Nervos' Force Bridge Drained for $3.76M One Day After Its Retirement Was Announced
Force Bridge lost $3.76 million to an access-control exploit on June 1st, in a sequence of events whose timing invites scrutiny: the protocol's sunset had been announced barely a day earlier.
On May 31st, Magickbase signaled that Force Bridge was winding down, framing the move as a strategic pivot toward "UTXO-native innovation, Web5 architecture, Fiber Network." The official sunset window was set to run from June 1st through November 30th, giving users months to withdraw funds. Instead, attackers struck on the very first day of that window.

Magickbase — described by The Block as Nervos' key infrastructure partner and the operator of Force Bridge — posted about "abnormal activity" late on June 1st. Force Bridge itself has no public account or communication channel of its own; all public updates came through Magickbase. Within hours, the scale became clear: $3.76 million had been drained across Ethereum and BNB Chain. According to Cyvers, the stolen assets included 257,800 USDT, 539.09 ETH, 898,300 USDC, 60,400 DAI, and 0.79 WBTC, all of which were converted to ETH and funneled into Tornado Cash.
Notably, this was not a one-shot exploit — the attacker had already made an unsuccessful attempt roughly six hours before succeeding, pointing to either persistence or advance knowledge of the system's weak points.
Reconstructing the attacker's preparation
According to forensic analysis from Hacken, the operation was planned methodically. One day before the exploit, on May 31st, the attacker funded an Ethereum address with 0.1237 ETH withdrawn from KuCoin.
Funding transaction on Ethereum: 0x0da4f731d05fce5358eb61115f71dad002d6b8b0c414d3269d8e45e7fa297e4d
Attacker address on Ethereum: 0x1998C6d25212194eBf9BB919b87D40b2Dc8aa8b9
A separate wallet was funded to carry out the parallel attack on BSC.
Funding transaction on BSC: 0xa29463be9b81b126d22bb2f6e8001ed36f0bbd71f2b2da763a538e732e747c25
Attacker address on BSC: 0x1998c6d25212194ebf9bb919b87d40b2dc8aa8b9
This funding took place the day before the sunset announcement went out — a coincidence, or preparation timed to a leak.
On June 1st, the attacker made several failed attempts against the Ethereum side before finally succeeding.
Attacked Force Bridge address on Ethereum: 0x63A993502e74828ddba5710327AFC6dc78d661b2
Example failed attack transaction on Ethereum: 0x69104f6b14faa6d77ae9837f6d5d01134b2af0e620d54a0723fdd931b40a87c7
Successful attack transaction 1 on Ethereum ($2.69 million): 0x6b6fbd9d6beef56d2a4f0d14852beea381764b962d7d73ecd216b9fd991299a1
Successful attack transaction 2 on Ethereum ($437k): 0x9859b6cbb2764a6cb86450cd7b514f54766b461735da081195226265d72a75fa
Total stolen on Ethereum: $3.127 million.
The same pattern repeated on BSC — multiple failed attempts followed by a successful drain.
Example failed attack transaction on BSC: 0x57a8d7b0fe1ad8b9159a37a09b3379e82cc85eb047528a5cef09dbf98b881357
Attacked Force Bridge address on BSC: 0x8215c949F2025B84629041903aDe8394f0a080c6
Attack transaction 1 ($571k): 0x4c7e83126e9327fe62cb8e3dab72121062eaf213852fd581e7ada43c93ea58a4
Attack transaction 2 ($63k): 0x555b07899ea87be062a7df84220b38fdf93aded10ad09229e9265bed5753744b

Total stolen on BSC: $634k.
Combined losses across both chains: $3.76 million.
Once the attacker gained entry, execution was straightforward: all proceeds were converted to ETH and moved through Tornado Cash, with FixedFloat handling the remainder. There were no flash loans or complex DeFi maneuvers involved — simply direct, privileged withdrawal calls. By the time Magickbase announced an "investigation" the following day, the laundering process was already complete.
Meanwhile, the Nervos Foundation's official response avoided the incident almost entirely. Rather than address the $3.76 million loss directly, it issued a reminder that the CKB network is "operated by a wide network of users, miners and full nodes," a decentralized system that "can't be shut down" and is "beyond anyone's control" — messaging that emphasized the network's resilience rather than the bridge's failure. Official communications instead pivoted to promoting Meepo, RGB++, and Fiber Network as the future roadmap for CKB, treating Force Bridge as a closed chapter.
Reading the exploit mechanism
Rather than a conventional bug hunt, the attacker's approach points to privileged access. Blockchain records show the attacker systematically unlocked tokens one after another, each unlock requiring admin-level function access that ordinary users cannot invoke. This is consistent with an access-control exploit, where compromised credentials, social engineering, or an insider effectively hands an attacker temporary ownership of the protocol — the ability to call restricted functions such as unlock(), withdraw(), or transferOwnership() without needing to find or exploit any code-level vulnerability.
The overall sequence — pre-funding a day ahead, testing the attack with failed transactions, executing successfully right after a sunset announcement — suggests deliberate planning rather than a lucky guess, though it remains unproven whether the attacker had inside knowledge.
In the end, Force Bridge shut down quietly: no official account issued a post-mortem, and the only public commentary came from Magickbase's roughly 300-follower Twitter account. Users were left to reconstruct what happened from on-chain data and third-party security alerts, credited variously to Magickbase, The Block, Cyvers, Hacken, and Extractor.
Get new scam files the moment we publish them — usually 2–3 emails a week.