A Look at Cross-Chain vs Multi-Chain Interoperability & the Wormhole Exploit

0xReclamation@bbs profile image
Feb 3, 2022

Hey BANTER!

With the recent Wormhole Exploit causing $300Mil+ to be stolen, I thought this would be a good time to look at some points for cross-chain vs multi-chain.

Let's take a look at the Wormhole Exploit first:

Some key points from the article:

  • On Wednesday, the decentralized finance (DeFi) platform Wormhole became the victim of the largest cryptocurrency theft this year — and among the top five largest crypto hacks of all time — when an attacker exploited a security flaw to make off with close to $325 million.  
  • The attack seems to have resulted from a recent update to the project’s GitHub repository, which revealed a fix to a bug that had not yet been deployed to the project itself.
  • Wormhole provides a service known as a “bridge” between blockchains, essentially an escrow system that allows one type of cryptocurrency to be deposited in order to create assets in another cryptocurrency. This allows a person or entity with holdings in one cryptocurrency to make trades and purchases using another, somewhat like being able to fund a bank account in dollars and then use a bank card to buy something priced in euros.
  • To carry out the attack, the attacker managed to forge a valid signature for a transaction that allowed them to freely mint 120,000 wETH ... without first inputting an equivalent amount.

So at it's core, there was an exploit found in a frequently used cross-chain Bridge. This type of security vulnerability was even talked about by Vitalik earlier in January:

Basically, Vitalik makes his point that he's pessimistic of Cross-Chain interoperability due to the security limitations of bridges themselves. Since the bridges have a different layer of security than the chains they operate within, it provides a point of attack for bridges with enough liquidity locked. The Wormhole exploit doesn't follow the exact mechanics Vitalik laid out, but it still shows that bridges are a potentially vulnerable aspect of the security layer.

As bridges grow and become more common, they will become more 'valued' targets of attack. I imagine as cross-chain interoperability is developed we'll see more exploits & hacks targeting bridges.

This is also why I'm so BULLISH on Polkadot, as they provide a way for cross-chain interoperability without the need for bridges.

Updates to the protocol happen fork-free via transparent on-chain voting, so protocol development never stalls due to the lack of a clear process. The relay chain uses a sophisticated governance mechanism that is designed to establish a transparent, accountable and binding process for resolving disputes and upgrading the network.

PolkaDot uses the Relay Chain in order to handle protocol inconsitincies and to form consensus between chains. Meaning instead of having several bridges vulnerable to attack, you'd have to attack the DOT Relay Chain in order to even have a chance of hacking or exploiting the network, AND even if someone does manage to exploit it, they would still have to process transactions that fall within the consensus of cross-chain data; meaning you could revert transactions but not double spend or 'steal' coins like you could otherwise.

I urge people to take care when using cross-chain Bridges, as they will be increasingly valuable targets for blackhats moving forward.

Stay safe out there, BANTER!

5
Comments
anonymous profile image
Powered by RoundtableBuilt on infrastructure designed for real-time media. Learn more at RTB.io.© Roundtable 2026. By using this site you agree to the Terms of Use and Privacy Policy