of the verifiable factual record rests on a single Tier 3 source with no corroboration. All claims in subsequent sections should be treated as alleged and low-confidence.","heading":"Source Reliability Assessment","sources":[{"url":"https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain","name":"$127M Stolen in DeFi Bridge Cross-Chain Hack — Nadcab Labs","type":"other","credibility":3},{"url":"https://defillama.com/hacks","name":"DeFi Hacks & Exploits Database — DefiLlama (no listing found for these protocols)","type":"research","credibility":2}],"severity":"critical"},{"content":"BridgeLink, CrossFlow, and Relay Protocol are described as cross-chain bridge protocols facilitating asset transfers between Ethereum mainnet, Arbitrum, and Polygon. No Tier 1 or Tier 2 independent sources confirm the prior existence, TVL, audit history, team composition, or governance structure of any of the three protocols before the alleged June 14, 2026 exploit. Searches across CoinDesk, The Block, Reuters, Bloomberg, and DefiLlama returned no pre-exploit coverage of any of these three named entities. The absence of prior coverage in established crypto media for protocols allegedly holding tens of millions of dollars in liquidity is a significant anomaly that cannot be resolved with available sources. No GitHub repositories, official documentation sites, or token contract addresses have been independently verified. The alleged Relay Protocol governance token is described as having traded at $0.67 before the event and falling to $0.46 afterward; no exchange listing or contract address corroborates this claim.","heading":"Protocol Identity and Background","sources":[{"url":"https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain","name":"$127M Stolen in DeFi Bridge Cross-Chain Hack — Nadcab Labs","type":"other","credibility":3}],"severity":"high"},{"content":"According to the Nadcab Labs article, the attack combined two vulnerability classes: a signature replay attack and finality manipulation. Validators in the alleged bridge multi-signature quorum signed messages without including chain-specific nonces or block height identifiers, enabling valid Ethereum signatures to authorize fraudulent withdrawal transactions on Arbitrum and Polygon. The bridge allegedly accepted cross-chain messages after one block confirmation rather than waiting for Ethereum's finality window of approximately 12 to 15 minutes (two epochs). The attacker allegedly compromised API keys from two of nine validator nodes, achieving the quorum threshold of five-of-nine. The attack is alleged to have executed 47 transactions across multiple chains in under 12 minutes, beginning at 03:42 UTC and flagged by automated monitoring at 03:54 UTC when anomalous mint events appeared on Arbitrum. By that point, $43 million in stablecoins had allegedly already been liquidated through decentralized exchanges. These vulnerability classes — signature replay without domain separation and premature finality acceptance — are documented real-world bridge attack vectors, as confirmed by academic literature and industry security resources. However, no independent security researcher, blockchain analytics firm, or on-chain forensics report has published analysis of transactions matching this event.","heading":"Alleged Exploit Mechanics","sources":[{"url":"https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain","name":"$127M Stolen in DeFi Bridge Cross-Chain Hack — Nadcab Labs","type":"other","credibility":3},{"url":"https://arxiv.org/html/2511.09134v1","name":"One Signature, Multiple Payments: Demystifying and Detecting Signature Replay Vulnerabilities in Smart Contracts — arXiv","type":"research","credibility":2},{"url":"https://orbitalxploration.com/cross-chain-bridge-security-avoiding-replay-relayer-and-validator-risks","name":"Cross-Chain Bridge Security: Avoiding Replay, Relayer, and Validator Risks — Orbital Exploration","type":"research","credibility":3}],"severity":"critical"},{"content":"The Nadcab Labs article alleges total losses of $127 million distributed across three protocols: BridgeLink ($52 million), CrossFlow ($48 million), and Relay Protocol ($27 million). The article further breaks down the aggregate loss as $89 million from primary bridge liquidity pools, $23 million from wrapped token reserves, and $15 million from market maker positions. As of June 16, 2026, approximately $89 million allegedly remained liquid across chains, with $38 million allegedly converted to privacy-preserving tokens — described as Tornado Cash equivalents and Monero — to evade freeze attempts. Blockchain forensics is alleged to have traced only 18% of funds to known exploit wallets, with the remainder moving through privacy layers. The primary attacker wallet is identified in the source as 0x7f3a...9c2d, a truncated address that cannot be independently verified on Etherscan or any on-chain explorer with the information provided. No freeze order, exchange cooperation notice, or stablecoin issuer blacklist action has been independently confirmed for addresses linked to this exploit.","heading":"Alleged Financial Losses","sources":[{"url":"https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain","name":"$127M Stolen in DeFi Bridge Cross-Chain Hack — Nadcab Labs","type":"other","credibility":3}],"severity":"critical"},{"content":"The Nadcab Labs article alleges that five institutional market makers suffered direct financial exposure from the exploit. Named firms and alleged losses include Wintermute ($12 million in isolated pools), Jump Crypto ($18 million in unreconciled positions), GSR ($9 million in pending withdrawals), and Amber Group ($7 million in bridge-connected liquidity), with a fifth unnamed firm accounting for approximately $11 million. The article does not include any direct quotes, official statements, or press releases from any of these firms. No independent financial media (Bloomberg, Reuters, WSJ) or crypto media (The Block, CoinDesk) has published reporting confirming that Wintermute, Jump Crypto, GSR, or Amber Group experienced losses in a June 2026 bridge exploit. Wintermute, Jump Crypto, and GSR are real, well-documented market makers active in DeFi, making their naming in an unverified context particularly notable. The specific figures and firm-by-firm allocations should be treated as unverified allegations absent confirmation from the named parties or independent reporting.","heading":"Alleged Institutional Market Maker Exposure","sources":[{"url":"https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain","name":"$127M Stolen in DeFi Bridge Cross-Chain Hack — Nadcab Labs","type":"other","credibility":3},{"url":"https://insights4vc.substack.com/p/inside-jump-crypto-13b-terra-trade","name":"Inside Jump Crypto: $1.3B Terra Trade, $321M Wormhole Rescue & More — Insights4VC","type":"other","credibility":3}],"severity":"high"},{"content":"The Nadcab Labs article and derivative search engine summaries allege that the SEC and CFTC opened emergency regulatory scrutiny within hours of the breach, focusing on whether bridge operators failed to implement adequate security controls for institutional-grade infrastructure. No SEC press release, CFTC enforcement notice, or official government statement corroborating an open investigation has been located. The SEC press release archive (sec.gov/newsroom/press-releases) and the CFTC enforcement actions page were checked and returned no relevant filings for June 2026 relating to BridgeLink, CrossFlow, or Relay Protocol. Industry observers have noted generally that the SEC and CFTC have been active in crypto regulation in 2026 following the CLARITY Act window and joint interpretive guidance, but no specific enforcement action tied to this alleged incident has been documented in Tier 1 sources.","heading":"Alleged Regulatory Response","sources":[{"url":"https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain","name":"$127M Stolen in DeFi Bridge Cross-Chain Hack — Nadcab Labs","type":"other","credibility":3},{"url":"https://www.sec.gov/newsroom/press-releases","name":"SEC Press Releases — SEC.gov (no relevant filing found)","type":"regulatory","credibility":1},{"url":"https://www.foley.com/insights/publications/2026/01/shifting-enforcement-priorities-at-the-cftc-and-the-sec/","name":"Shifting Enforcement Priorities at the CFTC and the SEC — Foley & Lardner","type":"other","credibility":2}],"severity":"high"},{"content":"The June 14 alleged exploit, if confirmed, would rank among the most significant cross-chain bridge attacks of 2026. Verified Tier 2 reporting documents a pattern of bridge exploits in 2026: the Kelp DAO rsETH incident (April 2026, approximately $292 million in unauthorized minting via a single-DVN LayerZero configuration, covered by Chainalysis and CoinDesk), the Verus-Ethereum bridge loss ($11 million, May 2026, covered by CoinDesk), and the CrossCurve bridge exploit (approximately $3 million via spoofed messages, covered by The Block). A separately documented exploit exceeding $300 million has been reported by Cybernews as the largest DeFi exploit of 2026, though details differ from the $127 million figure attributed to this case. Cumulative bridge losses since 2022 are estimated at over $2.8 billion according to Tier 3 aggregator sources. The vulnerability classes alleged in the June 14 incident — signature replay without chain-specific domain separation, and premature finality acceptance — are genuine, well-documented attack surfaces that have been exploited in confirmed historical incidents including the Wormhole ($320 million, February 2022) and Ronin ($625 million, March 2022) bridge hacks.","heading":"Broader 2026 Cross-Chain Bridge Exploit Context","sources":[{"url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/","name":"Inside the KelpDAO Bridge Exploit — Chainalysis","type":"research","credibility":2},{"url":"https://www.coindesk.com/markets/2026/05/18/yet-another-crypto-bridge-falls-victim-to-an-usd11-million-hack","name":"Verus-Ethereum bridge loses $11 million as hackers keep targeting cross-chain infrastructure — CoinDesk","type":"news_article","credibility":2},{"url":"https://www.theblock.co/post/387939/crosscurve-bridge-exploited-for-approximately-3-million-across-multiple-chains-via-spoofed-messages","name":"CrossCurve bridge exploited for approximately $3 million across multiple chains via spoofed messages — The Block","type":"news_article","credibility":2},{"url":"https://cybernews.com/crypto/300m-stolen-in-cross-chain-bridge-hack-largest-defi-exploit-of-2026/","name":"$300M stolen in cross-chain bridge hack, largest DeFi exploit of 2026 — Cybernews","type":"news_article","credibility":2},{"url":"https://blockworks.com/news/in-second-largest-defi-hack-ever-blockchain-bridge-loses-320m-ether","name":"In Second Largest DeFi Hack Ever, Blockchain Bridge Loses $320M Ether — Blockworks","type":"news_article","credibility":2}],"severity":"medium"}],"timeline":[{"date":"2026-06-14","event":"Alleged exploit begins at 03:42 UTC. Fraudulent cross-chain messages allegedly clear validator set on Ethereum mainnet, initiating unauthorized minting on Arbitrum.","source":"$127M Stolen in DeFi Bridge Cross-Chain Hack — Nadcab Labs (Tier 3, unverified)","source_url":"https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain"},{"date":"2026-06-14","event":"Automated monitoring allegedly flags abnormal mint events on Arbitrum at 03:54 UTC, 12 minutes after attack initiation. $43 million in stablecoins allegedly already liquidated through DEXes by this point.","source":"$127M Stolen in DeFi Bridge Cross-Chain Hack — Nadcab Labs (Tier 3, unverified)","source_url":"https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain"},{"date":"2026-06-14","event":"Five major market making platforms allegedly trigger emergency trading halts. Wintermute allegedly pauses all cross-chain strategies at 04:10 UTC.","source":"$127M Stolen in DeFi Bridge Cross-Chain Hack — Nadcab Labs (Tier 3, unverified)","source_url":"https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain"},{"date":"2026-06-14","event":"Attacker allegedly splits funds across 14 intermediary addresses and begins bridging portions to Polygon and Optimism. Primary wallet identified in source as 0x7f3a...9c2d (truncated, unverified).","source":"$127M Stolen in DeFi Bridge Cross-Chain Hack — Nadcab Labs (Tier 3, unverified)","source_url":"https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain"},{"date":"2026-06-14","event":"SEC and CFTC alleged to have opened emergency regulatory scrutiny of bridge operators. No official government filing has been independently located to corroborate this claim.","source":"$127M Stolen in DeFi Bridge Cross-Chain Hack — Nadcab Labs (Tier 3, unverified)","source_url":"https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain"},{"date":"2026-06-16","event":"Approximately $89 million alleged to remain liquid across chains. $38 million allegedly converted to privacy-preserving tokens (Tornado Cash equivalents and Monero). Blockchain forensics alleged to have traced only 18% of funds.","source":"$127M Stolen in DeFi Bridge Cross-Chain Hack — Nadcab Labs (Tier 3, unverified)","source_url":"https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain"},{"date":"2026-06-17","event":"Nadcab Labs publishes blog article describing the exploit. Article contains no transaction hashes, no official protocol statements, and no regulatory citations. This remains the sole identifiable source for the event.","source":"$127M Stolen in DeFi Bridge Cross-Chain Hack — Nadcab Labs","source_url":"https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain"},{"date":"2026-06-21","event":"AVOID.NET investigation conducted. No Tier 1 or Tier 2 independent corroboration found for BridgeLink, CrossFlow, or Relay Protocol as entities or for the $127M June 14 exploit. DefiLlama hacks database returns no matching entries.","source":"AVOID.NET investigation","source_url":"https://www.avoid.net"}],"sources_used":[{"url":"https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain","name":"$127M Stolen in DeFi Bridge Cross-Chain Hack — Nadcab Labs","type":"other","archive_url":"https://web.archive.org/web/20260727014307/https://www.nadcab.com/blog/defi-bridge-exploit-june-cross-chain","credibility":3,"archive_timestamp":"2026-07-27T01:43:07+00:00"},{"url":"https://defillama.com/hacks","name":"DeFi Hacks & Exploits Database — DefiLlama","type":"research","archive_url":"http://web.archive.org/web/20260726034353/https://defillama.com/hacks","credibility":2,"archive_timestamp":"2026-07-26T03:43:53+00:00"},{"url":"https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/","name":"Inside the KelpDAO Bridge Exploit — Chainalysis","type":"research","archive_url":"http://web.archive.org/web/20260730015225/https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/","credibility":2,"archive_timestamp":"2026-07-30T01:52:25+00:00"},{"url":"https://www.coindesk.com/markets/2026/05/18/yet-another-crypto-bridge-falls-victim-to-an-usd11-million-hack","name":"Verus-Ethereum bridge loses $11 million — CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20260526034614/https://www.coindesk.com/markets/2026/05/18/yet-another-crypto-bridge-falls-victim-to-an-usd11-million-hack","credibility":2,"archive_timestamp":"2026-05-26T03:46:14+00:00"},{"url":"https://www.theblock.co/post/387939/crosscurve-bridge-exploited-for-approximately-3-million-across-multiple-chains-via-spoofed-messages","name":"CrossCurve bridge exploited for approximately $3 million — The Block","type":"news_article","archive_url":"http://web.archive.org/web/20260211183757/https://www.theblock.co/post/387939/crosscurve-bridge-exploited-for-approximately-3-million-across-multiple-chains-via-spoofed-messages","credibility":2,"archive_timestamp":"2026-02-11T18:37:57+00:00"},{"url":"https://cybernews.com/crypto/300m-stolen-in-cross-chain-bridge-hack-largest-defi-exploit-of-2026/","name":"$300M stolen in cross-chain bridge hack, largest DeFi exploit of 2026 — Cybernews","type":"news_article","archive_url":"https://web.archive.org/web/20260727095149/https://cybernews.com/crypto/300m-stolen-in-cross-chain-bridge-hack-largest-defi-exploit-of-2026/","credibility":2,"archive_timestamp":"2026-07-27T09:51:49+00:00"},{"url":"https://phemex.com/blogs/defi-hacks-2026-bridge-exploits-explained","name":"Every Major DeFi Hack in 2026 So Far — Phemex","type":"other","archive_url":"http://web.archive.org/web/20260822233805/https://phemex.com/blogs/defi-hacks-2026-bridge-exploits-explained","credibility":3,"archive_timestamp":"2026-08-22T23:38:05+00:00"},{"url":"https://1inch.com/blog/post/the-biggest-bridge-hacks-in-2026","name":"Why crypto bridges still get hacked in 2026 — 1inch Blog","type":"other","archive_url":"https://web.archive.org/web/20260726231127/https://1inch.com/blog/post/the-biggest-bridge-hacks-in-2026","credibility":3,"archive_timestamp":"2026-07-26T23:11:27+00:00"},{"url":"https://arxiv.org/html/2511.09134v1","name":"One Signature, Multiple Payments: Demystifying and Detecting Signature Replay Vulnerabilities in Smart Contracts — arXiv","type":"research","archive_url":"http://web.archive.org/web/20251113030205/https://arxiv.org/html/2511.09134v1","credibility":2,"archive_timestamp":"2025-11-13T03:02:05+00:00"},{"url":"https://www.sec.gov/newsroom/press-releases","name":"SEC Press Releases — SEC.gov","type":"regulatory","archive_url":"http://web.archive.org/web/20260716153738/https://www.sec.gov/newsroom/press-releases","credibility":1,"archive_timestamp":"2026-07-16T15:37:38+00:00"},{"url":"https://www.foley.com/insights/publications/2026/01/shifting-enforcement-priorities-at-the-cftc-and-the-sec/","name":"Shifting Enforcement Priorities at the CFTC and the SEC — Foley & Lardner","type":"other","archive_url":"http://web.archive.org/web/20260514043043/https://www.foley.com/insights/publications/2026/01/shifting-enforcement-priorities-at-the-cftc-and-the-sec/","credibility":2,"archive_timestamp":"2026-05-14T04:30:43+00:00"},{"url":"https://blockworks.com/news/in-second-largest-defi-hack-ever-blockchain-bridge-loses-320m-ether","name":"In Second Largest DeFi Hack Ever, Blockchain Bridge Loses $320M Ether — Blockworks","type":"news_article","archive_url":"http://web.archive.org/web/20260316205159/https://blockworks.com/news/in-second-largest-defi-hack-ever-blockchain-bridge-loses-320m-ether","credibility":2,"archive_timestamp":"2026-03-16T20:51:59+00:00"},{"url":"https://www.cryptotimes.io/2026/05/18/crypto-bridge-hacks-top-328m-in-2026-as-cross-chain-exploits-accelerate/","name":"Crypto Bridge Hacks Top $328M in 2026 — CryptoTimes","type":"news_article","archive_url":"http://web.archive.org/web/20260726153716/https://www.cryptotimes.io/2026/05/18/crypto-bridge-hacks-top-328m-in-2026-as-cross-chain-exploits-accelerate/","credibility":3,"archive_timestamp":"2026-07-26T15:37:16+00:00"},{"url":"https://www.autheo.com/blog/bridge-security-lessons-hyperbridge-exploit-2026","name":"Bridge Security After the Hyperbridge Exploit — Autheo Blog","type":"other","archive_url":"https://web.archive.org/web/20260727005431/https://www.autheo.com/blog/bridge-security-lessons-hyperbridge-exploit-2026","credibility":3,"archive_timestamp":"2026-07-27T00:54:31+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-06-21T12:05:18.993921+00:00","updated_at":"2026-09-01T04:46:02.802537+00:00"},"source_quality":{"total":16,"tier1":1,"tier2":3,"tier3":0,"unrated":12},"follower_count":null}