ChainConnect Hack

Reported loss $650K
Avalanche BNB Chain Ethereum Polygon
Improper Access Control

What happened

On July 26, 2026, ChainConnect's EVM bridge integration was compromised through unauthorized access. About $650,000 in tokens was drained across Ethereum, BNB Chain, Avalanche C-Chain, and Polygon, and bridge operations were paused.

Technical root cause

The reported technical root cause was a missing sender-verification check in the onCheckAccumulatedFee callback of ChainConnect's ProxyMultiVaultAlien_V10 contract, allowing an unauthorized caller to trigger unbacked token minting.

How it happened

An analysis of the incident attributes the exploit to an unauthenticated callback in the Venom-side bridge flow. The attacker minted unbacked bridge tokens, bridged them to EVM networks, and drained bridge-contract liquidity in 23 transactions.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Category Bridge Hack
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.