{"investigation":{"slug":"wormhole-bridge","entity_name":"Wormhole Bridge","trust_score":63,"severity_base":null,"score_modifier":21,"confidence":0.88,"status":"published","content_type":"investigation","summary":"Wormhole Bridge is a cross-chain messaging and token bridge protocol originally developed by Certus One, later owned by Jump Crypto, enabling asset transfers between Solana, Ethereum, and other blockchains. On February 2, 2022, an attacker exploited a signature verification flaw in the Solana-side smart contract to fraudulently mint 120,000 wrapped ETH (wETH) worth approximately $320–326 million without posting collateral, making it the second-largest DeFi exploit in history at the time. Jump Crypto replenished the stolen ETH within 24 hours to prevent ecosystem collapse, and a court-authorized counter-exploit in February 2023 recovered approximately $140 million of the remaining stolen funds.","sections":[{"content":"On February 2, 2022, the Wormhole token bridge suffered a critical exploit resulting in the unauthorized minting of 120,000 wrapped Ether (wETH) on the Solana blockchain, valued at approximately $320–326 million at the time. The attack constituted the second-largest DeFi protocol theft in history up to that point. The attacker used Tornado Cash to obtain approximately 0.94 ETH for gas fees before executing the exploit. Post-attack, the attacker's Ethereum wallet address 0x629e7Da20197a5429d30da36E77d06CdF796b71A held 93,750.97 ETH, while a Solana-side wallet (CxegPrfn2ge5dNiQberUrQJkHCcimeR4VXkeawcFBBka) held 432,662.14 SOL. The Wormhole team embedded a $10 million bounty offer in a transaction sent to the attacker's wallet, which was not accepted.","heading":"The February 2022 Exploit","sources":[{"url":"https://www.coindesk.com/tech/2022/02/02/blockchain-bridge-wormhole-suffers-possible-exploit-worth-over-250m","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.bloomberg.com/news/articles/2022-02-02/blockchain-bridge-wormhole-hit-with-potential-315-million-hack","name":"bloomberg.com","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/wormhole-hack-february-2022/","name":"chainalysis.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-wormhole-hack-february-2022","name":"halborn.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The vulnerability resided in the Solana-side smart contract of the Wormhole bridge and was classified as an account confusion vulnerability stemming from the use of a deprecated, unchecked function. Specifically, the contract used load_instruction_at — a deprecated Solana function that does not validate the address of the Instructions sysvar — instead of the secure alternative load_instruction_at_checked, which performs that validation. The attacker exploited this gap by constructing a counterfeit Instructions sysvar account that mimicked a legitimate call to the Secp256k1 cryptographic program. This fake account was accepted by the verify_signatures instruction, enabling the creation of a fraudulent validator action approval (VAA). The VAA was then passed to the complete_wrapped function, which authorized the mint of 120,000 wETH on Solana without any backing ETH collateral being deposited on the Ethereum side. A fix for this exact vulnerability had been committed to Wormhole's public GitHub repository but had not yet been deployed to mainnet, raising the possibility that the attacker identified the vulnerability by reviewing the undeployed patch in the public repository before it went live.","heading":"Technical Root Cause: Signature Verification Flaw","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-wormhole-hack-february-2022","name":"halborn.com","type":"other","credibility":3},{"url":"https://immunebytes.com/blog/wormhole-bridge-hack-feb-2-2022-detailed-hack-analysis/","name":"immunebytes.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/wormhole-bridge-exploit-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://certik.medium.com/wormhole-bridge-exploit-analysis-5068d79cbb71","name":"certik.medium.com","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/wormhole-hack-february-2022/","name":"chainalysis.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Within approximately 24 hours of the exploit, Jump Crypto — the cryptocurrency division of Chicago-based proprietary trading firm Jump Trading, which owned Certus One, the original developer of Wormhole — deposited 120,000 ETH into the bridge to replenish the stolen funds. Jump Crypto stated publicly: 'Jump Crypto believes in a multichain future and that Wormhole is essential infrastructure. That's why we replaced 120K ETH to make community members whole and support Wormhole now as it continues to develop.' This action prevented a potential cascade of insolvencies across Solana-based DeFi protocols that held wETH as collateral, and prevented a confidence-driven depeg of wETH on Solana. This represented the largest-ever DeFi 'bailout' to that date. The vulnerability was patched by the Wormhole team in the immediate aftermath.","heading":"Jump Crypto Bailout and Immediate Response","sources":[{"url":"https://www.coindesk.com/business/2022/02/03/jump-trading-backstops-wormholes-320m-exploit-loss-sources","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/jump-crypto-replenishes-funds-from-320m-wormhole-hack-in-largest-ever-defi-bailout","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://decrypt.co/92709/jump-crypto-wormhole-defi","name":"decrypt.co","type":"other","credibility":3},{"url":"https://fortune.com/2022/02/04/320-million-crypto-hack-blockchain-ether-jump-trading-wormhole-refund-customer-losses/","name":"fortune.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The stolen funds remained largely dormant for nearly a year. On January 14, 2023, accounts associated with the exploit on both Ethereum and Solana became active within an hour of each other. The attacker moved approximately 95,630 ETH to the OpenOcean decentralized exchange and converted the funds into Lido Finance's staked ETH (stETH) and wrapped staked ETH (wstETH). The attacker then used approximately 25,000 wstETH as collateral to borrow 14,500,000 DAI on the MakerDAO protocol, using that DAI to acquire more stETH in a leveraged yield strategy. At peak, the exploiter was alleged to be the third-largest holder of wstETH. On February 21, 2023, Oasis.app received an order from the High Court of England and Wales directing it to take all necessary steps to retrieve assets associated with the exploit wallet. Acting on this court order, Oasis and Jump Crypto executed a counter-exploit against the attacker's Oasis vaults, exploiting an upgrade path in Oasis's own smart contracts (which used an upgradeable proxy pattern controlled by a 4-of-12 multisig). The operation recovered approximately $140 million net after DAI repayments, with funds transferred to a court-authorized third party. The action generated significant controversy in the DeFi community over the precedent of court-mandated smart contract manipulation and centralization risks inherent in 'decentralized' protocols.","heading":"Post-Exploit Fund Movement and Counter-Recovery","sources":[{"url":"https://www.elliptic.co/blog/analysis/stolen-funds-from-the-wormhole-hack-on-the-move-after-laying-dormant-for-almost-a-year","name":"elliptic.co","type":"other","credibility":3},{"url":"https://blockworks.com/news/jump-crypto-wormhole-hack-recovery","name":"blockworks.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2023/02/24/oasis-exploits-its-own-wallet-software-to-seize-crypto-stolen-in-wormhole-hack","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2023/02/27/wormhole-hacker-suffers-counter-exploit-from-jump-crypto-and-oasis-app/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://www.citationneeded.news/oasis-defi-centralization/","name":"citationneeded.news","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Wormhole undertook a substantial security overhaul. The protocol launched two separate $2.5 million bug bounty programs and engaged multiple third-party security firms to conduct audits. As of July 2023, Wormhole had completed 29 third-party security audits and made those reports publicly available. The protocol implemented additional safeguards including a Governor system and Global Accountant protocol designed to rate-limit potential future exploits. Wormhole was selected by the Uniswap DAO as one of two bridging protocols for cross-chain governance messaging, with the Uniswap Bridge Assessment Report acknowledging 'significant improvements' made in response to the exploit. In December 2023, CertiK discovered a separate $5 million vulnerability in the Wormhole bridge deployed on the Aptos blockchain, arising from an incorrect implementation of public(friend) and entry modifiers in the MOVE programming language; the flaw was patched within approximately three hours of disclosure and no funds were lost. As part of the patch, Wormhole also reduced daily withdrawal limits from Aptos from $5 million to $1 million.","heading":"Post-Hack Security Improvements","sources":[{"url":"https://techcrunch.com/2023/07/27/wormhole-new-security-320m-hack/","name":"techcrunch.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/certik-discovered-5-million-security-flaw-wormhole-bridge-aptos","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://beincrypto.com/security-flaw-aptos-wormhole-bridge/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://wormhole.foundation/blog/report-on-certiks-aptos-related-bug-bounty-2","name":"wormhole.foundation","type":"other","credibility":3},{"url":"https://immunefi.com/bug-bounty/wormhole/information/","name":"immunefi.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Wormhole exploit posed systemic risk to the broader Solana DeFi ecosystem because a significant number of Solana-based lending and trading protocols accepted wETH as collateral. Had Jump Crypto not replenished the funds, the 120,000 wETH on Solana would have been fully unbacked, creating potential for a mass liquidation event and depeg of the asset. The incident highlighted the systemic concentration risk in cross-chain bridge infrastructure, where a single smart contract vulnerability can threaten not just the bridge itself but all downstream protocols that depend on it. Chainalysis noted the hack as illustrative of a broader pattern of cross-chain bridge attacks that dominated the DeFi exploit landscape in 2022. The protocol had previously been described as securing up to $10 billion in cross-chain assets at its peak, amplifying the potential blast radius of any vulnerability.","heading":"Ecosystem Impact and Systemic Risk","sources":[{"url":"https://www.chainalysis.com/blog/wormhole-hack-february-2022/","name":"chainalysis.com","type":"other","credibility":3},{"url":"https://www.cbsnews.com/news/wormhole-ether-cryptocurrency-320-million-hack/","name":"cbsnews.com","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-wormhole-token-bridge-exploit","name":"merklescience.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2022-02-02","event":"Wormhole Bridge exploited; attacker mints 120,000 wETH (~$320-326M) on Solana without collateral using a signature verification bypass in the Solana smart contract.","source":""},{"date":"2022-02-02","event":"Wormhole team embeds a $10 million bounty offer in a transaction to the attacker's Ethereum wallet; the offer is not accepted.","source":""},{"date":"2022-02-03","event":"Jump Crypto deposits 120,000 ETH to replenish the bridge and make users whole, preventing cascading insolvencies across Solana DeFi.","source":""},{"date":"2023-01-14","event":"Attacker's Ethereum and Solana wallets activate simultaneously after nearly a year of dormancy; attacker begins converting stolen ETH into staked ETH derivatives via OpenOcean.","source":""},{"date":"2023-01-23","event":"Attacker moves approximately $155 million in ETH to decentralized exchanges, converting to stETH and wstETH and using them as collateral to borrow DAI on MakerDAO.","source":""},{"date":"2023-02-21","event":"Oasis.app receives an order from the High Court of England and Wales to retrieve assets associated with the Wormhole exploit wallet.","source":""},{"date":"2023-02-21","event":"Jump Crypto and Oasis execute a court-authorized counter-exploit against the attacker's Oasis vaults, recovering approximately $140 million net in stolen assets.","source":""},{"date":"2023-07-27","event":"TechCrunch reports on Wormhole's post-hack security overhaul including 29 third-party audits, two $2.5M bug bounty programs, and Uniswap DAO bridge selection.","source":""},{"date":"2023-12-05","event":"CertiK discovers a $5 million vulnerability in the Wormhole bridge on Aptos and discloses it to the Wormhole team; the flaw is patched within approximately three hours with no funds lost.","source":""}],"sources_used":[{"url":"https://www.coindesk.com/tech/2022/02/02/blockchain-bridge-wormhole-suffers-possible-exploit-worth-over-250m","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.bloomberg.com/news/articles/2022-02-02/blockchain-bridge-wormhole-hit-with-potential-315-million-hack","name":"bloomberg.com","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/wormhole-hack-february-2022/","name":"chainalysis.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-wormhole-hack-february-2022","name":"halborn.com","type":"other","credibility":3},{"url":"https://immunebytes.com/blog/wormhole-bridge-hack-feb-2-2022-detailed-hack-analysis/","name":"immunebytes.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/wormhole-bridge-exploit-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://certik.medium.com/wormhole-bridge-exploit-analysis-5068d79cbb71","name":"certik.medium.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/02/03/jump-trading-backstops-wormholes-320m-exploit-loss-sources","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/jump-crypto-replenishes-funds-from-320m-wormhole-hack-in-largest-ever-defi-bailout","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://decrypt.co/92709/jump-crypto-wormhole-defi","name":"decrypt.co","type":"other","credibility":3},{"url":"https://fortune.com/2022/02/04/320-million-crypto-hack-blockchain-ether-jump-trading-wormhole-refund-customer-losses/","name":"fortune.com","type":"other","credibility":3},{"url":"https://www.elliptic.co/blog/analysis/stolen-funds-from-the-wormhole-hack-on-the-move-after-laying-dormant-for-almost-a-year","name":"elliptic.co","type":"other","credibility":3},{"url":"https://blockworks.com/news/jump-crypto-wormhole-hack-recovery","name":"blockworks.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2023/02/24/oasis-exploits-its-own-wallet-software-to-seize-crypto-stolen-in-wormhole-hack","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2023/02/27/wormhole-hacker-suffers-counter-exploit-from-jump-crypto-and-oasis-app/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://www.citationneeded.news/oasis-defi-centralization/","name":"citationneeded.news","type":"other","credibility":3},{"url":"https://techcrunch.com/2023/07/27/wormhole-new-security-320m-hack/","name":"techcrunch.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/certik-discovered-5-million-security-flaw-wormhole-bridge-aptos","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://beincrypto.com/security-flaw-aptos-wormhole-bridge/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://wormhole.foundation/blog/report-on-certiks-aptos-related-bug-bounty-2","name":"wormhole.foundation","type":"other","credibility":3},{"url":"https://immunefi.com/bug-bounty/wormhole/information/","name":"immunefi.com","type":"other","credibility":3},{"url":"https://www.cbsnews.com/news/wormhole-ether-cryptocurrency-320-million-hack/","name":"cbsnews.com","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-wormhole-token-bridge-exploit","name":"merklescience.com","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":true,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T18:25:49.076085+00:00","updated_at":"2026-08-29T01:33:48.11+00:00"}}