Crypto World
Trump Calls Out Exxon, Chevron for Profiting From a War He Started
President Donald Trump said Monday, August 3, that ExxonMobil (XOM) and Chevron (CVX) made “too much money” during the Iran war. He called on both companies to cut retail gasoline prices.
Both oil majors released blowout second-quarter earnings three days before Trump’s remarks. Trump has otherwise positioned himself as an ally of the fossil fuel industry.
What Trump Said
Speaking to reporters at the White House, Trump singled out both companies by name for capitalizing on tight supply.
“They’re making too much money based on a shortage. I don’t like it.”
Trump, CNBC
Trump added that the companies should return some of that money to consumers. He said prices would “drop through the floor” once the war ends.
He has separately criticized Chevron chief executive Mike Wirth for not crediting his administration’s energy policies during a television interview.
Oil’s Wild Ride Since February
Crude prices have swung sharply since the U.S. and Israel struck Iran on February 28. Brent crude jumped from around $72 a barrel that week to nearly $120 at its peak. Iran had moved to choke off exports through the Strait of Hormuz timeline, a key global chokepoint. March alone saw Brent gain 51%, one of the largest monthly surges on record.
Prices have since cooled but remain volatile. Brent fell to $82 a barrel in late July after Iran signaled it might halt attacks. Crude slipped again on Monday, down about 5%, on hopes that renewed U.S.-Iran talks could ease the conflict.
U.S. oil futures still averaged roughly $92 a barrel from April through June, 27% above the first quarter. Gasoline has followed a similar path. It averaged $4.09 a gallon nationwide this week, up from $2.98 before the war, per AAA data. That squeeze has complicated the inflation picture the Federal Reserve has been tracking all year.
Where the Profits Came From
Chevron and Exxon reported their strongest quarters in years on Friday. Chevron’s profit more than quadrupled to $12.1 billion, up from $2.5 billion a year earlier. Exxon’s profit more than doubled to $14.5 billion, up from $7.1 billion.
Higher crude prices explain part of the jump, while refining margins drove much of the rest. Both companies ran their refineries near maximum capacity even as the war knocked out Middle East refining capacity elsewhere. Chevron used part of its windfall to cut debt by a record $8.4 billion. Exxon returned $9.4 billion to shareholders through dividends and buybacks.
Shares of both companies dipped modestly after Trump’s remarks, with Chevron down nearly 2% and Exxon slightly lower.
Trump’s public pressure campaign against the oil majors marks a notable shift, given his usual alignment with the industry. Whether that pressure lowers pump prices may depend on how long the conflict, and its disruption to oil flows, lasts.
The post Trump Calls Out Exxon, Chevron for Profiting From a War He Started appeared first on BeInCrypto.
Crypto World
Strategy sells $104.7 million in Bitcoin to support preferred stock
Strategy has sold 1,638 Bitcoin for $104.7 million after redirecting part of the proceeds toward preferred-stock dividends and share repurchases while increasing its U.S. dollar reserve.
Summary
- Strategy sold 1,638 Bitcoin for $104.7 million to fund STRC dividends and share repurchases.
- The company increased its U.S. dollar reserve to about $4 billion while raising another $290.6 million through MSTR stock sales.
- Strategy’s Bitcoin holdings now stand at 842,138 BTC as it continues prioritizing STRC support over new Bitcoin purchases.
An SEC filing submitted on Monday showed the company sold the Bitcoin between July 27 and Sunday at an average price of $63,957 per coin. Strategy allocated $52.4 million from the sale to dividend payments on its STRC perpetual preferred stock, while another $52.3 million went toward repurchasing STRC shares.
Following the transaction, Strategy’s Bitcoin holdings declined to 842,138 BTC acquired at a combined cost of approximately $63.5 billion.
The filing also disclosed that Strategy raised another $290.6 million by selling MSTR common shares during the same reporting period. Of that amount, $250 million was added to the company’s U.S. dollar reserve, $28.9 million funded additional STRC repurchases, and $11.7 million increased its cash balance.
Executive Chairman Michael Saylor said in a post on X that Strategy repurchased $81.2 million worth of STRC stock during the period and extended the company’s U.S. dollar funding runway by 57 days to roughly 2.3 years.
Bitcoin sale follows Strategy’s revised capital plan
The latest disposal comes after Strategy introduced a new capital framework at the end of June that allows Bitcoin sales to support preferred-stock dividends, debt obligations, approved security repurchases and the company’s dollar reserve.
Earlier SEC filings showed the company also sold 3,588 Bitcoin for approximately $216 million on July 6 and disclosed another sale of 32 Bitcoin in early June, its first reported Bitcoin disposal since a tax-related transaction in 2022.
Recent company updates had already pointed to a change in capital allocation. During its second-quarter earnings call on July 31, Executive Chairman Michael Saylor said Strategy would no longer direct every available dollar toward immediate Bitcoin purchases, choosing instead to maintain both cash and Bitcoin on its balance sheet.
Chief Executive Phong Le also said during the earnings call that Strategy would hold off on additional Bitcoin purchases while STRC continued trading below its $100 stated value.
By July 26, the company had built a $3.75 billion U.S. dollar reserve, which has now increased to about $4 billion after the latest stock sales. Strategy previously said the reserve is intended to cover preferred dividends and debt-related obligations unless the board approves another use.
STRC remains the company’s immediate priority
Supporting STRC has become a central part of Strategy’s financing plan because the preferred security is one of the vehicles it uses to raise capital for Bitcoin purchases.
Yahoo Finance data showed STRC traded at $89.40 during Monday’s pre-market session, leaving it 10.6% below its $100 stated value. MSTR shares were also down 0.9% before the opening bell.
A lower STRC price can make future fundraising through preferred-share sales less effective. The company has previously acknowledged that it wants the security to trade close to its stated value before resuming more aggressive Bitcoin accumulation.
Earlier this month, Strategy confirmed it would keep STRC’s annual dividend rate at 12% for August despite the preferred stock remaining below par. Under a revised policy adopted on June 29, management now considers factors including market price, competing yields, Bitcoin volatility, credit spreads and cash-reserve coverage instead of automatically raising the dividend whenever STRC trades below $100.
The company has increasingly relied on discounted share buybacks rather than repeated dividend increases. Earlier disclosures showed it repurchased roughly $25 million worth of STRC between July 20 and July 26, while nearly $1 billion remained available under its preferred-securities repurchase authorization.
Cash reserve has continued expanding while Bitcoin purchases pause
The latest filing indicates Strategy is still directing fresh capital toward strengthening liquidity even as it trims part of its Bitcoin position.
Most of the $290.6 million raised from MSTR share sales was added to the company’s dollar reserve, bringing the balance to approximately $4 billion as of Sunday. According to Saylor’s update, the additional liquidity extended the reserve’s ability to support dividend and interest obligations by nearly two months.
The approach follows management’s earlier comments that preserving funding flexibility could ultimately support future Bitcoin purchases rather than deploying all available capital immediately.
CryptoQuant founder and CEO Ki Young Ju argued in a June 24 post on X that Strategy should temporarily pause Bitcoin acquisitions, rebuild its cash reserves and adopt a more systematic purchase framework after estimating that the company’s dividend coverage had fallen sharply.
The company’s actions since then have largely centered on rebuilding liquidity, repurchasing discounted STRC shares and maintaining the preferred dividend instead of expanding its Bitcoin holdings.
Analysts and investors remain focused on Strategy’s funding model
Strategy reported an $8.22 billion net loss during the second quarter after recording an $8.32 billion unrealized loss on its Bitcoin holdings under fair-value accounting rules. Even so, management maintained that the accounting loss did not change the company’s long-term Bitcoin strategy.
During the earnings call, executives said restoring STRC closer to its $100 stated value would take priority before new Bitcoin purchases resume.
Benchmark and H.C. Wainwright both maintained buy ratings following the quarterly results, although Benchmark lowered its price target.
The firms said Strategy’s cash reserve, preferred-share repurchases and financing strategy could strengthen its ability to raise capital in the future, while continuing to note that the company’s outlook remains closely linked to Bitcoin prices and investor demand for its preferred securities.
Crypto World
Caleb & Brown Expands to UK, Betting on Untapped Crypto Demand
Cointelegraph is committed to providing independent, high-quality journalism across the crypto, blockchain, AI, and fintech industries.
All news, reviews, and analyses are produced with full journalistic independence and integrity. For more details on our standards and processes, please read our Editorial Policy.
Crypto World
Circle shares slide after Morgan Stanley slashes price target to $38
Circle Internet Group has received a downgrade from Morgan Stanley, which has lowered its rating to Underweight from Equal Weight and reduced its price target to $38 from $106 after cutting long-term expectations for USDC growth.
Summary
- Morgan Stanley downgraded Circle to Underweight and cut its price target from $106 to $38.
- The brokerage lowered its USDC circulation forecasts for 2027 and 2028, citing slower stablecoin growth and pressure on reserve income.
- Circle shares fell about 6% in premarket trading after the downgrade, while TD Cowen initiated coverage with a Buy rating and an $82 price target.
- Morgan Stanley said real world stablecoin payments remain limited despite rising industry adoption.
- The downgrade comes days after Circle secured a New York trust charter and ahead of its second quarter earnings report.
Morgan Stanley said the downgrade follows lower forecasts for USDC circulation and concerns that Circle’s earnings model could face pressure as reserve income becomes more sensitive to slower stablecoin growth and increasing competition from tokenized cash products.
Circle shares fell about 6% in premarket trading on Monday to $58.81 after the research note was published, even as another Wall Street firm took the opposite view by initiating coverage with a bullish rating.
https://x.com/wallstengine/status/2084212465739653360
Morgan Stanley expects slower USDC expansion
Morgan Stanley reduced its assumptions for USDC circulation by about 33% for 2027 and 44% for 2028, arguing that the stablecoin has not expanded as quickly as previously expected. The brokerage also lowered its GAAP earnings-per-share estimates to around 3% below consensus for 2027 and roughly 20% below consensus for 2028.
According to analyst James Faucette, Circle’s reserve-income business faces increasing pressure because tokenized money market funds and tokenized deposits could compete for the same capital that would otherwise remain in USDC. The report also argued that USYC, Circle’s tokenized money market fund, carries structurally lower economics than its reserve-income business.
Morgan Stanley further said Circle’s OpenUSD initiative introduces shared governance and reserve economics that increase the cost of maintaining USDC distribution, while agentic payment activity remains too small to contribute meaningfully to revenue. The brokerage estimated that agentic payments have fallen to roughly $41,900 in daily volume, implying an average transaction size of about $0.24.
The brokerage also questioned Circle’s long-term growth target, saying USDC has “effectively not grown” since the third quarter of last year despite management’s objective of averaging 40% annual growth across market cycles.
Stablecoin payments remain limited, report says
While payment companies including Mastercard and Stripe have expanded their stablecoin offerings, Morgan Stanley said commercial adoption has yet to produce meaningful transaction volumes outside a handful of use cases.
Drawing on data from McKinsey, the brokerage noted that stablecoins processed roughly $35 trillion in adjusted transaction volume during 2025. Only about $390 billion represented identifiable real-world payments, however, with most activity still tied to crypto trading and transfers rather than commerce.
Morgan Stanley said payment activity continues to be concentrated in cross-border business transactions, remittances and stablecoin-linked card spending. According to the report, those use cases have yet to generate the durable balances and recurring transaction economics needed to offset pressure on Circle’s reserve-income model.
TD Cowen has taken the opposite view on Circle
Offering a contrasting assessment, TD Cowen initiated coverage of Circle with a Buy rating and an $82 price target, arguing that investors may be underestimating the company’s ability to develop into a financial infrastructure platform beyond stablecoin issuance.
Analyst Bryan Bergin said Circle is building products across payments, treasury services, tokenized real-world assets, interoperability and developer infrastructure, which could diversify revenue over time alongside USDC circulation.
TD Cowen also described Circle as a way for investors to gain exposure to institutional adoption of stablecoins and the modernization of financial infrastructure.
Wall Street remains closely divided on the stock. LSEG data shows that 16 of the 30 analysts covering Circle currently rate the shares Hold or Sell, while the remaining 14 recommend Buy or Strong Buy.
Regulatory progress has continued despite investor concerns
The downgrade arrives only days after Circle strengthened its regulatory position in the United States by securing a limited-purpose trust charter from the New York Department of Financial Services for Circle Internet Trust Company LLC, operating as Circle New York Trust.
Circle said the state approval complements the federal trust bank authorization it received from the Office of the Comptroller of the Currency in July. While the OCC-approved Circle National Trust is expected to provide fiduciary digital asset custody services, the company has said USDC issuance will continue through its New York trust entity before gradually transitioning under its approved regulatory structure.
Chief executive Jeremy Allaire previously said obtaining a New York trust charter had been a long-standing objective because of the regulatory clarity provided by the NYDFS framework. Circle has also said the approval builds on its relationship with the regulator, which dates back to 2015 when it became the first company to receive a BitLicense.
The regulatory milestones have not translated into sustained support for the stock. Circle shares ended July 31 down 2.54%, and on the same day Cathie Wood’s ARK Invest purchased 109,129 Circle shares across three exchange-traded funds, increasing its exposure to the stablecoin issuer ahead of the company’s scheduled second-quarter earnings release on Aug. 5.
Investors are also watching the proposed Clarity Act, which is expected to establish a regulatory framework for the U.S. cryptocurrency industry. Morgan Stanley’s latest report indicates that, despite improving regulatory oversight, future performance will still depend on USDC adoption, transaction activity, and Circle’s ability to generate revenue beyond reserve income.
Crypto World
As Wall Street accelerates blockchain adoption, SHR Miner opens access to AI-powered computing, offering daily earnings of up to $1,500
Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.
SHR Miner explores the rising demand for computing infrastructure as blockchain adoption expands across tokenized assets, stablecoins, and financial services.
Summary
- SHR Miner expands AI-powered cloud infrastructure, offering users automated access to distributed computing resources worldwide.
- It combines AI scheduling and renewable energy to provide global access to digital infrastructure services.
- SHR Miner enables users to access global computing resources without hardware through its AI-driven infrastructure platform.
Blockchain adoption is entering a new stage as major financial institutions move tokenized assets and stablecoin settlement closer to real-world deployment.
The Depository Trust & Clearing Corporation recently completed live production transactions involving tokenized U.S. Treasuries, equities, collateral, securities lending and repo settlement. Around 40 financial and technology organizations participated, including BlackRock, Goldman Sachs, JPMorgan, Circle and Fireblocks.
Visa has also expanded its digital asset strategy with a stablecoin platform designed to help banks and fintech companies issue, transfer and manage stablecoins across blockchain networks.
These developments indicate that blockchain is no longer limited to cryptocurrency trading. It is becoming part of the infrastructure used for payments, asset settlement and global financial operations.
As blockchain and artificial intelligence adoption accelerate simultaneously, demand for data centers, computing power, energy systems and automated digital infrastructure is also increasing.
SHR Miner connects users to the infrastructure economy
The SHR Miner AI-powered digital infrastructure platform allows users to access distributed computing resources without purchasing or maintaining physical mining equipment.
Founded in the United Kingdom in 2018, the platform operates more than 150 data centers and infrastructure nodes across a network serving over five million users in more than 180 countries and regions.
Users can register online, select an infrastructure contract and monitor daily settlement information through a mobile or browser-based dashboard.
No mining hardware, technical configuration or equipment maintenance is required.
- AI-powered scheduling: Computing resources are automatically allocated across global nodes according to performance, energy costs and operating conditions.
- Advanced algorithm capability: SHR Miner uses deep reinforcement learning, temporal convolutional networks and graph neural networks to analyze infrastructure and digital asset data.
- Renewable-energy operations: The platform combines hydroelectric, solar and wind energy with AI-based energy scheduling.
- Automated risk management: Internal systems analyze market and blockchain data, optimize capital allocation and monitor operational risks.
- Multi-asset support: Supported assets include BTC, ETH, DOGE, USDT, USDC, XRP, SOL, LTC and BCH.
- Cloud-based access: Users can view contracts, rewards and resource information entirely online.
Use case: Moving beyond short-term trading
Daniel M., a cryptocurrency user from Canada, previously relied mainly on spot trading and spent several hours each day monitoring Bitcoin and Ethereum price movements.
After joining SHR Miner, he first claimed the platform’s $15 new-user computing-power reward and used the introductory contract to understand the dashboard and daily settlement process.
He later selected the MICROBT WhatsMiner M66 contract:
- Contract amount: $3,000
- Duration: 15 days
- Listed daily reward: $40.80
- Listed contract reward: $612.00
The calculation was straightforward:
$40.80 × 15 days = $612.00
Daniel did not need to purchase a physical mining machine, arrange cooling systems or manage electricity and maintenance costs. The contract information and daily settlement results were displayed directly in the SHR Miner application.
“I wanted a simpler way to participate without constantly watching market charts,” Daniel said. “The platform allowed me to view the contract and daily results directly from my phone.”
Five selected SHR Miner contracts
Users can explore SHR Miner’s available cloud computing contracts and choose an entry level based on their preferred participation scale.
| Contract | Entry Amount | Duration | Daily Reward | Listed Contract Reward |
| MICROBT WhatsMiner M66 | $3,000 | 15 days | $40.50 | $607.50 |
| Bitcoin Miner S21 XP Imm | $5,000 | 25 days | $70.50 | $1,762.5 |
| Bitcoin Miner S21e XP Hyd | $10,000 | 35 days | $151.00 | $5,285 |
The tiered structure allows new users to begin with a lower-cost contract before deciding whether to access additional computing capacity.
For example:
$70.5 per day × 25 days = $1,762.5 with the Bitcoin Miner S21 XP Imm contract.
$151 per day × 35 days = $5282 with the Bitcoin Miner S21e XP Hyd.
Claim a limited-time $15 new-user reward
Eligible new users can currently receive a $15 free computing-power reward after registering with SHR Miner.
The process involves three simple steps:
Register → Claim the $15 reward → Download the application
Users can then view available infrastructure contracts and daily settlement information through the cloud dashboard.
New users can create an SHR Miner account and claim the $15 computing-power reward before exploring the platform’s available infrastructure services.
A new phase of digital infrastructure
As blockchain becomes part of the global financial system and artificial intelligence drives greater demand for computing resources, the infrastructure behind these technologies is becoming increasingly important.
SHR Miner combines global computing nodes, automated resource scheduling, renewable-energy management, and cloud-based access to provide users with a simpler way to participate in the emerging digital infrastructure economy.
No hardware purchase. No equipment maintenance. No specialist technical background.
Discover the future of AI-powered digital infrastructure with SHR Miner.
Disclosure: This content is provided by a third party. Neither crypto.news nor the author of this article endorses any product mentioned on this page. Users should conduct their own research before taking any action related to the company.
Crypto World
Bitcoin price nears $64K as 32,000 BTC hits exchanges
Bitcoin price rebounded toward $63,900 on Aug. 3 after briefly falling near $62,300, but weak spot demand and fresh short-term holder losses continue to limit its recovery.
Summary
- Bitcoin price recovered to $63,894 after testing an intraday low of $62,300.
- The daily RSI remained neutral at 49.28, while the MACD showed weakening momentum.
- Short-term holders reportedly sent 32,000 BTC to exchanges at a loss within 24 hours.
- Liquidation liquidity is concentrated near $62,000 and $64,000, raising volatility risks.
Bitcoin price recovers from $62,300
According to data from crypto.news, Bitcoin (BTC) price traded at $63,894 at the time of writing, up 0.51% for the day after moving between $62,300 and $63,993.
The recovery followed a sharp decline toward $62,600 noted in Glassnode’s latest market report. According to the on-chain analytics firm, Bitcoin failed to hold its earlier move above $66,000 as weak spot demand and persistent net selling kept the market within a consolidation phase.
The daily chart shows that BTC has stabilized slightly above the 78.6% Fibonacci retracement level at $63,183. This area has acted as a short-term pivot since the beginning of July, with repeated price movements on both sides of it.

However, the rebound has not yet changed Bitcoin’s broader structure. BTC continues to trade below its July peak near $66,900 and remains well under the 61.8% Fibonacci retracement level at $67,394.
A daily close above $64,000 would strengthen the short-term recovery. Failure to hold $63,183 could expose Bitcoin to another test of the $62,000 region.
Short-term Bitcoin holders lock in losses
Selling by short-term holders appears to be adding pressure near the lower end of Bitcoin’s range.
A CryptoQuant chart shared by market observer Whale Factor showed that approximately 32,000 BTC reached exchanges at a loss within a single day. The account described the move as the largest short-term holder capitulation event in 30 days.
Transfers to exchanges do not confirm that every coin was sold. Still, coins moving from short-term holders at a loss can indicate defensive positioning or capitulation, particularly when prices are testing support.
Glassnode reported a similar deterioration in market profitability. The proportion of Bitcoin’s supply held in profit is approaching a cyclical low, while investor spending patterns increasingly reflect stop-loss activity.
Long-term holders have remained more resilient. Glassnode said the ratio of supply held by short-term holders relative to long-term holders remains near historical lows, indicating that older coins are not moving at the same rate.
Network activity has also increased. Daily active addresses and adjusted transfer volume moved above their recent statistical ranges, suggesting that Bitcoin’s latest volatility has been accompanied by greater on-chain usage.
Liquidation clusters put $62,000 and $64,000 in focus
CoinGlass’s three-day liquidation heatmap shows two major pools of leveraged positions surrounding Bitcoin’s current price.

The closest upside cluster sits between roughly $63,800 and $64,100. Bitcoin’s rebound toward $63,900 has already brought the price into this area, where further gains could force leveraged short positions to close.
Additional liquidity is visible around $64,300, followed by thinner bands near $64,800 and $65,000. A decisive move through $64,100 could therefore accelerate toward the upper clusters, although weak spot buying may limit the size of any short squeeze.
The largest nearby downside concentration is around $61,900 to $62,200. This bright liquidity band sits just below Bitcoin’s latest intraday low and could attract price if the recovery loses momentum.
Bitcoin’s position between these two clusters leaves it vulnerable to sharp moves in either direction. A break above $64,100 could target $65,000, while a decline below $62,000 would put the June–July floor near $57,820 back in view.
Momentum remains neutral despite the rebound
Bitcoin’s daily relative strength index stands at 49.28, slightly below its signal average of 50.87. That reading shows balanced momentum rather than a clear advantage for buyers or sellers.
The MACD is less constructive. Its histogram has turned negative, while the MACD line remains below the signal line. This indicates that the recovery from the late-June low has lost momentum, even though Bitcoin has avoided another major breakdown.
For a stronger bullish reversal, BTC would need to reclaim $64,000 and then clear the July resistance zone between $66,000 and $67,394. The next Fibonacci targets would sit at $70,352 and $73,309.
The bearish scenario would gain traction if Bitcoin closes below $63,183 and subsequently loses $62,000. That would increase the risk of a decline toward $60,000, followed by the broader range floor near $57,820.
US investors will also be watching spot Bitcoin ETF flows for evidence of institutional demand. Glassnode said ETF inflows and trading volumes improved during the past week, providing some support even as spot-market momentum remained weak.
For now, Bitcoin’s rebound has defended near-term support but has not resolved the wider range. The concentration of liquidation leverage on both sides of the price makes $62,000 and $64,100 the main boundaries for the next directional move.
Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.
Crypto World
What is account abstraction and why seed phrases are becoming optional
Smart accounts replace seed phrases with passkeys, social recovery, and gas sponsorship, making self-custody usable without memorizing 12 words.
Summary
- Account abstraction (AA) upgrades Ethereum wallets from fixed key pairs to programmable smart contracts that define their own validation rules.
- ERC-4337, live on mainnet since March 2023, introduced AA without changing Ethereum’s core protocol by routing transactions through an alternative mempool of UserOperations.
- Passkey wallets such as Coinbase Smart Wallet and Safe replace seed phrases with biometric authentication tied to the device’s secure enclave.
- Gas sponsorship (paymasters) lets applications pay transaction fees on behalf of users, removing the requirement to hold ETH before interacting with a dapp.
- Social recovery allows a set of trusted guardians to restore wallet access if a device is lost, eliminating the single point of failure that seed phrases represent.
Introduction
The standard advice for anyone entering crypto has not changed in a decade: write down 12 words, store them offline, and never lose them. This instruction is correct under the old model. Externally owned accounts (EOAs) derive a single private key from that mnemonic, and whoever holds the key controls the funds. There is no recovery, no spending limit, no way to require a second signature. Lose the phrase, lose everything.
Account abstraction changes this premise. Instead of coupling wallet security to a single secret, AA turns the wallet itself into a smart contract, one that can enforce arbitrary rules about who may sign, how gas is paid, and what happens when a key is compromised. The upgrade does not require users to understand smart contracts. From the outside, a passkey wallet looks like logging into an app with a fingerprint. Underneath, the architecture is fundamentally different.
This guide explains how AA works at the protocol level, what ERC-4337 introduced, and why the shift matters for self-custody going forward.
How Ethereum wallets worked before account abstraction
Every Ethereum address before AA was an externally owned account. An EOA is controlled by a private key derived from a mnemonic seed phrase. The account has no on-chain logic. It can send transactions and sign messages, but it cannot enforce rules about those actions. For a broader overview of wallet types and their mechanics, see what are crypto wallets.
This design has three structural limitations:
No recovery mechanism. If the private key is lost and no backup exists, the account is permanently inaccessible. Chainalysis estimates that roughly 20% of all Bitcoin is held in wallets whose keys are presumed lost. Ethereum faces the same problem.
No spending controls. An EOA cannot limit transaction size, restrict destination addresses, or require multiple signatures. A single compromised key means total loss. Organizations that need shared control over funds must use external multisig contracts instead of native account features. For how those multisig setups work and where they have failed, see how crypto’s biggest treasuries get secured and robbed.
Gas must be paid by the sender. Every transaction requires the signing account to hold ETH for gas. A new user receiving tokens on Ethereum cannot move them without first acquiring ETH from somewhere else. This creates an onboarding dead end that has persisted since Ethereum’s launch in 2015.
What ERC-4337 introduced
ERC-4337, authored by Vitalik Buterin, Yoav Weiss, Kristof Gazso, Namra Patel, Dror Tirosh, and Shahaf Nacson, went live on Ethereum mainnet in March 2023. It delivers account abstraction without requiring a hard fork, which was a critical design constraint. Previous AA proposals (EIP-2938, EIP-3074) required protocol-level changes that validators and client teams were reluctant to adopt. ERC-4337 sidesteps this by operating entirely at the smart contract layer.
The standard introduces four components:
UserOperations. Instead of sending a regular transaction, users submit a UserOperation (UserOp), a data structure that describes the intended action. UserOps enter a separate mempool, not the standard transaction mempool. Each UserOp contains the sender’s smart account address, the calldata for the intended action, gas limits, and an optional paymaster address.
Bundlers. Specialized nodes collect UserOps from the alternative mempool, bundle them into a single on-chain transaction, and submit that transaction to the network. The bundler pays gas upfront and is reimbursed by the smart account or a paymaster. Bundling creates gas savings: the fixed overhead of an Ethereum transaction is paid once per bundle rather than once per user action.
EntryPoint contract. A singleton contract deployed at a canonical address on every ERC-4337 chain. All bundled UserOps pass through this contract, which calls each smart account’s validation function, executes the operation, and handles gas accounting. The EntryPoint contract has been audited by OpenZeppelin and is immutable once deployed, providing a stable trust anchor for the entire system.
Paymasters. Optional contracts that sponsor gas on behalf of users. A paymaster can pay fees in exchange for ERC-20 tokens, absorb costs as a dapp subsidy, or implement any other payment logic. The paymaster’s validatePaymasterUserOp function is called during validation, and the paymaster can reject operations that do not meet its criteria.
The result: a wallet is no longer a key pair. It is a smart contract with a programmable validateUserOp function that decides whether a given operation is authorized.
The UserOperation lifecycle in detail
Understanding how a UserOp moves through the system clarifies what makes AA different from regular transactions.
- Construction. The wallet application constructs a UserOp containing the target contract call, gas parameters, and a nonce. If a paymaster is involved, the paymaster address and its approval data are included.
- Signing. The user signs the UserOp. The signature format is defined by the smart account, not by the protocol. This is the key flexibility: the smart account can accept ECDSA signatures, passkey signatures, multisig thresholds, or any other scheme.
- Submission. The signed UserOp is submitted to a bundler via a JSON-RPC endpoint (
eth_sendUserOperation). The bundler validates the UserOp off-chain to ensure it will not revert. - Bundling. The bundler groups multiple UserOps into a single transaction that calls the EntryPoint contract’s
handleOpsfunction. - Execution. The EntryPoint calls each smart account’s validation function. If validation passes, the EntryPoint executes the operation. If a paymaster is present, the EntryPoint charges the paymaster instead of the smart account for gas.
- Confirmation. The bundled transaction is included in a block. Each UserOp within it is treated as an independent action that either succeeds or fails without affecting other UserOps in the bundle.
This lifecycle means the user never interacts with the Ethereum mempool directly. The bundler handles gas estimation, nonce management, and transaction submission. From the user’s perspective, the experience is closer to submitting a form on a website than to broadcasting a raw blockchain transaction.
Passkey wallets and the end of seed phrases
The most visible consequence of AA is that wallets can now authenticate users with passkeys instead of seed phrases.
A passkey is a cryptographic credential stored in a device’s secure enclave (the Secure Enclave on Apple devices, Titan M on Google Pixels, or TPM on Windows machines). The user authenticates with a fingerprint, face scan, or device PIN. The private key never leaves the hardware.
Coinbase Smart Wallet, launched in June 2024, uses this approach. Account creation takes under 10 seconds. The user authenticates with a biometric, and the wallet deploys a smart contract account that recognizes that passkey as a valid signer. There is no seed phrase to write down, no browser extension to install. Coinbase reported deploying over 10 million smart accounts through this flow by early 2026.
Safe (formerly Gnosis Safe) has integrated passkey signing into its smart account framework. Users can add a passkey as one of multiple signers on a multi-signature account, combining the convenience of biometric login with the security of threshold signatures.
The tradeoff is platform dependency. A passkey created on an iPhone is synced through iCloud Keychain. If a user loses all Apple devices and cannot access iCloud, the passkey is gone. This is why social recovery exists as a complementary layer. Passkey wallets are strongest when combined with at least one backup signer that uses a different authentication method.
Social recovery: replacing backup with guardians
Social recovery, proposed by Vitalik Buterin in a 2021 blog post, replaces the single backup (seed phrase) with a group of guardians.
The mechanism works as follows:
- The wallet owner designates a set of guardians. Guardians can be friends, family members, institutional custodians, or even other smart contracts.
- The owner sets a threshold. For example, 3 of 5 guardians must approve a recovery request.
- If the owner loses access, they initiate a recovery process from a new device. Guardians independently confirm the request.
- Once the threshold is met, the smart account replaces the lost signing key with a new one.
The guardians do not need to coordinate simultaneously. Most implementations include a time delay (typically 24 to 48 hours) during which the original owner can cancel a fraudulent recovery attempt.
This model eliminates the single point of failure. Losing a device does not mean losing funds, as long as enough guardians are reachable. It also eliminates the physical security burden of storing a seed phrase in a fireproof safe or safety deposit box.
Guardian selection matters significantly. Guardians should be distributed across different geographies, communication channels, and relationship types. If all guardians are in the same group chat and that chat is compromised, the recovery mechanism becomes an attack vector. Some implementations allow adding institutional guardians (such as a hardware wallet provider or a custodial service) alongside personal contacts, creating defense in depth.
Gas sponsorship and how paymasters work
Before AA, a new user who received USDC on Ethereum could not send it anywhere without first acquiring ETH to pay gas. This chicken-and-egg problem has been one of the largest onboarding barriers in crypto.
Paymasters solve this. A paymaster is a smart contract that agrees to cover gas costs for a UserOperation, subject to its own rules.
Three common paymaster models have emerged:
Dapp-sponsored gas. The application pays all gas for its users. The dapp deposits ETH into the paymaster contract and authorizes UserOps from its users. From the user’s perspective, transactions are free. Dapps treat gas as a customer acquisition cost, similar to free shipping in e-commerce. This model is particularly effective on Layer 2 networks where gas costs are fractions of a cent per transaction.
ERC-20 gas payment. The paymaster accepts an ERC-20 token (USDC, DAI) instead of ETH. The user pays for gas, but in a token they already hold. The paymaster swaps the token for ETH to reimburse the bundler. This removes the need for users to hold two separate tokens (the asset they want to use plus ETH for gas).
Subscription or session-based. The paymaster authorizes a batch of operations within a time window or spending limit. A gaming dapp might sponsor 100 transactions per day per user, for example. Session keys extend this concept further: the user signs a single transaction that grants a temporary key the right to perform specific actions (such as moves in a game) without requiring approval for each one.
Pimlico, Alchemy, and Stackup operate paymaster infrastructure that dapps can integrate with a few API calls. Alchemy alone has facilitated over one million smart account deployments through its paymaster and bundler services. The economics are straightforward: on Layer 2 networks where gas costs pennies, sponsoring user transactions is trivially cheap.
EIP-7702 and the road to native account abstraction
ERC-4337 works without protocol changes, but it is not the end state. Ethereum’s roadmap includes EIP-7702 (authored by Vitalik Buterin and Sam Wilson), which was included in the Pectra upgrade.
EIP-7702 introduces a new transaction type that allows an EOA to temporarily point to smart contract code for the duration of a single transaction. The EOA does not permanently become a smart contract. Instead, it can behave like one when needed, gaining access to batched calls, sponsored gas, and custom validation logic, and then revert to standard EOA behavior.
This matters for two reasons. First, it lets existing EOA holders (anyone with a MetaMask wallet today) access AA features without migrating to a new account. Migration has been a major friction point: users do not want to move all their assets, permissions, and on-chain history to a new address. Second, it reduces gas costs because the permanent smart account deployment overhead is avoided for users who only need AA features occasionally.
The long-term vision, discussed across multiple Ethereum Foundation roadmap posts, is that every account on Ethereum becomes a smart account by default. StarkNet and zkSync already implement this: on those networks, every account is a smart contract from creation. EIP-7702 is the bridge that moves Ethereum’s existing user base toward this model without breaking backward compatibility.
Where account abstraction is deployed today
AA adoption is concentrated on Layer 2 networks where gas costs make experimentation cheap.
Base has the highest density of smart accounts, driven by Coinbase Smart Wallet. By mid-2026, Base had processed over 30 million UserOperations. The network’s sub-cent gas costs make paymaster sponsorship economically trivial.
Polygon integrated AA early and offers native account abstraction at the protocol level in its zkEVM rollup. Polygon’s focus on gaming and social applications aligns well with the session-key model, where users need many low-value transactions without repeated approval prompts.
Arbitrum and Optimism support ERC-4337 through the standard EntryPoint contract. Major dapps on both chains have begun migrating onboarding flows to smart accounts, particularly DeFi protocols that want to offer gasless first trades. For context on how Ethereum updates enabled wallets to operate as smart contracts, the timeline begins with the ERC-4337 EntryPoint deployment.
Ethereum mainnet supports ERC-4337 but higher gas costs mean paymaster sponsorship is more expensive. Most mainnet AA usage comes from high-value multi-sig wallets (Safe) rather than consumer dapps. Safe manages over $100 billion in assets across its smart account deployments.
StarkNet and zkSync implement native account abstraction at the protocol level, meaning every account is a smart contract by default. This is the direction Ethereum’s long-term roadmap points toward.
What this does not cover
This guide focuses on the mechanism of account abstraction and its immediate consequences for wallet design. It does not cover:
- Detailed comparison of specific smart account implementations (Safe, Kernel, Biconomy, ZeroDev)
- The MEV implications of the UserOperation mempool (for MEV mechanics, see what is MEV)
- Formal security audits of individual paymaster contracts
- Cross-chain account abstraction and how smart accounts interact with bridging
Practical checks for evaluating an AA wallet
Before trusting funds to a smart account wallet, consider these questions:
Is the smart contract audited? Check whether the wallet’s smart account implementation has undergone third-party security audits. Safe’s contracts are among the most audited in DeFi. Newer implementations may not have the same track record.
What happens if the provider shuts down? A passkey wallet tied to a single vendor creates a new form of dependency. Look for wallets that allow adding multiple signers, including a traditional private key as a backup.
Where is the passkey stored? Understand whether the passkey is device-bound or synced through a cloud provider. iCloud Keychain and Google Password Manager sync passkeys, which is convenient but expands the attack surface to include cloud account security.
Does the wallet support social recovery? If the only authentication method is a passkey and the passkey is lost, funds may be unrecoverable. Social recovery adds a safety net. Check how many guardians the wallet supports and whether the recovery process has been tested.
What chains does the smart account work on? A smart account on Ethereum mainnet has a different address than the same account on Arbitrum unless the wallet uses CREATE2 deterministic deployment. Verify cross-chain compatibility before depositing funds on multiple networks.
What is the upgrade path? Some smart account implementations are upgradeable (the contract logic can be changed by the owner). This is powerful but introduces risk: a compromised upgrade key could rewrite the wallet’s validation logic. Check whether upgrades require a time delay or multi-party approval.
What is account abstraction in simple terms?
Account abstraction turns a crypto wallet from a fixed key pair into a programmable smart contract. Instead of relying on a single seed phrase, the wallet can enforce custom rules for signing, recovery, and gas payment. The user experience changes from “guard these 12 words with your life” to “log in with your fingerprint.”
Is ERC-4337 the only way to implement account abstraction?
No. ERC-4337 is the most widely adopted standard on Ethereum because it works without protocol changes. StarkNet and zkSync implement native account abstraction at the protocol level. Ethereum’s roadmap includes EIP-7702, which allows EOAs to temporarily delegate to smart contract logic, bringing native AA closer to mainnet.
Are passkey wallets safe?
Passkey wallets are as secure as the device’s secure enclave and the cloud sync service backing them. The private key never leaves the hardware security module, making remote extraction extremely difficult. The main risk is losing access to the cloud account that syncs the passkey across devices. Adding a backup signer or enabling social recovery mitigates this.
Can I still use a seed phrase with account abstraction?
Yes. A smart account can accept a traditional private key (derived from a seed phrase) as one of its authorized signers. Many AA wallets allow users to add a seed-phrase-based key as a backup alongside a passkey. The difference is that the seed phrase is no longer the only option.
What is a paymaster?
A paymaster is a smart contract in the ERC-4337 system that pays gas fees on behalf of users. It can sponsor transactions entirely (dapp-subsidized), accept ERC-20 tokens as gas payment, or enforce spending limits. Paymasters remove the requirement for users to hold ETH before transacting.
How does social recovery work?
The wallet owner designates a group of guardians and sets a threshold (for example, 3 of 5). If the owner loses access, they request recovery from a new device. Once enough guardians approve, the smart account replaces the lost key with a new one. A time delay allows the original owner to cancel fraudulent attempts.
Do I need to pay gas to deploy a smart account?
Deployment costs gas, but the user does not necessarily pay it. Many AA wallet providers sponsor the deployment transaction through a paymaster, so the smart account is created at no cost to the user. The deployment typically happens lazily, only when the user sends their first transaction, rather than at account creation.
Which networks support account abstraction today?
ERC-4337 is live on Ethereum mainnet, Base, Arbitrum, Optimism, Polygon, Avalanche, BNB Chain, and most major EVM networks. StarkNet and zkSync have native AA built into their protocol. Layer 2 networks see the highest usage because low gas costs make paymaster sponsorship economically viable.
*Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency involves significant risk, and you should conduct your own research before making any decisions. Information is accurate as of August 2026.*
Crypto World
Boltz Suspends Bitcoin Swaps amid Surge in AI-Assisted Attacks
Boltz, a non-custodial Bitcoin swap service, says it is disabling its service until further notice after a rise in AI-assisted hacking attempts over the last few months.
In a post to X on Monday, Boltz said the decision came after seeing a steady increase in “automated AI-assisted probing” of its infrastructure this year.
“Over the past months… we have dealt with several exploits. Each was contained, but the pattern is clear: attackers now iterate faster than a team our size can find and patch.”
“After reviewing the results of our own recent security scans, we cannot responsibly re-enable Boltz swaps, especially as we are being actively targeted by what appear to be multiple resourceful groups while we race to deploy fixes.”
Boltz’s operational pause highlights the difficulty that smaller development teams are facing, as attackers discover vulnerabilities and adapt exploits faster than they can respond.

Source: Boltz
“In the past few days alone we saw a drastic acceleration [of attacks] and we do not believe this asymmetry will reverse,” said Boltz.
Solana’s security chief calls for automated defense
In July, Solana Foundation’s new chief information security officer, Michael Coates, told Cointelegraph there is a need to switch to automated defenses in the age of AI.
“We’re at a tipping point as an industry where humans cannot scale to meet these threats,” said Coates.
“The only path forward we have is to have autonomous defense that operates at the speed of machines.”
PayPerQ, a pay-per-prompt AI service that takes payment in Bitcoin and other cryptocurrencies, said it has also been dealing with a surge in exploits, possibly AI-powered.
“We’ve been fighting off exploits every other week for several months, most of which we believe are AI-powered. It’s a very dangerous time out there.”
No user funds at risk
Boltz lets users perform non-custodial, trustless atomic swaps, moving Bitcoin and Bitcoin-denominated assets between the mainnet and different layers of Bitcoin such as Lightning Network and Liquid Network.
Related: AI has not triggered DeFi ‘hackpocalypse,’ Dragonfly partner says
DefiLlama shows total value locked on Boltz at the time of writing is $180,860.
Boltz said no user funds have ever been at risk, as all Boltz swaps use advanced cryptography and are non-custodial, which means users retain full control of their assets throughout the swap process.
Boltz said its API will remain available to process refunds, and its support team will stay reachable.
“What we are seeing is a major paradigm shift for Bitcoin services operating on an open source stack, and it needs careful analysis. Do not expect swap services to resume shortly.”
Magazine: Fears of AI-driven DeFi hack epidemic overstated for now — but not for long
Crypto World
Bithumb Maps 2028 IPO Timeline as It Tightens Internal Controls
South Korea’s crypto exchange Bithumb said it intends to pursue a preliminary listing review in 2027 and complete an initial public offering (IPO) in 2028. The plan follows a corporate restructuring aimed at clarifying responsibilities across its business units and reducing potential conflicts of interest ahead of regulatory scrutiny.
In its announcement, Bithumb said preparations will include strengthening internal controls and moving from domestic accounting standards to K-IFRS, the international financial reporting framework used by listed companies in South Korea. The exchange added that the schedule could shift depending on market conditions and the timing of reviews by relevant authorities.
Key takeaways
- Bithumb targets a 2027 preliminary listing review and an IPO completion in 2028, subject to regulatory timelines.
- The exchange is restructuring its business, including spinning off Bithumb Asset, to separate responsibilities and limit conflicts of interest.
- Bithumb plans to upgrade internal controls and adopt K-IFRS accounting as part of its listing readiness.
- The IPO push comes amid intensified competition among South Korean exchanges as rivals deepen ties with traditional finance and technology groups.
- Recent issues linked to promotional controls and audits at Bithumb-affiliated listed firms add more scrutiny to the group’s broader compliance posture.
Restructuring and K-IFRS as IPO prerequisites
Bithumb’s statement points to two major adjustments intended to make it more “listing-ready.” First, it has reorganized its business structure, including the spin-off of Bithumb Asset, to sharpen accountability across units and reduce the risk of overlapping interests.
Second, it said it will upgrade internal control systems and switch to K-IFRS from domestic accounting standards. For exchanges preparing for public markets, the shift to K-IFRS typically signals an effort to align financial reporting with the requirements expected of companies after they become subject to broader investor and regulator oversight.
The exchange also cautioned that its timetable is not guaranteed. “Market conditions” and the review schedules of relevant authorities could change the pace of its listing process.
Fiat rails and competitive pressure from legacy finance
Bithumb is one of five South Korean exchanges that support fiat trading via real-name bank accounts, an offering delivered through its partnership with KB Kookmin Bank. That positioning matters because fiat on-ramps and compliance-driven user onboarding are central parts of how South Korean exchanges operate and how regulators evaluate market infrastructure.
Meanwhile, Bithumb’s IPO ambitions arrive as competitors push deeper connections with traditional finance and technology players. According to earlier coverage from Cointelegraph, Mirae Asset Consulting took control of rival exchange Korbit on July 23. Cointelegraph also reported that Upbit operator Dunamu is pursuing a share-swap arrangement that would make it a wholly owned subsidiary of Naver Financial, though completion is contingent on regulatory and shareholder approvals.
This backdrop suggests that Bithumb is not just preparing for capital markets—it is also moving in a landscape where large corporate backers may influence customer acquisition, risk management, and the pace of product and infrastructure development.
A compliance test after a 620,000 BTC crediting mix-up
Bithumb’s listing plans also come with attention on its operational controls. In a February promotional error, Bithumb mistakenly credited customer accounts with balances totaling 620,000 Bitcoin rather than distributing 620,000 Korean won in cash rewards. Cointelegraph previously reported that Bithumb recovered 99.7% of the erroneous credits, while customers sold about 1,788 BTC before account freezing.
At a Feb. 11 National Assembly parliamentary hearing, Bithumb CEO Lee Jae-won said the exchange’s process for checking the intended distribution against its actual holdings had failed, and that the promotional amount was not set aside in a separate account. Reporting on the hearing was carried by Yonhap.
For investors, that incident is relevant even though it involved a promotional mechanism rather than core trading operations. It highlights the importance of robust reconciliation procedures—an area regulators often scrutinize when a company moves from private or quasi-private market activity into public-company oversight.
Audit and listing troubles at Bithumb-linked firms
Bithumb’s IPO preparation is further complicated by audit and listing problems reported for companies linked to the exchange. Cointelegraph noted that Vidente, a major Bithumb shareholder, and Bucket Studio, which indirectly controls Vidente, have had their share trading suspended since March 2023 due to audit and other listing issues.
Yonhap reported that in June, Bucket Studio appointed a former police official as its standing auditor, and that Vidente plans to appoint a former National Tax Service official to the same role. Yonhap also said South Korea’s Government Public Service Ethics Committee cleared both hires after concluding there was no close relationship between the officials’ previous duties and their new roles.
While these developments do not automatically block Bithumb’s own listing timeline, they add another layer of scrutiny to the group’s corporate governance narrative—especially as Bithumb positions internal control upgrades and accounting standard changes as central steps toward public-market readiness.
As 2027 approaches, the key question for readers will be whether Bithumb’s announced restructuring, internal control upgrades, and K-IFRS transition can withstand regulatory review while addressing the operational and governance pressure points already in the public record. Any adjustment to the timetable could offer early signals about how regulators weigh those factors against the exchange’s preparation efforts.
Crypto World
What are intents and solvers? The invisible layer executing your DeFi trades
Intent-based protocols separate what a user wants from how it gets done, outsourcing execution to competitive solvers who find the best price across fragmented liquidity.
Summary
- An intent is a signed message describing a desired outcome (for example, “swap 1 ETH for at least 3,200 USDC”) rather than a specific execution path.
- Solvers are specialized agents that compete to fill intents, searching across DEXs, CEXs, private inventory, and cross-chain liquidity to find the optimal route.
- CoW Protocol, UniswapX, and Across are the three largest intent-based systems, collectively processing billions in monthly volume by mid-2026.
- Intent architectures protect users from MEV extraction by removing transactions from the public mempool, where frontrunners and sandwich bots operate.
- The tradeoff is trust: users must trust that the solver auction is competitive and that the protocol’s settlement contract enforces the promised outcome.
Introduction
Most DeFi users believe they interact directly with an automated market maker when they swap tokens on Uniswap or SushiSwap. In 2022, this was broadly true. A user signed a transaction, that transaction entered the public mempool, a validator included it in a block, and the AMM’s constant-product formula determined the price.
This model has a problem. Public mempools are hunting grounds. MEV bots monitor pending transactions and execute sandwich attacks: they buy before your trade pushes the price up, then sell after, extracting value from the spread. Flashbots estimated that MEV extraction on Ethereum exceeded $600 million in cumulative profit by 2023, with a significant share coming from sandwich attacks on retail swaps. For a deeper look at how this extraction works, see what is MEV.
Intent-based protocols restructure this flow. Instead of broadcasting a transaction that specifies every execution detail, the user signs an intent: a declarative statement of the desired result. A network of solvers then competes to fill that intent at the best possible price, off-chain, without exposing the order to the public mempool.
This guide explains the mechanics of intents and solvers, how the major protocols implement them, and what tradeoffs users accept.
The problem with direct AMM interaction
When a user swaps tokens through a traditional AMM, the transaction encodes a specific path: swap token A for token B on pool X, with a minimum output of Y, by deadline Z. This specificity creates three problems.
MEV vulnerability. The transaction sits in the public mempool until a validator includes it. During that window, bots can see the intended trade and sandwich it, extracting value from the user. Academic research from the Flashbots team documented that sandwich attacks cost retail users an estimated $200 million to $300 million annually on Ethereum alone. One particularly striking case saw a DeFi trader suffer 100% slippage in a sandwich attack, losing the entire value of the trade.
Suboptimal routing. A user submitting a transaction to a single AMM gets that AMM’s price. But liquidity is fragmented across dozens of DEXs, multiple chains, and centralized exchanges. The best price for a given swap might involve splitting the order across three pools on two chains, a route the user’s simple transaction never considers.
Gas inefficiency. Each user pays gas individually. If 50 users want to swap ETH for USDC in the same block, they submit 50 separate transactions, each paying its own gas overhead. There is no mechanism for batching.
How intents work
An intent inverts the transaction model. Instead of specifying how to execute a trade, the user specifies what they want to achieve.
A typical intent contains:
- Input token and amount. What the user is willing to spend.
- Output token and minimum amount. What the user wants to receive, with a floor price.
- Expiration. A deadline after which the intent expires.
- Signature. Cryptographic proof that the user authorized this intent.
The intent is not a blockchain transaction. It is an off-chain signed message, submitted to a protocol-specific order flow system instead of the Ethereum mempool. This distinction is crucial: because the intent never enters the public mempool, it is invisible to MEV bots scanning for sandwich opportunities.
Once submitted, the intent enters a solver auction. The signed message grants conditional approval for a settlement contract to transfer the user’s input tokens, but only when the solver delivers the promised output. The user’s funds remain in their wallet until the moment of atomic settlement.
What solvers do and how they compete
A solver is an entity (a bot, a market maker, a trading firm) that monitors incoming intents and competes to fill them.
The competition works differently across protocols, but the general structure is:
- Intent broadcast. The protocol distributes new intents to registered solvers.
- Solution generation. Each solver analyzes the intent and determines how to fill it. A solver might route through multiple DEX pools, tap private inventory, bridge from another chain, or combine several intents into a single batch.
- Bid submission. Solvers submit their proposed execution, including the output the user will receive.
- Auction resolution. The protocol selects the winning solver, typically the one offering the user the best price after all costs.
- On-chain settlement. The winning solver executes the trade on-chain, and the settlement contract verifies that the user received at least the promised minimum output.
Solvers operate at their own risk. They front the capital, pay gas, and handle execution complexity. Their profit comes from the spread between the price they can source and the price they bid to the user, minus gas and capital costs. Competition between solvers compresses this margin, pushing more value back to users.
The economics of solver operation create a natural barrier to entry. Competitive solving requires capital for inventory, low-latency infrastructure for monitoring multiple liquidity sources, and sophisticated routing algorithms. The scale at which MEV bots operate illustrates the computational intensity of on-chain execution optimization. Solvers do the same work but channel the value toward users instead of extracting it.
CoW Protocol: batch auctions and coincidence of wants
CoW Protocol (formerly CowSwap) pioneered the intent-solver model on Ethereum. The name derives from “coincidence of wants” (CoW), a concept from economics.
The key innovation is batch auctions. Instead of filling orders one at a time, CoW Protocol collects intents over a window (approximately 30 seconds), then runs a single batch auction where solvers compete to fill all orders simultaneously.
This creates an opportunity for direct matching. If Alice wants to sell 1 ETH for USDC and Bob wants to buy 1 ETH with USDC, a solver can match them peer-to-peer without touching a liquidity pool. Neither party pays the AMM’s fee or spread. The solver profits by capturing the spread between the two users’ limit prices.
CoW Protocol calls this a “coincidence of wants” trade. In practice, pure CoW trades account for a meaningful minority of volume, but when they occur, both parties get prices better than any AMM can offer.
For orders that cannot be matched peer-to-peer, solvers route through on-chain liquidity. The batch auction format still helps: because all orders settle in a single transaction, gas costs are amortized across the batch. A batch of 30 swaps pays the fixed transaction overhead once, not 30 times.
By mid-2026, CoW Protocol had processed over $80 billion in cumulative volume, making it one of the largest DEX protocols by trade count. Its solver set has also matured, with established market makers and trading firms competing alongside independent solver operators.
UniswapX: Uniswap’s intent layer
UniswapX, launched in 2023, adds an intent-based execution layer on top of Uniswap’s existing liquidity pools.
When a user submits a swap through the Uniswap interface, they can opt into UniswapX. Instead of routing directly through Uniswap V3 or V4 pools, the swap becomes an intent. Solvers (called “fillers” in UniswapX terminology) compete to fill it.
UniswapX introduces Dutch order auctions. The user’s minimum acceptable output starts high and decays over time, following a predefined curve. The first solver willing to fill at the current price wins. This mechanism incentivizes solvers to fill quickly (they get a better margin early) while protecting users from receiving a bad price (the auction starts at an aggressive level).
A critical design choice: if no solver fills the order before it reaches the Uniswap pool price, the order automatically falls back to on-chain Uniswap routing. The user always gets at least the AMM price. Solvers can only win by offering something better.
UniswapX also introduces cross-chain intents. A user on Arbitrum can express an intent to receive tokens on Optimism. The solver handles the bridging, and the settlement contracts on both chains verify the outcome. From the user’s perspective, it is a single swap. This cross-chain capability was expanded in 2025 with permissionless bridging across nine networks, powered by the Across Protocol’s intent infrastructure.
Across: intents for cross-chain transfers
Across Protocol applies the intent-solver model specifically to cross-chain transfers.
Bridging tokens between chains traditionally involved lock-and-mint mechanisms, optimistic verification windows (often 7 days for optimistic rollups), or liquidity pool-based bridges. All of these are slow, expensive, or both.
Across restructures bridging as an intent. The user signs a message: “I have 1,000 USDC on Ethereum and want 1,000 USDC on Arbitrum.” A solver (called a “relayer” in Across) immediately sends 1,000 USDC to the user on Arbitrum from its own inventory, then later claims reimbursement from Across’s settlement system on Ethereum.
The result: bridge times measured in seconds rather than minutes or days. The user does not wait for the cross-chain verification. The solver takes on that waiting risk in exchange for a fee.
Across’s verification layer uses an optimistic oracle (UMA). If the solver’s claim is not disputed within a challenge window, the reimbursement is processed. This creates an economic game where honest relaying is profitable and fraudulent claims are punished by bond slashing.
Across’s collaboration with Uniswap on the Open Intents Framework aims to standardize how intents work across protocols, reducing the fragmentation that currently forces users to pick a specific intent system.
ERC-7683 and the standardization push
A major limitation of current intent systems is that each protocol defines its own intent format, solver network, and settlement contract. An intent submitted to CoW Protocol cannot be filled by a UniswapX solver. This fragmentation limits solver competition and reduces the pool of available liquidity for each system.
ERC-7683, proposed by Uniswap and Across in 2024, aims to create a universal standard for cross-chain intents. The proposal defines a common intent format (called a “CrossChainOrder”) that any protocol can adopt. Solvers who implement the standard can fill intents from any compliant protocol, increasing competition and improving prices.
The standard defines two interfaces: ISettlementContract (which settlement contracts implement) and IOriginSettler / IDestinationSettler (which handle cross-chain execution). By standardizing these interfaces, ERC-7683 would let a single solver operate across CoW Protocol, UniswapX, and Across simultaneously, competing for order flow from all three.
Adoption is still early. The standard requires existing protocols to modify their settlement contracts, which involves security audits and governance votes. But the direction is clear: intent-based trading is moving toward a unified solver marketplace instead of fragmented protocol-specific pools.
The tradeoffs of intent-based systems
Intent-based protocols improve user outcomes on price and MEV protection. They also introduce new trust assumptions and risks.
Solver centralization. In practice, a small number of well-capitalized solvers win most auctions. CoW Protocol’s solver leaderboard consistently shows 3 to 5 solvers handling the majority of volume. If solver competition weakens, users lose the price improvement that makes the system valuable.
Latency. Batch auctions and solver competitions add time between order submission and execution. CoW Protocol’s batches settle roughly every 30 seconds. UniswapX’s Dutch auctions resolve faster but still involve a delay. For time-sensitive trades, this latency can matter.
Solver trust. Users trust that the settlement contract correctly enforces the minimum output. The smart contracts are audited, but they are still smart contracts. Additionally, the off-chain auction mechanism must be fair. If the protocol operator can privilege certain solvers, the auction is not truly competitive.
Censorship risk. Because intents are submitted off-chain to protocol-specific systems, the protocol operator could theoretically censor certain intents. This is a different trust model than submitting transactions directly to Ethereum’s censorship-resistant mempool.
Regulatory attention. Solver networks that route order flow bear structural resemblance to broker-dealers in traditional finance. The question of whether solver activity constitutes regulated market making is unresolved. Regulatory clarity could either legitimize the model or impose compliance requirements that reduce the number of active solvers.
What this does not cover
This guide explains the core mechanism of intents and solvers. It does not cover:
- The technical implementation of specific solver algorithms
- Regulatory considerations around solver activity (order flow payment, best execution obligations)
- Detailed tokenomics of CoW Protocol (COW token) or UMA (used by Across)
- The relationship between intents and Ethereum’s proposer-builder separation (PBS) roadmap
Practical checks before using intent-based protocols
Compare prices. Before submitting an intent, check the quoted output against direct AMM execution. Intent-based protocols should consistently offer better prices. If they do not, the solver auction may not be competitive.
Understand the fallback. UniswapX falls back to on-chain AMM routing if no solver fills the order. CoW Protocol expires unfilled orders. Know what happens if solvers do not execute your intent.
Check slippage tolerance. The minimum output in an intent functions like a slippage tolerance. Setting it too tight may result in unfilled orders. Setting it too loose gives solvers room to offer worse prices. Most interfaces set a default, but users can adjust it.
Verify the settlement contract. The smart contract that enforces intent execution is the critical trust component. Check whether it has been audited and by whom. Look for contracts that are immutable or governed by a time-locked multisig rather than a single admin key.
Consider order size. Intents offer the most price improvement for medium to large orders, where routing optimization and MEV protection have the greatest impact. For very small swaps on low-gas chains, the price improvement may be negligible because MEV extraction is less profitable on small orders.
Watch for gas overhead. On Ethereum mainnet, the settlement contract execution adds gas costs that may offset the price improvement for small trades. On Layer 2 networks where gas is cheap, this overhead is negligible. Compare the total cost (including gas) of an intent-based swap against a direct AMM trade to see the net benefit.
The future of intent-based trading
Intent-based architectures are expanding beyond simple token swaps. Several trends are emerging by mid-2026.
Multi-action intents. Current intents describe single operations (swap token A for token B). Next-generation systems allow compound intents: “swap A for B, deposit B into a lending protocol, and borrow C against it” as a single atomic intent. Solvers who can execute the entire sequence efficiently compete for the bundle.
AI-powered solvers. Machine learning models are being applied to solver optimization. An AI solver can predict short-term price movements, anticipate liquidity conditions across chains, and dynamically adjust routing strategies. The computational advantage of AI-powered solvers could accelerate the trend toward solver centralization, as only well-resourced teams can train and operate these models.
Intent-aware wallets. Wallets are beginning to default to intent-based execution for all swaps, making the intent layer invisible to users. MetaMask’s integration of Uniswap’s API for in-wallet swaps points toward a future where every wallet swap is automatically routed through a solver auction, with users seeing only the quoted price and confirmation.
Regulatory frameworks. As intent-based trading grows, regulators are beginning to examine whether solver activity constitutes regulated financial services. The Payment for Order Flow (PFOF) model in traditional equity markets has structural similarities to how some protocols compensate solvers. Regulatory clarity will shape whether intent-based trading remains permissionless or requires licensed participants.
What is the difference between a transaction and an intent?
A transaction specifies exactly how to execute an action: call this contract, with these parameters, paying this much gas. An intent specifies the desired outcome: I want to swap this for that, receiving at least this much. The execution details are left to solvers who compete to find the best path.
Do I need to trust solvers with my funds?
No. Solvers never take custody of user funds in well-designed intent protocols. The user signs an intent that authorizes a settlement contract to transfer tokens only when the solver delivers the promised output. The smart contract enforces the atomic swap. If the solver cannot deliver, the trade does not execute.
How do solvers make money?
Solvers profit from the spread between the price they can source liquidity at and the price they bid in the auction. If a solver can buy 1 ETH for 3,195 USDC across various sources and fill a user’s intent at 3,200 USDC, the solver keeps the 5 USDC difference minus gas costs. Competition between solvers compresses this margin over time.
Can intents be censored?
Intents submitted to protocol-specific off-chain systems can theoretically be censored by the protocol operator. This is a different trust assumption than submitting transactions to Ethereum’s decentralized mempool. Some protocols mitigate this by running open solver networks where anyone can participate.
Are intent-based swaps always cheaper than direct AMM trades?
Usually, but not guaranteed. Intent-based protocols offer better prices when solver competition is strong and there is enough order flow to enable batch optimization or coincidence-of-wants matching. For very small trades or during periods of low solver activity, the improvement may be minimal.
What happens if no solver fills my intent?
It depends on the protocol. UniswapX falls back to direct on-chain Uniswap routing, so the trade still executes at the AMM price. CoW Protocol expires unfilled orders after the batch window, and the user can resubmit. Across intents expire if no relayer fills them within the deadline.
How do intents protect against MEV?
Intents are signed messages submitted off-chain, not transactions in the public mempool. Since MEV bots operate by monitoring the mempool for pending transactions to sandwich, removing the transaction from the mempool removes the attack vector. The solver executes the trade on-chain, but the solver is a sophisticated actor who can protect against MEV during their own execution.
Can I use intents for cross-chain trades?
Yes. UniswapX supports cross-chain intents where a user swaps tokens on one chain and receives tokens on another. Across Protocol is built entirely around cross-chain intents for bridging. The solver handles the cross-chain execution, and settlement contracts on both chains verify the outcome.
*Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency involves significant risk, and you should conduct your own research before making any decisions. Information is accurate as of August 2026.*
Crypto World
How cross-chain bridges work and why $4 billion has been stolen from them
Bridges move assets between blockchains using lock-and-mint, burn-and-mint, or liquidity pool mechanisms, but their trust assumptions have made them the most exploited category in crypto.
Summary
- Cross-chain bridges transfer value between blockchains that cannot natively communicate, using mechanisms like lock-and-mint, burn-and-mint, and liquidity pools.
- Bridge exploits have caused over $4 billion in losses since 2021, making bridges the single most attacked category of smart contracts.
- The Ronin ($624 million), Wormhole ($326 million), and Nomad ($190 million) hacks each exploited different trust assumptions, from compromised validator keys to faulty message verification.
- Light client bridges and zero-knowledge proof verification offer stronger security guarantees but are more expensive to operate and slower to deploy.
- Users should evaluate a bridge’s verification mechanism, audit history, and total value locked relative to its security budget before transferring significant funds.
Introduction
Blockchains do not talk to each other. Ethereum cannot read Solana’s state. Arbitrum cannot verify a transaction on Avalanche. Each chain maintains its own ledger, its own consensus, and its own finality rules. This isolation is a feature of security design, but it creates a practical problem: users hold assets on one chain and want to use them on another.
Bridges exist to solve this. A bridge is a system that lets a user deposit assets on chain A and receive corresponding assets on chain B. The concept sounds simple. The implementation is where billions of dollars have been lost.
The core difficulty is verification. When a user claims to have deposited 100 ETH on Ethereum and asks for 100 ETH on Arbitrum, someone or something must verify that the deposit actually happened. The mechanism chosen for this verification determines the bridge’s security model, its speed, its cost, and its attack surface. As a Coinbase analysis of bridge hacks noted, bridge security failures consistently stem from the gap between the trust assumptions a bridge claims and the trust assumptions it actually enforces.
This guide covers how the major bridge architectures work, why each of the largest exploits succeeded, and what to check before trusting a bridge with your funds.
Lock-and-mint: the original bridge mechanism
The earliest and most common bridge design is lock-and-mint. The mechanism works in three steps:
- Lock. The user sends tokens to a smart contract on the source chain. The tokens are locked (held) in that contract, not burned or transferred.
- Verify. A set of validators, relayers, or an oracle observes the deposit on the source chain and attests to its validity on the destination chain.
- Mint. A smart contract on the destination chain mints a synthetic version of the locked token. The user receives “wrapped ETH” or “bridged USDC” that represents a claim on the locked original.
To move back, the process reverses: the user burns the synthetic token on the destination chain, validators attest to the burn, and the original tokens are unlocked on the source chain.
The security of lock-and-mint depends entirely on the verification step. If an attacker can convince the destination chain that a deposit occurred when it did not, they can mint unbacked tokens. This is exactly what happened in the largest bridge exploits.
The arithmetic problem. Lock-and-mint bridges must maintain a 1:1 ratio between locked originals and minted synthetics. If 10,000 ETH is locked on Ethereum, exactly 10,000 bridged ETH should exist on the destination chain. Any discrepancy means some bridged tokens are unbacked. When exploits create unbacked synthetics, the last users to redeem find the vault empty. This creates a bank-run dynamic: once news of an exploit spreads, every holder of the wrapped token rushes to redeem, knowing that only the first to arrive will receive real assets.
Burn-and-mint: native cross-chain tokens
Burn-and-mint eliminates the wrapped token problem by destroying the original and creating a new one.
- Burn. The token is permanently destroyed on the source chain.
- Verify. The burn event is verified on the destination chain.
- Mint. New tokens are minted natively on the destination chain.
This model works only for tokens whose issuers control minting on multiple chains. Circle’s Cross-Chain Transfer Protocol (CCTP) for USDC is the largest implementation. When a user bridges USDC from Ethereum to Avalanche through CCTP, the Ethereum USDC is burned and native USDC is minted on Avalanche. There are no wrapped tokens, no liquidity fragmentation, and no unbacked synthetics.
The limitation is that burn-and-mint requires the token issuer to deploy and operate infrastructure on every supported chain. It is not a general-purpose mechanism. Arbitrary ERC-20 tokens cannot use burn-and-mint unless their developers build the cross-chain minting infrastructure. CCTP currently supports over a dozen chains, but each integration requires Circle’s direct involvement.
Liquidity pool bridges: speed through capital
A third model avoids both wrapping and burning by using pre-funded liquidity pools on each chain.
The mechanism:
- Deposit. The user deposits tokens into a pool on the source chain.
- Withdrawal. The user (or a relayer acting on their behalf) withdraws equivalent tokens from a pool on the destination chain.
- Rebalancing. The protocol periodically rebalances pools across chains to maintain adequate liquidity.
Stargate (built on LayerZero) and Across Protocol use variations of this model. The advantage is speed: because tokens already exist on the destination chain, there is no minting delay. The user receives real, native tokens immediately.
The tradeoff is capital efficiency. Liquidity must be pre-positioned on every supported chain, and that capital earns a return only when bridges are actively used. During low-volume periods, liquidity providers earn little while their capital sits idle. The aggregate capital requirements across all supported chains can reach hundreds of millions of dollars, creating a barrier to entry and a concentration risk if a single liquidity provider dominates.
The Ronin bridge hack: $624 million from compromised keys
On March 23, 2022, attackers drained $624 million in ETH and USDC from the Ronin bridge, which connected Ethereum to the Ronin sidechain used by the game Axie Infinity.
Ronin’s bridge used a multisig validation scheme. Nine validator nodes verified bridge transactions, and any five could authorize a withdrawal. The security assumption was that compromising five of nine independent validators would be impractical.
The assumption was wrong. Sky Mavis, the company behind Axie Infinity, controlled four of the nine validator nodes. A fifth validator had granted Sky Mavis temporary permission to sign on its behalf during a period of high transaction volume and never revoked the permission.
The attackers (later attributed to North Korea’s Lazarus Group by the FBI) compromised Sky Mavis’s systems and obtained the private keys for all five validators. With five of nine signatures, they authorized two fraudulent withdrawals: 173,600 ETH and 25.5 million USDC.
The exploit was not discovered for six days. It came to light only when a user tried to withdraw 5,000 ETH and found the bridge did not have enough funds.
The lesson. Multisig security is only as strong as the independence of its signers. When a single organization controls a majority of keys, the multisig is a single point of failure with extra steps.
The Wormhole hack: $326 million from a verification bypass
On February 2, 2022, an attacker exploited the Wormhole bridge to mint 120,000 wETH (wrapped ETH) on Solana without depositing any ETH on Ethereum. The exploit was worth approximately $326 million.
Wormhole’s bridge relied on a set of 19 guardians to verify cross-chain messages. The guardians would observe a deposit on Ethereum, produce a signed attestation (called a VAA, Verified Action Approval), and the Solana-side contract would verify the signatures before minting.
The vulnerability was in the Solana-side signature verification. Wormhole’s Solana contract used a deprecated system instruction (verify_signatures) that did not properly validate the accounts passed to it. The attacker crafted a fake guardian set, submitted a forged VAA with signatures from that fake set, and the contract accepted it as valid.
In effect, the attacker told the Solana contract “these guardians approved this mint” and the contract did not check whether the guardians were real.
Jump Crypto, which backed Wormhole, replaced the stolen 120,000 ETH from its own reserves. The full restoration happened within 24 hours, an unprecedented response that prevented cascading losses across Solana DeFi protocols that held wETH.
The lesson. Bridge verification code is high-value attack surface. A single logic error in how signatures are validated can allow unlimited unauthorized minting.
The Nomad hack: $190 million from a faulty update
On August 1, 2022, the Nomad bridge was drained of approximately $190 million. Unlike Ronin and Wormhole, Nomad was not attacked by a sophisticated group. It was drained by hundreds of individual copycats after the initial exploit became public.
Nomad used an optimistic verification model. Cross-chain messages were submitted and assumed valid unless challenged within a 30-minute window. A routine contract upgrade introduced a bug: the contract was initialized with a trusted root of 0x00, the zero bytes32 value.
In Nomad’s verification logic, every message was checked against the trusted root. Because 0x00 is the default value for uninitialized storage in Solidity, every message automatically passed verification. Any user could submit any message and the contract would accept it as proven.
Once the first attacker demonstrated that arbitrary messages were accepted, others copied the transaction, changed the recipient address, and replayed it. The bridge was drained by a swarm of opportunistic attackers, including white-hat hackers who later returned approximately $36 million in recovered funds.
The lesson. Initialization bugs in bridge contracts can be catastrophic. A single misconfigured parameter turned Nomad’s security model from “optimistic verification with fraud proofs” to “no verification at all.”
The Harmony Horizon hack: $100 million from a two-of-five multisig
In June 2022, the Harmony Horizon bridge lost $100 million when attackers compromised the private keys of two out of five validators in the bridge’s multisig. Harmony’s bridge required only two of five signers to approve a transaction, an unusually low threshold for a bridge holding $100 million.
The attack reinforced the Ronin lesson: multisig bridges are only as secure as their weakest signer set. When the threshold is low relative to the number of signers, a single infrastructure compromise can be sufficient. Security researchers had publicly criticized Harmony’s two-of-five threshold before the attack occurred.
The lesson. Threshold selection matters as much as validator count. A five-of-nine multisig offers meaningfully different security than a two-of-five multisig, even though both use the same underlying mechanism.
Cumulative losses and attack patterns
The scale of bridge losses is without precedent in smart contract security. Bridge exploits represent roughly $3 billion of the $17 billion in total crypto hacks over the past decade, making bridges the single most attacked category of smart contracts.
The attack patterns cluster into three categories:
Key compromise. The attacker obtains enough validator or signer keys to forge bridge messages. Ronin and Harmony followed this pattern. The vulnerability is not in the code but in the operational security of the signer infrastructure.
Verification bypass. The attacker finds a bug in the verification logic that allows forged messages to pass. Wormhole followed this pattern. The vulnerability is a code-level error in the most critical function of the bridge contract.
Initialization or upgrade errors. The attacker exploits a misconfiguration introduced during deployment or upgrade. Nomad followed this pattern. The vulnerability is procedural: the team made an error during a routine operation.
Each pattern requires a different defense. Key compromise is mitigated by increasing signer diversity and using hardware security modules. Verification bypass is mitigated by auditing and formal verification. Initialization errors are mitigated by upgrade procedures that include mandatory test runs on forked networks.
A fourth emerging pattern deserves mention: governance attacks. An attacker who accumulates enough governance tokens to control a bridge’s upgrade mechanism can modify the bridge contract to drain funds. This attack is slower and more visible than the others, but it targets bridges whose governance is concentrated or whose time-lock on upgrades is too short. Bridge teams increasingly use multi-day time-locks (48 to 72 hours) on contract upgrades to give users time to withdraw before a malicious change takes effect.
The intent-based alternative to traditional bridges
A newer approach sidesteps bridge contracts entirely by using intent-based cross-chain transfers. Across Protocol and UniswapX’s cross-chain mode let users express a bridging intent: “I have 1,000 USDC on Ethereum and want 1,000 USDC on Arbitrum.” A solver (called a relayer) immediately sends tokens from their own inventory on the destination chain, then later claims reimbursement.
This model reduces the trust surface. The user never deposits tokens into a bridge contract that holds pooled funds. The solver takes on the reimbursement risk, and the settlement contract enforces that the user received the promised output. There is no large pool of locked assets for an attacker to target.
The tradeoff is solver dependency: if no solver is willing to fill the intent at an acceptable price, the transfer does not execute. For high-traffic routes (Ethereum to Arbitrum, Ethereum to Base), solver competition is strong. For low-volume routes, solvers may not be active.
Light client bridges and zero-knowledge verification
The exploits above share a common weakness: they rely on external validators or multisigs to attest that something happened on another chain. If those attestors are compromised, the bridge fails.
Light client bridges take a different approach. Instead of trusting a validator set, the destination chain runs a light client that verifies the source chain’s consensus directly.
A light client bridge to Ethereum, for example, would track Ethereum’s validator set and verify block headers and state proofs on-chain. When a user claims to have deposited tokens on Ethereum, the bridge contract verifies the Merkle proof against the Ethereum block header it has already validated.
This approach is trust-minimized: the bridge trusts the source chain’s consensus, not an external committee. But it is expensive. Verifying Ethereum’s consensus on another chain requires significant computation, which translates to high gas costs.
Zero-knowledge proofs offer a solution to the cost problem. Instead of verifying every validator signature on-chain, a ZK proof can compress the verification into a single succinct proof. The destination chain verifies one proof instead of hundreds of signatures.
Projects like Succinct Labs, Polymer, and Lagrange are building ZK-verified bridges. These are still maturing, but they represent the strongest security model for cross-chain communication: trust the math, not the committee. Early implementations show verification costs dropping as ZK proving systems become more efficient, with some bridges already operating on mainnet with proving times under 30 seconds.
What this does not cover
This guide explains bridge mechanics and the largest exploits. It does not cover:
- Token-specific bridging strategies or which bridge to use for a given asset
- Detailed comparison of bridge aggregators (Li.Fi, Socket, Bungee)
- The economics of liquidity provision for bridge pools
- Cross-chain messaging protocols beyond their bridging function (LayerZero, Axelar, Chainlink CCIP as general messaging layers)
Practical checks before using a bridge
Check the verification mechanism. Multisig bridges are the weakest model. Light client and ZK-verified bridges are the strongest. Optimistic bridges fall in between. Know what you are trusting.
Look at the validator or guardian set. For multisig bridges, check how many signers exist, who operates them, and whether they are genuinely independent. If the majority of signers belong to the same organization or geographic jurisdiction, the multisig provides limited security.
Review audit history. Bridge contracts are high-value targets. Look for multiple independent audits from reputable firms. A bridge that has not been audited, or has been audited only once, warrants extra caution. Pay attention to the scope of audits: an audit of the token contract does not cover the verification logic.
Consider total value locked versus security budget. A bridge holding $500 million with a five-of-nine multisig presents a very different risk profile than a bridge holding $5 million. Attackers target bridges where the potential payout justifies the effort. The rational attacker calculates whether the cost of compromising enough keys is less than the value that can be extracted.
Test with small amounts first. Before bridging significant value, send a small test transaction. Verify that the receiving address, token, and amount are correct. Bridge transactions are typically irreversible.
Prefer native bridges for rollups. For Ethereum L2 rollups (Arbitrum, Optimism, Base), the canonical bridge inherits security directly from Ethereum’s consensus. Third-party bridges may be faster but introduce additional trust assumptions. Use canonical bridges for large transfers where security matters more than speed.
What is a cross-chain bridge?
A cross-chain bridge is a system that transfers assets or data between two blockchains that cannot natively communicate. The bridge locks, burns, or pools tokens on one chain and issues corresponding tokens on another, using a verification mechanism to ensure the transfer is legitimate.
Why have bridges been hacked so often?
Bridges are high-value targets because they hold large pools of locked assets. They also introduce complex trust assumptions at the boundary between two different security models. A vulnerability in the verification mechanism (compromised keys, faulty signature checks, initialization bugs) can allow an attacker to drain the entire pool in a single transaction.
What is the difference between lock-and-mint and burn-and-mint?
Lock-and-mint holds the original token on the source chain and mints a synthetic (wrapped) version on the destination chain. Burn-and-mint destroys the original and mints a new native token on the destination. Burn-and-mint produces native tokens rather than synthetics but requires the token issuer to control minting on both chains.
Are wrapped tokens safe?
Wrapped tokens are only as safe as the bridge that issued them. If the bridge is exploited and the backing assets are drained, the wrapped tokens become unbacked and lose their peg. Users holding wrapped tokens bear the bridge’s security risk, not just the underlying asset’s risk.
How long does bridging take?
It varies by mechanism. Liquidity pool bridges and intent-based bridges (Across) can complete in seconds. Lock-and-mint bridges with multisig verification typically take 10 to 30 minutes. Optimistic bridges with fraud proof windows can take 7 days for withdrawals from optimistic rollups to Ethereum, though fast bridges can front the liquidity to reduce this.
What is a light client bridge?
A light client bridge verifies the source chain’s consensus directly on the destination chain, rather than relying on an external validator set. It checks block headers and state proofs, trusting the source chain’s own security. This is more trust-minimized than multisig or optimistic verification but costs more gas to operate.
Can I lose money using a bridge?
Yes. If the bridge is exploited after you have deposited but before you have withdrawn, your locked tokens may be stolen. If you hold wrapped tokens and the bridge is hacked, your wrapped tokens may become worthless. Additionally, incorrect destination addresses or unsupported token types can result in permanent loss.
Which bridge should I use?
No single bridge is best for all situations. For USDC, Circle’s CCTP is the most secure option because it uses burn-and-mint with no wrapped tokens. For general ERC-20 transfers, compare the verification mechanisms of available bridges. Prefer bridges with light client or ZK verification, multiple independent audits, and a track record of secure operation. Bridge aggregators like Li.Fi can help compare routes.
*Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency involves significant risk, and you should conduct your own research before making any decisions. Information is accurate as of August 2026.*
-
Business5 days agoWhy Trees Belong on the Risk Register
-
Fashion3 days agoWeekend Open Thread: Wit & Wisdom
-
Politics3 days agoMeta enters AI-training agreement with far-right ‘propaganda rag’ Newsmax
-
Entertainment6 days ago‘Stargate’ Creator’s New Sci-Fi Series Returns for Season 3 Tomorrow
-
Crypto World2 days agoMicroStrategy Post-Earnings CLARITY Act Push Could Add New Catalyst for Its Stock
-
Politics7 days agoThe Part of the Electric Transition Nobody Wants to Discuss
-
Business6 days agoMajor shareholder moves on Canyon
-
Crypto World3 days agoXRP Ledger v3.3.0 brings five institutional features
-
News Videos5 days agoBitcoin Enters the 3rd Stage of the Bear Market
-
Crypto World6 days agoKraken Enables Retail Access to Jersey Mike’s IPO via Tokenized Shares
-
Politics4 days agoLuke Littler’s dominance sparks GOAT debate
-
News Videos6 days agoClaude: Build Financial Dashboards in Minutes (2026)
-
Politics5 days agoReform UK betrays West Mids residents by running from party pledges
-
Sports4 days agoSeema Kaliramna Wins Discus Throw Bronze, Takes India’s CWG Medals Tally To 17
-
Business6 days agoJohnson & Johnson agrees to $5.5B settlement over talc cancer claims
-
Crypto World2 days agoCrypto PAC spending tops $2M in Michigan House race
-
Crypto World3 days agoNew York sues Kalshi over prediction market gambling
-
Business3 days agoTrump Announces Hamas Disarmament Agreement as Iran Strikes Kuwait Air Base and US Attacks Pause Overnight
-
Tech6 days agoGemini can now summarize the messiest comment threads in Google Docs
-
Tech2 days agoESET tracks rise in malicious AI skills and adaptable malware

You must be logged in to post a comment Login