Alephium Hack
What happened
On May 30, 2026, the Alephium TokenBridge was exploited across Ethereum and BNB Chain due to an off-chain backend vulnerability. Within approximately 7 minutes, the attacker successfully forged cross-chain messages to illegitimately drain $815,000 in multi-chain assets while minting roughly 13.7 million unbacked, wrapped ALPH.
The security incident was not the result of a smart contract bug or compromised guardian validator keys. Instead, the attacker uncovered and exploited a logic flaw embedded in the off-chain bridge backend software that triggered on specific edge cases. By exploiting this backend vulnerability, the attacker managed to programmatically forge valid-looking deposit authorization messages without locking actual assets on the native side.
These fraudulent messages were transmitted to the bridge’s deployment endpoints on both Ethereum and BNB Chain, prompting the contracts to unlock or mint assets. The attacker successfully extracted a mixed pool of stablecoins and major crypto assets (including USDT, USDC, WETH, WBTC, and WBNB) and generated millions of unbacked wrapped ALPH tokens on Ethereum. Because the bridge architecture was halted immediately after detection, the attacker lost the ability to redeem or move those newly minted wrapped ALPH tokens back through official channels, isolating the remaining damage to shallow decentralized exchange liquidity pools.
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report x.com
- report Report x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.