BLOCKCHAIN AI.NEWS

Infrastructure · Analysis

Bridge Hacks Went From 3 to 26. The Same File Also Says 11 to 39

This week's coverage of the Liquid hack cites DefiLlama for a startling jump in attacks on cross-chain infrastructure. This desk pulled the same public file and found a second bridge field sitting next to the first, giving a different pair of numbers and a much gentler slope. Both are defensible. Only one is being quoted.

Editorial illustration: two identical frosted-glass measuring columns rising from one chrome basin, filled to visibly different heights, one lit gold and one lit blue
✓ Bridge-attack framing and the institutional-adoption angle reported first by Bloomberg (Suvashree Ghosh, Sep 8; read via Insurance Journal) · Quoted analysts Nikhil Raghuveera of Predicate and Ziqing Ang of TRM Labs via the same report · All incident counts, classifications, bridge flags and dollar totals computed by this desk directly from DefiLlama's public hacks file at api.llama.fi/hacks on September 8, 2026

A figure went around the wires this week, attached to the $320 million Liquid Network hack and the broader argument that crypto's plumbing is the weak part. Bloomberg's Suvashree Ghosh reported that 26 of 2026's attacks — over 10 percent — hit bridges and cross-chain infrastructure, against only three such incidents identified in 2025. The source given was DefiLlama.

The figure is correct. This desk downloaded DefiLlama's public hacks file on Monday and counted 26 records for 2026 carrying the classification Bridge & Cross-Chain, and exactly three for 2025. The 2025 totals quoted alongside it match too: 146 incidents, $2.71 billion.

The same file carries a second bridge field. Every record has a boolean called bridgeHack, and it does not agree. On that measure 2026 has 39 bridge incidents and 2025 has 11.

So the honest sentence is that attacks on cross-chain infrastructure rose either roughly ninefold or roughly threefold last year, depending on which column of one file you read — and the number in circulation is the steeper one.

Why the file has two answers

Neither field is wrong, and this is not a story about a bad dataset. The two columns are measuring different things, and the difference is a real distinction that anyone writing about bridge security ought to want.

classification records what went wrong — the primary technical cause. bridgeHack records what got hit. An attacker who compromises a validator key and drains a bridge with it has committed a key compromise against bridge infrastructure. DefiLlama files that under Key Compromise and flags it bridgeHack: true. Count by cause and it is not a bridge hack. Count by target and it plainly is.

Fifteen of 2026's records sit in exactly that gap: flagged as bridge incidents, classified as something else. Several of them have the word in the name.

Flagged as bridge incidents, filed under another cause (2026)

Target Amount Technique Classified as
AFX Bridge$24.15MValidator key compromisedKey Compromise
Wanchain$10.00MSignature verification flawInput Validation
Gravity Bridge$5.40MValidator key compromisedKey Compromise
IoTeX$4.40MValidator key compromisedKey Compromise
Maya Protocol$1.70MWithdrawal logic flawProtocol Logic
Allbridge Core$1.65MWithdrawal logic flawProtocol Logic
Echo Bridge$0.82MPrivate key compromisedKey Compromise
…and 8 smaller records$2.96Mmixedmixed
The 15 records in DefiLlama's 2026 data flagged bridgeHack: true but classified under a cause other than Bridge & Cross-Chain. Two records run the opposite way — classified as bridge incidents without the flag. Computed by this desk from api.llama.fi/hacks, September 8, 2026.

Read that table and the case for the higher count is not subtle. AFX Bridge and Gravity Bridge are bridges that lost money because someone got the validator keys. A reader told "26 bridge attacks" is not being told about them.

The direction is not in dispute

It would be easy to read all this as debunking, and it is not. Whichever column you take, 2026 is an outlier, and the trend Bloomberg described is real.

The bridge flag has been in this dataset for years, and its history is stable: 12 incidents in 2021, 13 in 2022, seven in 2023, seven in 2024, 11 in 2025. Then 39 in 2026, with nearly four months still to run. That is not an artefact of counting. Something changed.

Bridge incidents by year, and what they cost

2021 · 12 incidents$656M
2022 · 13 incidents$1.91B
2023 · 7 incidents$301M
2024 · 7 incidents$37M
2025 · 11 incidents$38M
2026 · 39 incidents$739M
Incidents carrying bridgeHack: true, by calendar year, with total reported amounts at right. Bar widths are proportional to incident count, not to dollars — 2022's losses exceed 2026's. 2026 covers January 1 to September 8. Computed by this desk from DefiLlama's public hacks file, September 8, 2026.

The dollars tell a sharper story than the count, and nobody led with them. Bridge-flagged losses went from $38 million in all of 2025 to $739 million so far in 2026 — a roughly nineteenfold increase, far steeper than either incident ratio. That is the number that should have carried the coverage.

It also comes with the heaviest caveat. Two events supply most of it. The Liquid Network hack alone accounts for 43 percent of 2026's bridge-flagged dollars; add April's $293 million Kelp incident and the two together make up 89 percent of the losses in the narrower bridge classification. Strip them out and 2026 looks like a year of many small bridge failures rather than a year of catastrophic ones — which is a different problem, and arguably a worse one, but not the one the headline number implies.

For scale: 2022, the year of the great bridge robberies, produced $1.91 billion in bridge losses from 13 incidents. 2026 has three times the incidents and, so far, a bit over a third of the money.

A live file, quoted as a fixed one

One more discrepancy is worth flagging for anyone checking this work. Bloomberg reported roughly $1.4 billion across 250 attacks for 2026. The file this desk read on Monday showed $1.82 billion across 256 records.

Most of that gap is the Liquid record itself, which carries $320 million and was presumably added between the two reads; removing it leaves $1.50 billion across 255. The rest is ordinary drift. This is a continuously maintained public dataset, and it is revised as incidents are confirmed, amended and backfilled. Every count in this story, including ours, is a snapshot with a timestamp on it.

That is also why the returned-funds problem matters. Of 2026's 256 records, only five carry any recovered amount at all, totalling about $1.9 million. The Liquid entry still shows $320 million taken and nothing returned, days after 3,400 BTC went back on chain. Any "crypto lost $X this year" figure built on this file is a gross number that barely tracks recoveries — which is fine, as long as the people quoting it know that is what they are quoting.

The Take

DefiLlama did nothing wrong here, and neither, really, did Bloomberg — 26 is a number that is genuinely in the file, next to a label that genuinely says bridge. The failure is the one that happens every time a maintained dataset meets a deadline: a field gets read as an answer rather than as one of several available answers, and by the second day it is a fact that everyone knows. The dataset is more honest than its citations. It carries two bridge columns precisely because "what broke" and "what got hit" are different questions, and a project that only wanted a headline would have shipped one. So the correction is small and the lesson is not. If you are going to attribute a number to a public file, open the file. It takes a single request and it took this desk about ten minutes, and the version of the story that survives that check is better than the one that does not: bridge incidents are up on every measure, the money is up nineteenfold, and most of the money is two bad afternoons. That is a more useful thing to know than a ratio of 26 to 3, and it was sitting in the same download the whole time.

More on the subject