Summary
On October 6, 2022, an attacker forged a Merkle proof against the BSC Token Hub, the cross-chain bridge of BNB Chain, and minted 2 million BNB worth roughly $570 million out of thin air. The bridge verified inbound messages from the BNB Beacon Chain using Cosmos IAVL Merkle range proofs, and the verifier had two compounding defects: it computed the tree root from the left path only (ignoring any right child), and it never rejected proof path nodes that carried both a left and a right child. So the attacker took a real, years-old proof (a 0.05 BNB transfer whose root was already trusted), kept its left path intact so the root hash stayed identical, then injected a crafted leaf authorizing a mint into a node's right field with an empty inner node for padding. After depositing 100 BNB to register as a relayer, the forged package passed the iavlMerkleProofValidate precompile at address 0x65 and the handlePackage() handler minted 1 million BNB to the attacker, executed twice. No existing user funds were touched: every stolen token was freshly minted. BNB Chain then halted its validators, freezing the bulk of the loot on-chain, so only about $100 to $137 million ever escaped to other networks.
How to fix it
- Verify IAVL and Merkle range proofs correctly: reject any path node that carries an unexpected right (or left) child, and reject proofs where both children are set.
- Ensure the computed root depends on every supplied proof node, not just the left path.
- Patch and pin the proof library (cosmos-sdk, tendermint, iavl) to fixed versions; do not carry a vendored copy that silently drifts.
- Replace open, bond-only relayer registration with an allowlist or threshold attestation so a single forged submission is not enough.
- Add per-epoch mint caps and circuit breakers so an abnormal mint trips a breaker before it can be repeated.
How to avoid it in your code
- Fuzz and formally verify cross-chain proof verifiers against forged and edge-case tree structures; the canonical invariant is that the root must be a function of all proof nodes.
- Gate privileged cross-chain handlers (handlePackage, token issuance) behind stricter authorization and value-anomaly limits.
- Never treat a freshly minted balance as equivalent to a verified deposit; isolate issuance behind independent checks.
- Keep a rehearsed validator-halt playbook as a genuine last-resort control, accepting the centralization tradeoff it implies.
Advisory details
How it happened
The attacker registered as a legitimate bridge relayer by depositing 100 BNB to the RelayerHub, then submitted a forged cross-chain package. The first mint of 1 million BNB landed around 18:26 UTC; a second attempt hit 15 failures (rejected for an out-of-order package sequence) before succeeding around 20:43 UTC, for 2 million BNB total. Rather than dump the tokens and crash the price (which would have self-defeated the theft), the attacker parked roughly 900,000 BNB as collateral on the Venus lending protocol and borrowed about $150 million in stablecoins against it, then bridged value out to Ethereum, Polygon, Fantom, Avalanche, Optimism and Arbitrum. The defect was a classic forgeable proof: the IAVL range-proof code should have verified that no path node had an unexpected child, but it did not, so a real proof could be padded with a malicious right leaf without changing the root that the bridge trusted.
The response and what it means
BNB Chain stopped the bleeding the only way a young chain could: it contacted validators one by one and halted block production roughly three hours in. By its own account the network ran 26 active validators out of 44 total at the time (the often-repeated "21 validators" figure is unverified). The halt stranded about $430 million of the minted BNB on-chain; Tether and Circle later blacklisted reachable stablecoins (around $33.5 million combined), and Elliptic estimated more than $350 million was ultimately made inaccessible, leaving only tens of millions in censorship-resistant form. The community then voted through emergency governance on whether to freeze the funds, whether to use BNB Auto-Burn to cover the loss, and on bug and recovery bounties, and the Moran hard fork (October 12, 2022) shipped the corrected IAVL check and whitelisted relayers, closing the open registration path. No individual or group was ever named. The headline that "$570 million was stolen" is misleading: about $570 million was minted, but the realized loss to the chain was far smaller, and the episode showed both how a single proof-verification bug can mint a half-billion dollars and how a fast halt can claw most of it back. It belongs to the same brutal 2022 bridge wave as Wormhole, Ronin, Nomad and Poly Network, which together pushed cross-chain bridge theft past $2 billion for the year.
References
- https://swarm.ptsecurity.com/binance-smart-chain-token-bridge-hack/
- https://www.halborn.com/blog/post/explained-the-bnb-chain-hack-october-2022
- https://medium.com/immunefi/hack-analysis-binance-bridge-october-2022-2876d39247c1
- https://blog.verichains.io/p/binance-chain-bridge-exploitation
- https://www.bnbchain.org/en/blog/bnb-chain-ecosystem-update
- https://www.elliptic.co/blog/analysis/attack-mints-569-million-worth-of-bnb-tokens-in-bsc-bridge-exploit
- https://www.nbcnews.com/tech/crypto/crypto-exchange-binance-suffers-570-million-hack-rcna51266
- https://www.chainalysis.com/blog/cross-chain-bridge-hacks-2022/
Related vulnerabilities
All Web3 →- CRITICALWEB3-KELPDAO-LAYERZERO-2026
On April 18, 2026, North Korea's Lazarus Group drained about 116,500 rsETH (roughly $292 million) from KelpDAO's LayerZero-based bridge, the largest DeFi exploit of the year. No smart contract was broken; the contracts did exactly what they were written to do. The attack was against the bridge's off-chain verification. rsETH's LayerZero channel was configured to trust a single verifier (a 1-of-1 DVN), so the attackers compromised LayerZero's internal RPC nodes, knocked out the honest external node with a denial-of-service flood, and forced that single verifier to attest to a cross-chain message that never really happened. The Ethereum side then released unbacked rsETH from escrow, leaving wrapped rsETH stranded across more than twenty chains and triggering a bank-run across DeFi.
- HIGHWEB3-FRONTEND-DNS-HIJACK-2022
A frontend hijack leaves the on-chain contracts untouched but replaces the Web2 surface serving the dApp UI with a wallet-drainer clone, so no Solidity audit can catch it. The recurring pattern: attackers take over the domain registrar or DNS provider account (or a CDN/tag-manager account), repoint the domain to a cloned site, and prompt visitors to sign malicious token approvals, EIP-2612 permit signatures, or transfers. Curve Finance was hit twice: on August 9-10, 2022 its curve.fi domain was DNS-hijacked via a compromised nameserver and drained ~$570K in USDC/DAI; and again around May 12, 2025 at the registrar level, after which Curve permanently migrated to curve.finance and announced an ENS move (Convex Finance and Resupply, which depend on Curve's data feeds, suffered dependency-driven outages but were not themselves compromised). In July 2024 a mass wave hit DeFi domains registered through Squarespace, whose forced migration off Google Domains stripped 2FA: Compound's frontend redirected to an Inferno Drainer clone and 100+ protocols were exposed (Celer blocked its takeover via domain monitoring). Ambient Finance's domain was hijacked through stolen registrar credentials on October 17, 2024. Most recently, on April 14, 2026 attackers used forged identity documents to social-engineer the registrar into handing over DNS control of CoW Swap's swap.cow.fi and cow.fi domains, redirecting users to a pixel-perfect drainer clone for about 90 minutes; over $1M was taken in roughly three hours, including 219 ETH (~$750K) from a single wallet, while CoW's contracts, backend APIs, and solver network were untouched. The same bucket includes CDN-account injections (KyberSwap's September 2022 Cloudflare/Google Tag Manager compromise, ~$265K) and BGP route hijacks that swap signed bundles for drainer code.
- HIGHWEB3-CURVE-DNS-2025
On May 12, 2025, attackers hijacked Curve Finance's primary domain, curve.fi, at the registrar and DNS level and pointed visitors at a wallet-draining clone of the site. Curve's smart contracts and on-chain funds were never touched; this was a Web2 attack on the domain, the soft underbelly that no Solidity audit can protect. The nameservers for curve.fi were swapped to attacker-controlled infrastructure at the registrar (iwantmyname, the same registrar implicated in Curve's 2022 hijack), and the clone prompted users to approve malicious token transactions. On-chain analysts estimated user losses around $520,000, most of it taken in the first ninety minutes. Curve repointed the domain to neutral nameservers, then permanently migrated to curve.finance and signaled a move toward decentralized (ENS) hosting.
- CRITICALWEB3-KILOEX-2025
On April 14, 2025 the perpetuals DEX KiloEx lost about $7.5 million across BNB Chain, Base, opBNB, and Taiko to what was reported as oracle price manipulation but was really an access-control failure. KiloEx's price feed (KiloPriceFeed.setPrices) was meant to be reachable only through a keeper-gated call chain, but the top-level MinimalForwarder.execute function was publicly callable and validated an attacker-supplied signature against attacker-supplied data, letting anyone forge a trusted call that reached setPrices and write an arbitrary price. The attacker set a market price far below true value, opened a leveraged position, then set the price far above value and closed it in the same flow, extracting fabricated profit from the vault; the sequence was repeated across all four chains, with a single transaction netting $3.12M. Reporting that framed it as flash-loan oracle manipulation was imprecise: no market liquidity was moved, the price was simply written directly through the unprotected forwarder. After KiloEx offered a 10% (~$750K) whitehat bounty and no legal action, the attacker returned essentially all of the funds by April 18, 2025.
- CRITICALWEB3-BYBIT-2025
On 21 February 2025, the crypto exchange Bybit lost about $1.5 billion in ether, the largest hack in history, to North Korea's Lazarus Group. Bybit had done what custody best-practice prescribes: the funds sat in a cold wallet behind a multisig requiring several human signers. The attackers beat it anyway, not by stealing keys but by tampering with what the signers saw. Weeks earlier they had compromised a developer at Safe, the multisig-wallet provider, and slipped malicious code into the Safe web app, so that when Bybit's executives reviewed a routine transfer, the screen showed a legitimate transaction while their hardware wallets were actually signing a malicious one that handed the wallet to the attacker. It is the defining lesson that a multisig is only as trustworthy as the screen you approve it on, and that blind-signing is the modern crypto catastrophe.
- CRITICALWEB3-RADIANT-2024
On October 16, 2024, the cross-chain lending protocol Radiant Capital lost roughly $50M (about $53M across Arbitrum and BSC) after attackers compromised the devices of at least three of its multisig signers. Initial access began September 11, 2024 via a Telegram message spoofing a trusted former contractor, delivering a ZIP with a decoy PDF that was actually a macOS application carrying INLETDRIFT backdoor malware. The malware sat between the signers' browsers and their hardware wallets, so the Safe (Gnosis) UI and Tenderly simulations displayed correct data while the signers blind-signed a malicious transferOwnership() call on the LendingPoolAddressesProvider contract; the 3-of-11 threshold was met and the attacker then upgraded the pools to a malicious implementation and drained them. Mandiant assessed with high confidence the attack was conducted by North Korea-linked UNC4736 (aka Citrine Sleet/AppleJeus), part of the Lazarus cluster. Funds were not recovered and the protocol later wound down.