In an apparent attack, one of the most prominent bridges between the Ethereum and Solana blockchains lost more than $320 million on Wednesday afternoon.
It is the largest attack on Solana, a rival to Ethereum that is gradually gaining pace in the non-fungible token (NFT) and decentralized finance (DeFi) ecosystems, and it is DeFi’s second-largest exploit ever, barely after the $600 million Poly Network crypto theft.
Ethereum is the most widely used blockchain network, and it is a major participant in the DeFi space, where programmable code known as smart contracts can take the role of middlemen such as banks and attorneys in certain types of business transactions.
Solana, a more recently launched competitor, is gaining traction as a cheaper and speedier alternative to Ethereum.
Because cryptocurrency users do not always operate within a single blockchain ecosystem, developers have created cross-chain bridges that allow users to transmit cryptocurrency from one chain to another.
Wormhole is a system that allows users to transfer tokens and non-fungible tokens (NFTs) between Solana and Ethereum.
Wormhole’s developers confirmed the breach on Twitter, stating the network is “offline for maintenance” as they investigate a “possible exploit.” The official website for the protocol is now unavailable.
According to Auston Bunsen, co-founder of QuikNode, which provides blockchain infrastructure to developers and businesses, bridges like Wormhole function by having two smart contracts – one on each chain.
There was one smart contract on Solana and one on Ethereum in this example. Wormhole is an Ethereum bridge that accepts an Ethereum token, locks it into a contract on one chain, and then issues a parallel token on the other chain.
Bridges won’t be around much longer in the crypto ecosystem, according to Ethereum founder Vitalik Buterin, in part because “fundamental limits to the security of bridges that hop across multiple ‘zones of sovereignty.’
“The $320 million hack on Wormhole Bridge highlights the growing trend of attacks against blockchains protocols,” said CertiK co-founder Ronghui Gu. “This attack is sounding the alarms of growing concern around security on the blockchain.”
To read our blog on “Most Defi hacks in 2021 had to do with centralization issues, according to Certik,” click here.
