BNB Chain Bridge
Summary
The BSC Token Hub, BNB Chain's cross-chain bridge connecting BNB Beacon Chain and BNB Smart Chain, was exploited on October 6, 2022 via a forged IAVL Merkle proof that allowed an attacker to mint approximately 2 million BNB valued at roughly $566–570 million. Rapid validator coordination halted the chain and froze most funds on BSC, limiting the attacker's realized gain to an estimated $137 million, though the incident exposed deep structural centralization concerns about BNB Smart Chain's 21-validator Proof of Staked Authority model.
Connected Entities
1 entitiesTimeline(9 events)
2022-10-06
Attacker executes two transactions of 1 million BNB each via a forged IAVL Merkle proof on the BSC Token Hub bridge, minting approximately 2 million BNB (~$566–570 million).
2022-10-06
BNB Chain contacts all 44 active validators and requests they suspend block production on BNB Smart Chain to prevent further fund movement.
2022-10-06
Binance CEO Changpeng Zhao publicly confirms the exploit on Twitter, states the issue is contained and user funds are safe.
2022-10-07
BNB Smart Chain resumes operations with a hotfix. Tether and Circle blacklist the attacker's addresses, freezing $33.5 million combined in USDT and USDC.
2022-10-07
Post-incident analysis confirms approximately $137 million was moved to other chains before the halt, with roughly $430 million remaining frozen on BSC.
2022-10-11
BNB Chain announces a scheduled hard fork for October 12 to permanently patch the cross-chain bridge vulnerability.
2022-10-12
BNB Chain hard fork (client v1.1.15) executed at 08:00 UTC, patching the IAVL proof verification flaw and re-enabling the cross-chain bridge.
2022-10-13
Cosmos SDK releases coordinated security disclosures for the 'Dragonfruit' and 'Dragonberry' bugs affecting all IBC-enabled chains using the same IAVL library.
2023-02-06
BNB Chain's Planck hard fork implements BEP-171, introducing permanent security enhancements including ICS23 proof verification, transfer time-locks, and emergency channel-pause mechanisms.
Decision Log
- hash: 4BwZkzn8giT8qRVfhsctJBtjv1yqCwtiiUa5fFcmgUE3
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/30/2026, 6:25:01 PM
last updated: 5/30/2026, 6:25:03 PM
avoid.net — verified advice for a post-truth world