Alephium Hack

TOTAL LOST $815K
Low Other ethereum

What happened

On May 30, 2026, the Alephium TokenBridge was exploited across Ethereum and BNB Chain due to an off-chain backend vulnerability. Within approximately 7 minutes, the attacker successfully forged cross-chain messages to illegitimately drain $815,000 in multi-chain assets while minting roughly 13.7 million unbacked, wrapped ALPH.

The security incident was not the result of a smart contract bug or compromised guardian validator keys. Instead, the attacker uncovered and exploited a logic flaw embedded in the off-chain bridge backend software that triggered on specific edge cases. By exploiting this backend vulnerability, the attacker managed to programmatically forge valid-looking deposit authorization messages without locking actual assets on the native side.

These fraudulent messages were transmitted to the bridge’s deployment endpoints on both Ethereum and BNB Chain, prompting the contracts to unlock or mint assets. The attacker successfully extracted a mixed pool of stablecoins and major crypto assets (including USDT, USDC, WETH, WBTC, and WBNB) and generated millions of unbacked wrapped ALPH tokens on Ethereum. Because the bridge architecture was halted immediately after detection, the attacker lost the ability to redeem or move those newly minted wrapped ALPH tokens back through official channels, isolating the remaining damage to shallow decentralized exchange liquidity pools.

Case & protocol details

Classification Bridge / Bridge & Cross-Chain
Protocol Type Exploit/Other
Smart Contract Language Solidity
Official Website alephium.org/
Protocol Twitter/X @alephium

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.