warm background

What is cross-chain? Bridges, risks, and how it works

AdminAdmin
Published on 7 min read

Cross-chain refers to moving assets or data between separate blockchains, which cannot natively talk to each other. Bitcoin has no way to read Ethereum's ledger, so anything crossing between them needs a system standing in the middle.

Those systems have been the most reliably exploited component in crypto. Chainalysis estimated that roughly $2 billion was stolen from cross-chain bridges across 13 separate incidents in 2022, accounting for about 69% of all crypto stolen that year, and the pattern has continued since.

Why blockchains cannot talk to each other

Each blockchain is a closed system. Its nodes verify its own transactions against its own rules. Observing another chain is not something they can do at all.

Sending Bitcoin to an Ethereum address therefore does not work. The two use different address formats, different consensus rules, and entirely separate ledgers. Nothing physically moves between them, because there is no shared space for it to move through.

Cross-chain infrastructure works around that isolation. Every approach involves trusting something.

How bridges actually work

Despite the name, nothing travels across. Lock-and-mint is the standard mechanism.

  1. You send an asset to a contract on the source chain, which locks or burns it.
  2. A verifier observes that event and confirms it happened.
  3. A matching amount of a wrapped token is minted on the destination chain.

Reverse the process and the wrapped token is burned, releasing the original.

Losses happen at step 2. That verifier might be a set of validators holding keys, a multi-signature wallet, or an oracle network. Whatever it is, it decides what the destination chain believes happened on the source chain. Anyone controlling it can lie.

The main approaches

ApproachHow it worksWhat you trust
Lock and mint bridgeAsset locked on chain A, wrapped version minted on chain BThe verifier set holding the locked funds
Liquidity networkPools on both chains, you draw from the destination poolPool solvency and the relayer
[Atomic swap](/en/cryptopedia/atomic-swap)Direct peer-to-peer trade using hash timelock contractsNothing beyond the two chains' own code
Native issuanceIssuer burns on one chain and mints on another, as with Circle's CCTPThe issuer
Messaging protocolGeneral data passing between chains, not only assetsThe verifier network attesting to messages

Only atomic swaps require no trusted third party, and they need a counterparty wanting the exact opposite trade at the same moment, which is why they stayed niche.

The major bridge failures

Instructive across all of them is that the smart contracts usually were not the problem.

  • Poly Network, August 2021. Roughly $611 million taken across three chains. The attacker returned virtually all of it.
  • Wormhole, February 2022. About $320 million, after a signature verification flaw let an attacker mint 120,000 wrapped ETH without depositing collateral. Jump Crypto replaced the funds from its own reserves.
  • Ronin, March 2022. Approximately $625 million in ETH and USDC, the largest bridge exploit to date. Attackers linked to North Korea's Lazarus Group obtained five of nine validator keys, partly through a fake job offer sent to an employee. Nobody noticed for six days.
  • Nomad, August 2022. Around $190 million, after a faulty upgrade made the system treat essentially every message as valid, producing a free-for-all as others copied the exploit.
  • Kelp DAO, April 2026. Roughly $292 million, and no contract code was exploited at all. Attackers compromised two RPC nodes and knocked out a third, forcing the bridge to rely on infrastructure they controlled. The bridge used a single verifier with no independent second opinion, so the false data was accepted.

Four years apart, on entirely different technology, the failure lands in the same place. The verifier.

Wrapped tokens, and what you actually hold

Bridging usually leaves you holding a wrapped token, which is a claim rather than the asset itself, and not something you can send to a native crypto address on the original chain.

WBTC on Ethereum is not Bitcoin. It is a token backed by Bitcoin held by a custodian, and its value depends on that custodian remaining solvent and honest. Same for most bridged assets: the wrapped version is only as good as whoever holds the original.

Practically, this matters. Sending WBTC to a native Bitcoin address loses it. Two bridged versions of the same asset from different bridges are not interchangeable, either.

How to reduce the risk

  • Prefer native issuance where it exists, since Circle's CCTP and similar mechanisms remove the wrapped-token layer.
  • Check the verifier design. A single verifier or a small multi-signature is the weak point. Independent verification by separate parties is stronger.
  • Bridge small amounts and only when necessary. Every bridge transaction is exposure to a system that has historically failed.
  • Check total value locked and track record, since a bridge holding billions is a target proportionate to that amount.
  • Confirm which wrapped version you are receiving and whether your destination platform supports it.
  • Never leave large balances sitting in bridge contracts.

Where mb.io fits

Isolation between chains is why bridging exists, and it is a problem a centralized exchange sidesteps. A regulated exchange sidesteps much of that problem, since assets on different networks can be traded through one account without moving anything through a bridge contract.

mb.io is a regulated crypto spot exchange backed by MultiBank Group, a financial institution founded in 2005 that serves more than 2 million clients across 100+ countries.

  • Regulated by VARA in the UAE and AUSTRAC in Australia
  • 10/10 security score from Hacken, an independent blockchain security auditor
  • Institutional-grade MPC custody powered by Fireblocks, with segregated client funds
  • Deposit and withdrawal flows that name the network explicitly before funds move
  • Buy, sell, and swap in three steps, from sign-up to purchase
  • 24/7 customer support, on web and on the iOS and Android apps

Open your account and start trading on mb.io.

Frequently asked questions

What does cross-chain mean?

Moving assets or data between separate blockchains that have no native way to communicate. It requires infrastructure standing between the two chains and attesting to what happened on each.

Why do bridges get hacked so often?

Because they concentrate large amounts of value behind a verification step that is usually simpler than the money it guards. Ronin, Wormhole, Nomad, and Kelp DAO all failed at the verifier rather than in token logic.

Is a bridge the same as a cross-chain swap?

Not quite. A bridge moves an asset to another chain, usually creating a wrapped version. Exchanging one asset for a different one across chains is a cross-chain swap, which sometimes uses a bridge underneath.

What is a wrapped token?

A token on one chain representing an asset held on another. WBTC on Ethereum represents Bitcoin held by a custodian. Its value depends entirely on that custodian holding the backing asset.

Are atomic swaps safer than bridges?

Structurally, yes, since neither party can take the other's funds and no third party holds anything. They require a counterparty wanting the exact opposite trade at the same time, which is why they never scaled.

How much has been stolen from bridges?

Chainalysis estimated roughly $2 billion across 13 incidents in 2022 alone, about 69% of all crypto stolen that year. Losses continued afterwards, including approximately $292 million from Kelp DAO in April 2026.

Do I need to bridge to use multiple blockchains?

Not necessarily. Buying an asset natively on the chain you want, through an exchange that supports that network, avoids bridge exposure entirely.

RELATED POSTS

Frequently Asked Questions

Frequently Asked Questions

My Account
What is mb.io?mb.io is a secure, regulated crypto exchange designed to make cryptocurrency trading simple, fast, and stress-free. Whether you're buying your first Bitcoin or managing a diversified portfolio, mb.io gives you the tools you need without the complexity.Built on institutional-grade security and backed by MultiBank Group, mb.io offers spot trading with competitive fees, MPC-powered custody, and a clean interface that adapts to your experience level. Trade with confidence knowing your assets are protected by the same security standards trusted by major financial institutions.How long does account verification take?Most verifications are completed within a few minutes.Once you submit your documents, our system reviews them automatically. If everything looks good, you'll be verified and ready to trade almost immediately.In some cases, we may need to review your documents manually. This can add a bit of time, but it's usually still done the same day.Why is my account verification pending?If your verification is taking longer than expected, here are a few common reasons: Document quality issues: Blurry photos, missing corners, or glare can slow things down.Mismatched information: The details on your documents need to match what you entered during signup.High volume: During busy periods, manual reviews can take a bit longer. If your verification has been pending for more than an hour, contact our support team. They'll check what's happening and help you get verified quickly. They're available 24/7 via live chat or email.
Adding Funds
Withdrawing funds
Features
Regulations
Client Support
Account Security
Deposits & Withdrawals
View more