As you may know, the Wormhole bridge was exploited on Wednesday, resulting in the loss of USD 321 million. Wormhole allows to transfer coins between Ethereum, Solana, Binance Smart Chain, Polygon, Avalanche, Oasis and Terra. It is the second-largest decentralized finance hack to date. The Wormhole team assured that its ETH supply would be replenished to “ensure wETH is backed 1:1,” but they did not say where those funds will come from or when. As of today, wETH tokens sent across the bridge are not yet redeemable, while the Wormhole team attempts to fix the exploit. A few days ago, Qubit Finance’s QBridge had also been exploited for $80 million on the Binance Smart Chain...
What can we learn from these exploits?
First of all, everyone should have carefully read what Vitalik Buterin wrote on Jan. 7:
The fundamental security limits of bridges are actually a key reason why while I am optimistic about a multi-chain blockchain ecosystem (...) I am pessimistic about cross-chain applications.
To understand why bridges have these limitations, we need to look at how various combinations of blockchains and bridging survive 51% attacks. Many people have the mentality that "if a blockchain gets 51% attacked, everything breaks, and so we need to put all our force on preventing a 51% attack from ever happening even once". I really disagree with this style of thinking; in fact, blockchains maintain many of their guarantees even after a 51% attack, and it's really important to preserve these guarantees (...) Now, imaging what happens if you move 100 ETH onto a bridge on Solana to get 100 Solana-WETH, and then Ethereum gets 51% attacked. The attacker deposited a bunch of their own ETH into Solana-WETH and then reverted that transaction on the Ethereum side as soon as the Solana side confirmed it. The Solana-WETH contract is now no longer fully backed, and perhaps your 100 Solana-WETH is now only worth 60 ETH. Even if there's a perfect ZK-SNARK-based bridge that fully validates consensus, it's still vulnerable to theft through 51% attacks like this.
For this reason, it's always safer to hold Ethereum-native assets on Ethereum or Solana-native assets on Solana than it is to hold Ethereum-native assets on Solana or Solana-native assets on Ethereum. And in this context, "Ethereum" refers not just to the base chain, but also any proper L2 that is built on it.
Vitalik had already said everything:
- Bridges are vulnerable. That's exactly what the latest exploits on Wormhole and QBridge have shown.
- It's safer to hold Ethereum-native assets on Ethereum or Solana-native assets on Solana than it is to hold Ethereum-native assets on Solana or Solana-native assets on Ethereum.
- In this context, "Ethereum" refers not just to the base chain, but also any proper L2 that is built on it.
Therefore, we'd better stop transfering coins through bridges. In this case, using centralized exchanges is safer. You will not anxiously wait for the arrival of your coins on the other side anymore. Furthermore, if you want to hold ETH or ERC-20 tokens, it is safer to make it on a layer-2 sidechain of Ethereum (e.g. Arbitrum, Optimism or Polygon) rather than on Solana. And if you want to hold Solana or SPL tokens, just make it on Solana. It's as simple as that...
Frankly speaking, that's good news for Ethereum L2 sidechains and their tokens, e.g. MATIC for Polygon. That's even a bullish case. We could also expect that some other layer-2 sidechains will launch their tokens, which might be extremely bullish too. Therefore, investing in Polygon (especially now that MATIC token has significantly dumped) and start playing with the other L2s which have no token yet might be a good idea. Please DYOR, as usual.
Keep safe... and if you want to earn a bit more cryptos without risk, you can click on the links below:
- Elrond: earn $10 EGLD
- Legion Network: earn $5 LGX
- Crypto.com: earn $25 CRO / Referral code: 439km3wyjs