Key Takeaways
Quick answer
A crypto bridge moves tokens or data between blockchains that cannot communicate on their own. Often it locks your tokens on one chain and creates a matching token on the other. Bridges hold large pools of funds; the FBI has reported bridge thefts worth hundreds of millions of dollars.
- Blockchains cannot natively talk to each other, so bridges move tokens and messages between them.
- Most bridges lock or burn tokens on one chain and mint a matching token on the other chain.
- Trusted bridges rely on an outside group of verifiers; trust-minimised bridges rely on the connected chains themselves.
- The FBI has linked bridge thefts to North Korean hackers, including $100 million from Harmony's Horizon bridge in 2022.
- A wrapped or bridged token is a representation of the original asset, and depends on the bridge working as designed.
What is a blockchain bridge?
ethereum.org gives a short definition: “Bridges facilitate communication between blockchains through the transfer of information and assets.”
The reason they exist is that every blockchain is its own closed system. ethereum.org explains that blockchains are built in isolated environments with different rules and mechanisms: “This means they cannot natively communicate, and tokens cannot move freely between blockchains.” Bitcoin cannot read Ethereum’s ledger, for example. A bridge is the go-between — including for layer 2 networks: ethereum.org says “Bridges are crucial to onboarding users onto Ethereum L2s, and even for users who want to explore different ecosystems.”
If you are new to how ledgers record ownership, start with what a blockchain is.
How does a crypto bridge move tokens?
A bridge does not really “send” your coins across. ethereum.org’s developer docs list three main methods:
- Lock and mint. “Lock assets on the source chain and mint assets on the destination chain.” Your original tokens sit in the bridge’s contract; a new token appears on the other chain.
- Burn and mint. “Burn assets on the source chain and mint assets on the destination chain.” The original is destroyed rather than held.
- Atomic swaps. You swap your asset on one chain for another party’s asset on the other chain.
With lock and mint, the token you receive is only as good as the pile of locked tokens behind it. If that pile is stolen, the token on the other side may be left without backing.

What is a wrapped token?
A wrapped token is a version of one asset issued on a different blockchain. ethereum.org’s example is Wrapped Bitcoin (WBTC): it is a token native to Ethereum, “which means it’s an Ethereum version of Bitcoin and not the original asset on the Bitcoin blockchain.”
So when you hold a bridged or wrapped coin, you hold a claim that depends on the bridge or custodian working as promised. ethereum.org warns that many bridges use wrapped assets and that “This exposes the ecosystem to systemic risk, as we have seen wrapped versions of tokens exploited.”
What is the difference between trusted and trustless bridges?
| Type | Who checks transfers? | What you rely on |
|---|---|---|
| Trusted | An external group of verifiers (for example a multi-signature group or an oracle network) | That the operators stay honest, online and secure |
| Trustless (trust-minimised) | The connected blockchains and their validators, via smart contracts | That the smart-contract code has no exploitable bugs |
ethereum.org states: “Trusted bridges are externally verified.” Trustless bridges, by contrast, rely on the blockchains they connect. Neither is free of risk. ethereum.org’s own conclusion: bridges “are in the early stages of development” and interacting with any type of bridge carries risk.
Why do hackers target bridges?
Because a lock-and-mint bridge holds a large pool of locked tokens in one place, a single weakness can expose the whole pool. ethereum.org: “While many bridges have successfully passed audits, all it takes is one flaw in a smart contract for assets to be exposed to hacks.”
US authorities have described several large thefts:
| Source | What the authority said |
|---|---|
| FBI alert, Aug 2022 | Between January and March 2022 criminals stole $1.3 billion in crypto, almost 97% of it from DeFi platforms. One attack described exploited a signature-verification flaw in a platform’s token bridge, causing about $320 million in losses. |
| US Treasury, May 2022 | On 23 March 2022 North Korea’s Lazarus Group carried out a heist “worth almost $620 million” from a blockchain project linked to the game Axie Infinity. |
| FBI, Jan 2023 | Lazarus Group (also known as APT38) was responsible for the $100 million theft from Harmony’s Horizon bridge reported in June 2022; over $60 million was later laundered through a privacy protocol. |
The FBI’s figures show the share of crypto thefts coming from DeFi platforms rose from 30% in 2020 to 72% in 2021, before reaching almost 97% in the first quarter of 2022.
What are the risks of using a crypto bridge?
ethereum.org lists the main risks in its own words:
- Smart-contract risk: “the risk of a bug in the code that can cause user funds to be lost”.
- Censorship risk: “bridge operators can theoretically stop users from transferring their assets using the bridge”.
- Custodial risk: “bridge operators can collude to steal the users’ funds”.
- Wrapped-asset risk: wrapped versions of tokens have been exploited, which ethereum.org says exposes the wider ecosystem to systemic risk.
- Fake bridge websites. The FBI has warned about spoofed websites that trick people into connecting their wallets to “drainer” contracts. Always reach a bridge from an address you have verified yourself.
The FBI’s advice for DeFi platforms in general applies here too: research the protocol and its smart contracts, check whether independent auditors have reviewed the code, and be wary of pools with very short windows to join. ethereum.org says interactions with smart contracts are irreversible, so test with a small amount and double-check the destination chain and address. Learn the general red flags of crypto scams as well.
Blockhorizon is an education site. Nothing here is a recommendation to use any particular bridge or buy any crypto-asset.
Frequently asked questions
Is a bridged token the same as the original coin?
No. It is a representation on another chain. ethereum.org says WBTC on Ethereum is “an Ethereum version of Bitcoin and not the original asset on the Bitcoin blockchain”.
Does an audit make a bridge safe?
No. ethereum.org notes that even after audits, “all it takes is one flaw in a smart contract for assets to be exposed to hacks.”
Who do I report a bridge hack or theft to?
In the US, the FBI asks victims of DeFi theft to contact its Internet Crime Complaint Center (ic3.gov) or a local FBI field office. Elsewhere, report to your national police or fraud service. Beware of anyone offering to recover funds for a fee — see recovery scams.
Do I need a bridge to use a layer 2 network?
Often, yes. ethereum.org says “By bridging your ETH from the Mainnet to an Ethereum L2 rollup, you can enjoy lower transaction fees.” That is why bridge risk is part of layer 2 risk.
Article Sources
7 sources
Blockhorizon checks every figure, date and quotation against primary sources: regulators, statistics bodies and original technical documents. Read our editorial policy.
- ethereum.org — Introduction to blockchain bridges (updated 24 Jul 2026) — ethereum.org (accessed 2026-10-02)
- ethereum.org — Bridges (developer docs) — ethereum.org (accessed 2026-10-02)
- FBI IC3 — Cyber Criminals Increasingly Exploit Vulnerabilities in DeFi Platforms (PSA I-082922-PSA, 29 Aug 2022) — ic3.gov (accessed 2026-10-02)
- FBI — FBI Confirms Lazarus Group Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft (23 Jan 2023) — fbi.gov (accessed 2026-10-02)
- US Treasury — Treasury sanctions virtual currency mixer Blender.io (6 May 2022) — home.treasury.gov (accessed 2026-10-02)
- ethereum.org — Introduction to smart contracts — ethereum.org (accessed 2026-10-02)
- FBI IC3 — Criminals Pose as NFT Developers (PSA I-080423-PSA, 4 Aug 2023) — ic3.gov (accessed 2026-10-02)
