📈 Get daily crypto insights that make you smarter about your money

Force Bridge Exploit Exposes Access Control Failures as $3.9 Million Drained From Nervos Network

Cross-chain bridge infrastructure faces renewed scrutiny after Nervos Network’s Force Bridge suffers a devastating exploit that siphons nearly $3.9 million in digital assets. The incident, unfolding between May 31 and June 1, 2025, underscores persistent vulnerabilities in bridge architectures that continue to plague the decentralized finance ecosystem.

The Exploit Mechanics

According to blockchain security firm Cyvers Alerts, the attacker seized control of Force Bridge’s cross-chain infrastructure through an access control failure. The exploit targeted both the Ethereum and BNB Chain sides of the bridge, draining a combination of major tokens including 60,400 DAI, 539 ETH, 898,300 USDC, 257,800 USDT, and 0.79 WBTC. The total haul reached approximately $3 million from Ethereum and an additional $800,000 from BNB Chain.

Security researchers at Hacken revealed that the attack was not instantaneous. The perpetrator made multiple failed attempts over a six-hour window before successfully breaching the system. A small test transaction at 02:23 UTC netted just $25, serving as a proof-of-concept before the full-scale assault at 07:36 UTC, when 874 BNB worth roughly $572,000 was drained. This extended attack window represents a critical monitoring failure.

Affected Systems

Force Bridge serves as a critical component of Nervos Network’s multi-chain strategy, facilitating asset transfers between Nervos, Ethereum, and Binance Smart Chain. The bridge operates by locking assets on the source chain and issuing matching tokens on Nervos, protected by a multi-signature wallet system managed by Nervos and its partners.

The compromised bridge had already been announced for deprecation, adding another layer to the incident. Deprecated or sunset infrastructure often receives reduced security attention, creating an exploitable window that attackers can identify and target. In this case, the bridge’s pending shutdown status may have contributed to gaps in monitoring and access control maintenance.

The Mitigation Strategy

Magickbase, a Nervos Network community developer, responded by halting all Force Bridge activity immediately upon detecting the irregular transactions. The team issued a public statement acknowledging the abnormal activity and confirming the precautionary shutdown while investigations proceed.

The stolen assets were quickly routed through crypto mixers and anonymous platforms, including Tornado Cash and FixedFloat, in an effort to obscure the transaction trail. Funds were split among newly created wallets and routed through multiple hops before being deposited to these mixing services, complicating recovery efforts.

Lessons Learned

This exploit reinforces several critical security principles for the crypto industry. First, deprecated infrastructure must maintain full security protocols until complete shutdown, not gradually reduce protections. Second, six-hour attack windows with multiple failed attempts should trigger automated alerts and temporary freezes. Third, bridge architectures remain high-value targets requiring continuous auditing and real-time monitoring.

The Force Bridge incident joins a growing list of cross-chain exploits that have collectively cost the industry billions. With Bitcoin trading at approximately $105,652 and Ethereum near $2,536 at the time of the attack, the total crypto market capitalization above $3.4 trillion makes bridge security a systemic concern affecting the entire ecosystem.

User Action Required

Users who previously transacted through Force Bridge should monitor their wallets for any unauthorized activity. Those holding bridged assets on Nervos Network should check official Nervos channels for updates on the investigation and any potential recovery plans. The broader community should evaluate their exposure to cross-chain bridges and consider whether the convenience of interoperability justifies the additional counterparty risk. As bridge exploits continue to accumulate, the industry must prioritize security architecture over feature velocity to protect user funds and maintain trust in decentralized systems.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any financial decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “Force Bridge Exploit Exposes Access Control Failures as $3.9 Million Drained From Nervos Network”

  1. nonce_forensics_

    539 ETH and 898K USDC gone because nobody configured access controls correctly. how many bridges need to drain before multisig thresholds become the default not an option

  2. 6 hours of failed attempts and zero alerts. force bridge was operating infrastructure worth millions with less monitoring than a discord server

    1. Hadiya M. the monitoring gap is what kills me. any basic anomaly detection on failed transactions would have flagged this. they had 6 hours and did nothing

    1. defi exploits are mostly social engineering now? this was a straight access control failure. attacker got admin keys. bridge security is fundamentally broken

      1. six_hour_window_

        exploit_db 6 hours of failed attempts before the access control bug worked. any monitoring system should have flagged that pattern. bridge ops are asleep at the wheel

        1. six_hour_window_ 6 hours of failed attempts and nobody at Force Bridge got a page. their incident response is non-existent. bridge ops need 24/7 monitoring or they shouldnt be running bridges

    1. bridge_auditor_

      hardware wallets dont help when the bridge smart contract has an access control bug. completely different threat model

  3. 539 ETH and 898K USDC gone because of an access control failure. this is the same vulnerability pattern as wormhole and nomad. nobody learns

    1. Kofi A. wormhole nomad and now force bridge. same access control failure pattern every single time. the bridge thesis is fundamentally broken until multi sig thresholds become mandatory

  4. bridge_rekt_2025

    539 ETH plus 898K USDC plus 257K USDT. the attacker basically cleared the treasury across two chains and nobody noticed for hours

  5. bridge_autopsy_

    6 hours of failed attempts before the exploit worked and force bridge had zero monitoring. any SRE worth their salt would have paged on the first 3 failed transactions. bridge ops need 24/7 or they shouldnt operate

    1. bridge_autopsy_ wormhole nomad ronin and now force bridge. same access control pattern every single time. multisig thresholds should be mandatory for any cross chain bridge holding user funds

      1. Hadi N. wormhole nomad ronin and now force bridge. the access control pattern is identical every time. multisig should be regulated for bridges holding over 1M

  6. test_tx_tracer_

    the 25 dollar test transaction at 02:23 UTC was the canary. 5 hours later they drained 3.9M. monitoring caught nothing

    1. test_tx_tracer_ the 25 dollar test tx at 02:23 is textbook exploit behavior. every major bridge drain starts with a micro test before the full drain

      1. bridge_tax_ the 25 dollar test tx pattern is universal across every bridge hack. Nomad did the same thing. Multi million exploits always start with a dust transaction to verify the path works

  7. 60400 DAI plus 539 ETH across two chains and the bridge kept operating normally. the access control layer was so broken the attacker could have drained more if they wanted

    1. access_key_leak_

      relay_drain_ the scary part is they could have drained more. the bridge kept operating normally during the exploit. access controls were so broken the attacker was being polite

      1. bridge_trough_

        access_key_leak_ the bridge operating normally during the exploit is the wildest detail. attacker had full admin and the system just kept serving users like nothing happened

  8. Hacken revealing the 6 hour attack window after the fact is useless. where was the real time monitoring? bridges holding millions need 24/7 anomaly detection not post mortem reports

  9. 6 hours of failed attempts before the exploit landed. any bridge with basic anomaly detection would have caught this. Force Bridge was running on hope

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$63,927.00-1.4%ETH$1,871.97-2.0%SOL$76.03-0.4%BNB$598.33-0.8%XRP$1.01-1.9%ADA$0.1920-1.2%DOGE$0.0698+0.6%DOT$0.8047+0.8%AVAX$6.43-0.4%LINK$8.29+1.0%UNI$3.94-1.3%ATOM$1.40+1.8%LTC$45.14-0.8%ARB$0.0798+2.3%NEAR$1.59-0.2%FIL$0.7016+0.2%SUI$0.6843-0.2%BTC$63,927.00-1.4%ETH$1,871.97-2.0%SOL$76.03-0.4%BNB$598.33-0.8%XRP$1.01-1.9%ADA$0.1920-1.2%DOGE$0.0698+0.6%DOT$0.8047+0.8%AVAX$6.43-0.4%LINK$8.29+1.0%UNI$3.94-1.3%ATOM$1.40+1.8%LTC$45.14-0.8%ARB$0.0798+2.3%NEAR$1.59-0.2%FIL$0.7016+0.2%SUI$0.6843-0.2%
Scroll to Top