What Is a Bridge in Crypto?
Ethereum and Solana don't communicate. Arbitrum and BNB Chain don't share state. Every blockchain is its own isolated network.
Bridge connects them. Deposit assets on one chain. Receive equivalent assets on another. Move capital wherever it needs to go.
Sounds simple. Infrastructure underneath is complex. That complexity is why bridges get exploited constantly.
How Bridging Actually Works
Few different mechanisms depending on the bridge.
- Lock and mint. Most common. Send ETH to the bridge contract on Ethereum. Contract locks it. Bridge mints wrapped ETH on the destination chain. Want to go back? Burn the wrapped version. Original unlocks.
- Wrapped token represents the bridged asset. WETH on Arbitrum backed by real ETH locked in a contract on Ethereum mainnet. Bridge stays solvent, worth exactly 1 ETH. Bridge gets hacked, suddenly worth considerably less.
- Liquidity pools. Bridge maintains pools on both chains. Deposit USDC on Ethereum side. Withdraw from the pool on Arbitrum side. Faster than lock and mint. Depends on available liquidity in the pool on the destination side.
- Canonical bridges. Official bridge run by the L2 team itself. Arbitrum Bridge. Optimism Gateway. Most secure option. Slowest for withdrawals back to Ethereum. Seven day challenge period on optimistic rollups. Security mechanism not a bug. Just slow.
2022 Taught Everyone Bridge Risk the Hard Way
Bridges hold enormous amounts of locked assets. High value targets. Complex code across multiple chains. More attack surface than almost anything else in DeFi.
Ronin Bridge. March 2022. $625 million. Largest DeFi hack at the time. Validators behind the Axie Infinity bridge compromised. North Korean hackers traced later. Sky Mavis didn't notice for six days.
Wormhole. February 2022. $320 million. Smart contract vulnerability on the Solana side. Attacker minted 120,000 wrapped ETH without depositing collateral. Jump Crypto covered the loss to prevent cascade. Not every bridge has Jump Crypto backing it.
Nomad. August 2022. $190 million. Initialization bug meant any transaction could be replicated. Once someone figured it out the information spread. Hundreds of wallets drained it simultaneously. Crowd sourced exploit.
Horizon (Harmony). June 2022. $100 million. Private key compromise on multisig.
Over a billion dollars stolen from bridges in one calendar year. Pattern wasn't coincidence. Bridges are structurally difficult to secure. High value, complex code, often trusted validators as a point of failure.
Canonical vs Third Party
Two categories. Different tradeoffs.
Canonical bridges. Official. Run by the L2 team. Arbitrum, Optimism, zkSync all have their own. Most secure because the security model matches the rollup itself. Slow. Seven day withdrawal period back to Ethereum mainnet on optimistic rollups. Challenge period allows fraud proofs. Can't skip it on the canonical bridge.
Third party bridges. Stargate, Across, Hop, Synapse. Minutes instead of days. Different security assumptions. Smart contracts, liquidity pools, sometimes trusted validators or oracles. Faster means more trust required somewhere in the system.
Most users bridge through third party for speed. Most security conscious users use canonical for large amounts. Tradeoff isn't subtle.
Wrapped Tokens
Bridging often produces wrapped versions of assets.
WBTC. Bitcoin on Ethereum. Backed by real BTC held by custodians. 1:1 in theory. Depends on custodian remaining honest and solvent.
WETH. Wrapped ETH on various chains. Backed by ETH locked in bridge contracts.
Wrapped tokens inherit the risk of the bridge or custodian behind them. Asset is only as good as what's backing it. Wormhole hack created a gap where wrapped ETH on Solana temporarily wasn't fully backed. Jump Crypto filled it. Without that intervention those tokens would have deppegged.
Withdrawal Times Nobody Mentions Until It's Too Late
Moving from Ethereum to Arbitrum. Fast. Few minutes.
Moving back from Arbitrum to Ethereum via canonical bridge. Seven days. Challenge period for optimistic rollup fraud proofs.
People discover this at inconvenient moments. Need funds on mainnet. Funds sitting on Arbitrum. Canonical bridge says seven days. Third party bridge says twenty minutes for a fee.
Fast bridges charge for liquidity. Someone fronts the ETH on mainnet immediately. Gets repaid when the canonical withdrawal completes. You pay for that service.
Not a flaw in the system. Just how optimistic rollups achieve security. Worth knowing before bridging significant amounts somewhere you might need them back quickly.
