
Alephium's TokenBridge was drained of approximately $815,000 after an attacker exploited a flaw that allowed forged messages to pass through the protocol's guardian network and authorize fraudulent token transfers. According to reports from Blockaid, the exploit window ran from roughly 09:10 to 09:17 UTC on May 30, 2026, with the entire operation taking approximately 7 minutes. The attacker used a compromised set of 3-of-4 guardians to submit six forged VAAs (Verifiable Action Approvals) and repeatedly called completeTransfer() on the TokenBridge proxy, enabling unauthorized asset minting and withdrawals. The bridge proxy contract now holds roughly 1,000 USDT and less than 0.03 WETH, while the attacker's wallet still holds most of the stolen assets. However, Alephium has disputed early reports, stating that "The exploit was NOT caused by a compromise of the guardian keys, contrary to some early external reports." According to the protocol, the exploit was "caused by an offchain vulnerability in the bridge backend that could be triggered in specific edge cases."
On Ethereum, losses included 200,967 Tether (USDT), 17,594 USD Coin (USDC), 5.18 Wrapped Ether (WETH), and 0.335 Wrapped Bitcoin (WBTC). An additional 36,750 USDT and 24.386 Wrapped BNB were removed from the BNB Chain side of the bridge. The attacker also minted 13.76 million unbacked wrapped ALPH and transferred them directly to their wallet, which exceeds 100% of the prior wrapped ALPH supply on Ethereum. As reported by Blockaid, the attacker has begun moving proceeds through privacy infrastructure, making five separate 10 ETH deposits into Tornado Cash, with approximately 50 ETH already routed through the privacy service. The minted wALPH alone carries an estimated value of $536,000 to $560,000, though the full extent of Tornado Cash deposits remains unclear. On-chain analyst Specter flagged that the attack hit both the Ethereum and BNB Chain bridge contracts, with the attacker then moving stolen funds from BNB Chain to Ethereum.
Developers built the Alephium TokenBridge on a fork of the Wormhole protocol, which relies on a guardian network to validate cross-chain messages. According to Blockaid's analysis, the exploit involved compromising 3 of 4 guardian keys to sign forged VAAs that tricked the bridge contract into minting tokens and releasing reserves for transfers that never occurred on Alephium. This distinction is crucial, as a key compromise would point to operational failure, while a forged-message attack indicates a flaw in how the bridge validated incoming data before presenting it to guardians. The attacker's 3-of-4 threshold means they only needed to compromise three keys out of four, compared to Wormhole's mainnet deployment using 19 guardians or Ronin's 2022 attack on a 9-validator system. The contract itself worked exactly as designed, but the failure occurred upstream when the attacker forged VAAs claiming transfers that never happened. In the Alephium TokenBridge, when users switch from Alephium to Ethereum, the real ALPH is locked on a single chain, with Ethereum used to mint a wrapped version (wALPH). Before allowing minting to proceed, three guardians of the bridge confirm the lock was made, and to verify cross-chain transfers, the system uses guardian signatures. For a transfer message to be approved by the bridge, three of the four guardians must sign it.
The Alephium incident adds to a worsening picture for cross-chain infrastructure in 2026, with May crypto hack losses reaching $606 million and May DeFi hack tally continuing to climb heading into June. As reported by Blockaid, this adds to the year's total alongside CrossCurve bridge exploit and Hyperbridge exploit, both revised to $2.5 million. The attacker's use of privacy infrastructure suggests they do not plan to return funds, with no official compensation plan announced by Alephium. The company has explicitly warned users to avoid interacting with wrapped ALPH on Ethereum and urged liquidity providers on Uniswap and PancakeSwap to withdraw their positions immediately. The bridge remains fully disabled to prevent further exploit activity, with no additional bridge transfers possible while the investigation remains active. Alephium has provided comprehensive guidance, stating "Because the bridge has been shut down, the attacker cannot redeem or bridge these wrapped ALPH back through the Alephium bridge. We therefore ask users not to provide liquidity to ALPH pools on Ethereum or $BNB Chain, to withdraw any existing liquidity, and not to swap against these pools." The platform has promised to share recovery and remediation updates in the coming week.