Bridge Exploit Postmortem Points to a Key Rotation That Never Completed
Funds were moved with a signer set the team believed it had retired eleven months earlier.
An attacker drained a cross-chain bridge using signatures from a validator set the operating team had publicly announced as decommissioned, according to the project's postmortem and on-chain evidence reviewed by MyBunnyFarm.
The rotation was executed on one side of the bridge and never finalised on the other. Monitoring covered the contract balance and the new signer set, so the stale configuration produced no alert.
Forensic analysts tracing the outflow report the funds moved through a mixing service within four hours and then sat unmoved, a pattern consistent with an attacker waiting out attribution efforts rather than an immediate cash-out attempt.
The broader lesson auditors are drawing is unglamorous: migrations, not novel cryptography, remain the dominant source of catastrophic loss. Half-completed upgrades leave a live privileged path that nobody is watching.
- exploit
- bridge
- security
- postmortem
About the author
Naomi Feldstein — Naomi Feldstein covers security: bridge exploits, custody failures, laundering typologies and the slow work of tracing stolen funds. She spent five years in incident response before turning to reporting and verifies every attribution against on-chain evidence.
Security & Forensics Reporter · Tel Aviv, Israel · More from Naomi Feldstein
Corrections to this report: corrections desk. Nothing in this article is investment advice.
