Transparent, non-custodial, yours

Bridges are where the money and the complexity meet

Bridges concentrate value behind complex verification logic. The recurring failure patterns, and how to limit exposure when you must use one.

Pattern one Compromise of an external validator or signer set
Pattern two A flaw in proof or message verification logic
Pattern three Admin or upgrade keys without a timelock

FBT Swap

What you should know

Several of the largest single losses in crypto have been bridge exploits. This is not bad luck — it follows from what a bridge is: a large pool of locked value guarded by code that must verify events on a chain it cannot execute.

The failure patterns repeat, which makes them worth knowing before you choose a route.

Compromised validator sets

Many bridges rely on a set of external signers to attest that a deposit occurred. Compromise enough of those keys and you can authorise withdrawals that never had a matching deposit.

Small signer sets, keys held by one organisation, and no timelock on withdrawals turn a key compromise into an immediate total loss.

Verification bugs

The proof-checking logic is intricate and has repeatedly contained flaws: accepting a forged Merkle proof, mishandling an empty input, or failing to check that a message came from the expected contract. One accepted fake message can mint unlimited tokens.

These are the most costly bugs in the space because the contract holds everything at once.

Upgrade and admin keys

A bridge that can be upgraded by a single key can be drained by whoever holds it, whether through theft or decision. Timelocks and multisigs reduce this; their absence is a standing risk regardless of the code quality.

This applies to the token contracts the bridge issues as well as to the bridge itself.

Limiting your exposure

Do not treat a bridge as storage. Move, then move on. Prefer canonical routes operated by the destination chain over third-party bridges where both exist. Split large transfers rather than sending one large amount through one contract.

FBT Swap routes swaps on each supported network; cross-chain movement remains a separate action with its own risk profile, and it is worth evaluating the specific bridge each time.

At a glance

At a glance

Pattern one

Compromise of an external validator or signer set

Pattern two

A flaw in proof or message verification logic

Pattern three

Admin or upgrade keys without a timelock

Mitigation

Canonical routes, short exposure, split large transfers

FAQ

Frequently asked questions

Clear answers before you decide.

Are canonical bridges always safer?

They are usually operated by the destination chain's own team and use its native messaging, which removes one external trust layer. They still have upgrade keys and code risk, so safer is relative rather than absolute.

Is bridging a stablecoin safer than bridging a volatile token?

The bridge risk is identical. What differs is what you hold afterwards: a bridged stablecoin can trade below the native version if confidence in the bridge drops, which is a second exposure.

Should I avoid bridges entirely?

That is impractical in a multi-chain world. The realistic goal is minimising time and amount at risk, choosing better-governed routes, and not leaving funds sitting in a bridged representation longer than necessary.

Risk notice

Crypto assets are volatile and on-chain transactions cannot be reversed. You can lose money, including all of it. Nothing here is financial advice.