Refreshed 1h ago· updates every 6h

Wormhole (2022) — Crypto Hack

Fully Recovered
Feb 2, 2022·
SolanaEthereum
Amount Stolen
$320.0M
120,000 wETH
Recovered
$320.0M
100% of stolen funds

Attacker exploited a signature verification bypass in Wormhole's Solana contract to mint 120,000 wETH without backing.

Summary

Attacker exploited a signature verification bypass in Wormhole's Solana contract to mint 120,000 wETH without backing.

How It Was Compromised — Bridge via Smart Contract Exploit

BridgeSmart Contract Exploit

The attacker found a vulnerability in Wormhole's Solana contract that allowed bypassing signature verification. By exploiting a legacy 'verify_signatures' function that was not properly deprecated, they crafted a spoofed VAA (Verified Action Approval) to mint 120,000 wETH on Solana. They then bridged 93,750 wETH to Ethereum.

Fund Flow & Laundering Analysis

Stolen ETH largely held in the attacker's wallet for months. Some converted to SOL through Jupiter aggregator. Eventually linked to Jump Crypto, which replenished the 120,000 ETH to make users whole. Attacker's identity unknown. Funds moved to various DeFi protocols.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.