ChainSwap's Second Bridge Exploit in a Month Nets Attacker $4.4 Million
Cross-chain bridges are increasingly attractive targets as demand for multi-chain DeFi grows, and ChainSwap — the Alameda-backed platform describing itself as a "cross-chain hub for all smart chains" — became a repeat example of the trend. On July 13, 2021, the project suffered its second security incident within a single month, this time losing an estimated $4.4 million, up from roughly $800,000 in the earlier breach.
01How the exploit worked

On Ethereum, each token approved for bridging is tied to its own proxy Factory contract. The attacker, operating from address 0xEda5066780dE29D00dfb54581A707ef6F52D8113, found a way to abuse this contract to mint tokens directly to arbitrary addresses, later consolidating them back into the wallet that initiated the transactions.
The pattern, as documented by researcher @cmichelio, followed these steps repeated many times over:
- Call the
receivefunction on the Factory (minting) contract. - Bypass the contract's weak authentication check by supplying a fresh address as the signature on each transaction.
- Pay a 0.005 ETH
chargeFee. - Set the
toparameter to whichever address should receive the newly minted tokens. - Repeat.
02Scope on BSC
According to ChainSwap's own post-mortem, the attack affected 20 different tokens on Binance Smart Chain. One example involved the NFT platform WilderWorld: in one of 40 near-identical transactions, the attacker minted 500,000 $WILD tokens each time, ultimately generating roughly 20 million WILD. Those tokens were then sold through PancakeSwap for approximately 650 WBNB — about $200,000 at the time — which drained the WILD/WBNB liquidity pool in the process.
By the time the exploit concluded, the attacker's wallet held a mix of tokens worth an estimated $4.4 million in total, with the trail of 0.005 ETH transactions serving as a clear on-chain record of each round of minting via the ChainSwap bridge.
03Cashing out
Some of the ETH that had been moved over from BSC was subsequently converted through 1inch: five transactions totaling 456 ETH, worth approximately $935,000 at the time of the report.
The broader pattern is one Rekt flagged as a growing risk: as activity increases on chains like BSC, Solana, and Polygon, bridges connecting them are likely to keep surfacing similar loopholes. (The earlier $800,000 incident that month wasn't covered separately at the time, on the basis that sub-million-dollar losses didn't meet the bar for a standalone write-up.)

04A curious email
Looking back at ChainSwap's first post-mortem from earlier in the month turned up an unusual detail: an email purportedly sent by the attacker. Whether it genuinely came from the hacker or was authored internally by ChainSwap itself was left open to speculation.
One inconsistency stood out — the sender had funded the relevant wallet using Tornado Cash, a privacy tool, but then asked for the "bounty" to be paid out in USDT, a centralized stablecoin whose issuer, Tether, can freeze funds. That choice would expose the attacker to exactly the kind of traceability they'd otherwise tried to avoid, and there was no evidence any laundering had actually taken place. Questions remained over whether this pointed to an insider at ChainSwap or the return of whoever had used "fake KYC accounts" in connection with the case.
ChainSwap put together a full compensation plan for affected users, though the reputational damage from a second exploit in the same month was harder to undo.
Get new scam files the moment we publish them — usually 2–3 emails a week.