
Ethereum and Solana don't communicate. Arbitrum and BNB Chain don't share state. Every blockchain is its own isolated network.
Bridge connects them. Deposit assets on one chain. Receive equivalent assets on another. Move capital wherever it needs to go.
Sounds simple. Infrastructure underneath is complex. That complexity is why bridges get exploited constantly.
Few different mechanisms depending on the bridge.
Bridges hold enormous amounts of locked assets. High value targets. Complex code across multiple chains. More attack surface than almost anything else in DeFi.
Ronin Bridge. March 2022. $625 million. Largest DeFi hack at the time. Validators behind the Axie Infinity bridge compromised. North Korean hackers traced later. Sky Mavis didn't notice for six days.
Wormhole. February 2022. $320 million. Smart contract vulnerability on the Solana side. Attacker minted 120,000 wrapped ETH without depositing collateral. Jump Crypto covered the loss to prevent cascade. Not every bridge has Jump Crypto backing it.
Nomad. August 2022. $190 million. Initialization bug meant any transaction could be replicated. Once someone figured it out the information spread. Hundreds of wallets drained it simultaneously. Crowd sourced exploit.
Horizon (Harmony). June 2022. $100 million. Private key compromise on multisig.
Over a billion dollars stolen from bridges in one calendar year. Pattern wasn't coincidence. Bridges are structurally difficult to secure. High value, complex code, often trusted validators as a point of failure.
Two categories. Different tradeoffs.
Canonical bridges. Official. Run by the L2 team. Arbitrum, Optimism, zkSync all have their own. Most secure because the security model matches the rollup itself. Slow. Seven day withdrawal period back to Ethereum mainnet on optimistic rollups. Challenge period allows fraud proofs. Can't skip it on the canonical bridge.
Third party bridges. Stargate, Across, Hop, Synapse. Minutes instead of days. Different security assumptions. Smart contracts, liquidity pools, sometimes trusted validators or oracles. Faster means more trust required somewhere in the system.
Most users bridge through third party for speed. Most security conscious users use canonical for large amounts. Tradeoff isn't subtle.
Bridging often produces wrapped versions of assets.
WBTC. Bitcoin on Ethereum. Backed by real BTC held by custodians. 1:1 in theory. Depends on custodian remaining honest and solvent.
WETH. Wrapped ETH on various chains. Backed by ETH locked in bridge contracts.
Wrapped tokens inherit the risk of the bridge or custodian behind them. Asset is only as good as what's backing it. Wormhole hack created a gap where wrapped ETH on Solana temporarily wasn't fully backed. Jump Crypto filled it. Without that intervention those tokens would have deppegged.
Moving from Ethereum to Arbitrum. Fast. Few minutes.
Moving back from Arbitrum to Ethereum via canonical bridge. Seven days. Challenge period for optimistic rollup fraud proofs.
People discover this at inconvenient moments. Need funds on mainnet. Funds sitting on Arbitrum. Canonical bridge says seven days. Third party bridge says twenty minutes for a fee.
Fast bridges charge for liquidity. Someone fronts the ETH on mainnet immediately. Gets repaid when the canonical withdrawal completes. You pay for that service.
Not a flaw in the system. Just how optimistic rollups achieve security. Worth knowing before bridging significant amounts somewhere you might need them back quickly.