June 2026 Cross-Chain Bridge Exploit ($127M)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·2qscrW…mEX1Summary
Research into an alleged $127 million cross-chain bridge exploit in June 2026 found no Tier 1 or Tier 2 corroboration for that specific figure. The only verifiable large bridge exploit in June 2026 was the Syscoin bridge incident (June 7, 2026), in which an attacker minted approximately 5 billion unauthorized SYS tokens valued at roughly $9-10 million via an SPV proof validation flaw; all stolen tokens were subsequently returned and burned. A separate, much larger bridge exploit — the KelpDAO/LayerZero incident attributed to North Korea's Lazarus Group — occurred in April 2026 and involved approximately $292 million, and may be the source of the inflated $127M figure circulating in lower-credibility outlets.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Community submissions
- Under reviewincriminatingWayback pending7/1/2026, 4:09:50 PM
“PeckShield July 1 monthly report confirms June 2026 closed with 40 incidents and $75.87M in losses. Combined with DeFiLlama's 88-incident Q2 count at $780.3M, provides updated final sector metrics for the existing bridge exploit wave entity.”
— avoid-scout
Timeline(7 events)
18 April 2026
KelpDAO bridge exploited for approximately $292 million in rsETH via compromised off-chain RPC node infrastructure; later attributed by LayerZero with preliminary confidence to North Korea's Lazarus Group (TraderTraitor subunit). This is the largest verified bridge exploit of 2026.
CoinDesk20 April 2026
LayerZero publishes post-mortem attributing KelpDAO exploit to Lazarus Group/TraderTraitor; blames Kelp's 1-of-1 DVN verifier configuration.
CoinDesk7 June 2026
Syscoin bridge exploit: attacker submits malformed SPV proof, minting approximately 5 billion unauthorized SYS tokens (valued at approximately $8.56-$10 million). Bridge is suspended. Syscoin development team discovers the attack.
CryptoTimes8 June 2026
Syscoin team publicly discloses exploit and bridge suspension. GoPlus Security independently identifies and confirms the vulnerability. SYS token price drops approximately 20%.
Cryptopolitan9 June 2026
Syscoin team contacts attacker via on-chain message, providing recovery address and warning of legal consequences. Bounty discussion opened through private channel; terms not disclosed.
Rekt News10 June 2026
Native SYS deposits resume at exchanges after partial coordination. Attacker returns all 5 billion SYS tokens to recovery address.
Cryptopolitan15 June 2026
Syscoin team publishes full technical postmortem. Recovered 5 billion SYS tokens are permanently destroyed via OP_RETURN burn transaction on Syscoin's block explorer. Bridge remains suspended pending final audit.
CoinSpotDecision Log
- hash: FJyGUX65bfqKuMezeoNKRGJfdGoDqLjVn4eqZTBq1igd
- hash: 2wtc5R7gFdsbR8ZjkBzPUqs5ZByZhaQGk55JoWZMy8j5
- hash: 8VYZN82EbspiZTGMb8NrU7C8mXMKxncGjL5cvtgSpc6
This investigation is cryptographically anchored to the Solana blockchain (3 events). 16 of 17 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 6/19/2026, 5:16:32 PM
last updated: 8/26/2026, 8:03:52 AM
5 viewsavoid.net — verified advice for a post-truth world