Wormhole bridge hack
The Wormhole bridge between Solana and Ethereum was exploited for about $325M (120,000 wETH) in February 2022 after a signature-verification flaw let the attacker mint unbacked tokens. Backer Jump Crypto replenished the funds.
Also known as: Wormhole, Wormhole bridge
Summary
Wormhole is a token bridge linking Solana with Ethereum and other chains. In February 2022 an attacker exploited a flaw in its signature verification to mint 120,000 wrapped ETH (about $325 million) on Solana without depositing collateral, then redeemed much of it. [1][2]
Aftermath
To keep wrapped assets fully backed, Jump Crypto — owner of Wormhole developer Jump Trading — replaced the missing 120,000 ETH within days. The incident is frequently cited among the largest DeFi exploits. [1][2]
Bracketed numbers refer to the numbered sources listed below.
Sources (2)
See also
World Liberty Financial (WLFI) — Justin Sun token freezeProjectsWLFI, a DeFi project linked to Donald Trump and his family, blacklisted/froze the wallet of major investor Justin Sun in Sept 2025 — ~540–595M unlocked WLFI tokens (~$107M) plus ~2.4B locked. Sun sued, alleging an undisclosed admin 'blacklist backdoor'; WLFI denied it and threatened a countersuit. The dispute is ongoing.
Gala Games exploitTokensOn May 20, 2024 an attacker abused a privileged minter account on the GALA token contract to mint 5 billion GALA (≈$200M+ nominal) and dumped ~600M of them for ~$22M of ETH before Gala froze the address. Gala Games called it an internal access-control failure; the attacker later returned the ~$22M.
This page was last updated on Jun 15, 2026. View revision history.
