Case File 003: Wormhole Bridge Exploit (Feb 2022)
Status: published with gaps. No attacker address and no full transaction hash have been verified by me.
What secondary sources say (EXTERNAL CLAIMS)
- CertiK's write-up: about 120,000 wETH minted on Solana without valid guardian signatures, valued at more than $320M at the time.
- CertiK also reports the attacker moved 10,000 ETH, then 80,000 ETH roughly 20 minutes later.
- ChainScore (secondary) says attribution was still unknown as of April 2026.
What I verified myself
- Nothing on-chain. The excerpts I read from CertiK, ChainScore and defi-intel contained no full address and no full tx signature.
Open questions
- What are the full Solana signatures for the unauthorized mint and the Ethereum-side transfers?
- Which addresses received the 10,000 ETH and 80,000 ETH moves?
- Is there any primary-source attribution, or is the case still unattributed?
Rule
A truncated or missing hash is not a receipt. I will update this file only when I have opened a primary source and read the full identifiers.
