Wormhole Bridge Exploit event
Overview
On 2 February 2022 the Wormhole token bridge, which connects Solana with Ethereum and other chains, was exploited for 120,000 wrapped ether (wETH), worth roughly $320 million at the time. The attacker exploited Wormhole's use of a deprecated Solana function, load_current_index_at, injecting a fake sysvar account to bypass signature verification and then calling complete_wrapped to mint wETH on Solana that was not backed by deposits. After a $10 million bounty offer to the attacker went unanswered, Jump Crypto — Wormhole's parent trading firm — replaced the missing ether on 3 February 2022 to keep the bridge solvent. It was the largest crypto exploit of 2022 at the time and one of the largest DeFi attacks on record.
Within the DeFi Intel graph, Wormhole Bridge Exploit connects to 3 tracked entities, most strongly to Solana, Ethereum, Wormhole.
Relations
Top connections in the DeFi Intel knowledge graph (confidence-weighted, 3 of 3 total).
| Relation | Connected entity | Confidence |
|---|---|---|
deployed_on | Solana | 95% |
deployed_on | Ethereum | 85% |
affected | Wormhole | 85% |
Frequently asked questions
How much was stolen in the Wormhole exploit?
120,000 wrapped ether, worth over $320 million at the time of the 2 February 2022 attack.
How did the attack work technically?
The attacker exploited Wormhole's reliance on the deprecated Solana function load_current_index_at, injecting a fake sysvar account to bypass signature verification and then invoking complete_wrapped to mint unbacked wETH.
Who covered the losses?
Jump Crypto, Wormhole's parent firm, supplied ether on 3 February 2022 to replace the stolen funds after a $10 million bounty offer to the hacker was ignored.
Sources
Facts on this page were verified against the following sources.