{"id":55569,"date":"2022-01-09T13:12:31","date_gmt":"2022-01-09T11:12:31","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=55569"},"modified":"2025-09-04T02:13:18","modified_gmt":"2025-09-03T23:13:18","slug":"vitalik-buterin-says-cross-chain-bridges-are-vulnerable-to-51-attacks","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/vitalik-buterin-says-cross-chain-bridges-are-vulnerable-to-51-attacks\/","title":{"rendered":"Vitalik Buterin says cross-chain bridges are vulnerable to 51% attacks"},"content":{"rendered":"<p>Ethereum founder Vitalik Buterin said he supports the concept of a multi-chain ecosystem, but is &#8216;pessimistic&#8217; about <a href=\"https:\/\/forklog.com\/en\/news\/what-are-cross-chain-bridges\">cross-chain bridges<\/a>. He says the latter are vulnerable to <a href=\"https:\/\/forklog.com\/en\/news\/what-is-a-51-attack\">51% attacks<\/a>.<\/p>\n<blockquote class=\\\"twitter-tweet\\\">\n<p lang=\\\"en\\\" dir=\\\"ltr\\\">My argument for why the future will be *multi-chain*, but it will not be *cross-chain*: there are fundamental limits to the security of bridges that hop across multiple \\&#8221;zones of sovereignty\\&#8221;. From <a href=\\\"https:\/\/t.co\/3g1GUvuA3A\\\">https:\/\/t.co\/3g1GUvuA3A<\/a>: <a href=\\\"https:\/\/t.co\/tEYz8vb59b\\\">pic.twitter.com\/tEYz8vb59b<\/a><\/p>\n<p>\u2014 vitalik.eth (@VitalikButerin) <a href=\\\"https:\/\/twitter.com\/VitalikButerin\/status\/1479501366192132099?ref_src=twsrc%5Etfw\\\">January 7, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\\\"https:\/\/platform.twitter.com\/widgets.js\\\" charset=\\\"utf-8\\\"><\/script><\/p>\n<blockquote class=\\\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\\\">\n<p>\u00abThe fundamental security limitations of bridges are the main reason I remain optimistic about a multi-chain blockchain ecosystem (indeed, there are several separate communities with different values, and it\\&#8217;s better for them to exist separately than fight for influence), but I observe cross-chain applications with a degree of pessimism,&#8221; he wrote on Reddit.<\/p>\n<\/blockquote>\n<p>Buterin said that, compared with layer-1 networks, cross-chain bridges are more vulnerable to 51% attacks. He explained that even if an attacker manages to seize a majority of the network\\&#8217;s computing power, they would not be able to steal users\\&#8217; crypto, because that would &#8216;violate the protocol\\&#8217;s rules&#8217;.<\/p>\n<p>The Ethereum founder added that a 51% attack could subject a decentralized application to censorship or a temporary reversal, but the network would later return to a &#8216;consensus state&#8217;.<\/p>\n<blockquote class=\\\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\\\">\n<p>\u00abIf you had 100 ETH, but sold them for 320,000 DAI on Uniswap, even after a blockchain attack in some crazy way you would end up with a reasonable outcome \u2014 you would either keep your 100 ETH, or receive 320,000 DAI. An outcome in which you get neither (or, if you will, a third outcome) violates the protocol rules, and therefore will not be accepted\u00bb, \u2014 said Buterin.<\/p>\n<\/blockquote>\n<p>He stressed that cross-chain bridges do not offer such guarantees, and therefore users could lose funds. As an example, he cited a hypothetical Ethereum-Solana bridge scenario:<\/p>\n<ul class=\\\"wp-block-list\\\">\n<li>An attacker deposits a large amount of their own funds into wrapped ETH on Solana;<\/li>\n<li>attacks the Ethereum network and, after awaiting the transaction confirmation on the Solana side, reverses it;<\/li>\n<li>The Solana-WETH contract is no longer fully collateralized, causing the price of wrapped assets for other users to fall \u2014 effectively they lose money.<\/li>\n<\/ul>\n<blockquote class=\\\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\\\">\n<p>\u00abEven if there exists a perfect bridge based on <span data-descr=\\\"zero-knowledge proof\\\" class=\\\"old_tooltip\\\">ZK-SNARK<\/span>, which fully confirms consensus, it would still be vulnerable to theft via 51% attacks like this\u00bb, \u2014 said he.<\/p>\n<\/blockquote>\n<p>In Buterin\\&#8217;s view, connecting hundreds of blockchains via cross-chain bridges will lead to many interdependent decentralized applications. In such a setting a 51% attack on even a single network creates a &#8216;systemic infection&#8217; that threatens the economy of the entire ecosystem. <\/p>\n<blockquote class=\\\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\\\">\n<p>\u00abI do not expect these problems to appear immediately. Carrying out a 51% attack even on a single chain is difficult and expensive. However the more cross-chain bridges and applications are used, the higher the probability\u00bb, \u2014 he concluded.<\/p>\n<\/blockquote>\n<p>Frax Finance founder Sam Kazemian noted that there is a concept of an inter-network bridge capable of solving the problem highlighted by Buterin. It involves a system that checks the states of blockchains interacting with the bridge before confirming a transaction, and then passes this information to an anchor network, which could be Ethereum.<\/p>\n<p>Blockchain Foundry CTO Jag Sidhu noted that a similar idea is being pursued by cross-chain exchange zkLink.<\/p>\n<blockquote class=\\\"twitter-tweet\\\">\n<p lang=\\\"en\\\" dir=\\\"ltr\\\">Zklink tries to do this sam, so the rollups are seperate then an outer proof is aggregated on each rollup to create a final proof that is put into each contracts and an oracle system pushes the proof to each chain to ensure it\u2019s consistent. There are better ways but same idea<\/p>\n<p>\u2014 jagdeep sidhu (@realSidhuJag) <a href=\\\"https:\/\/twitter.com\/realSidhuJag\/status\/1479612192894840832?ref_src=twsrc%5Etfw\\\">January 8, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\\\"https:\/\/platform.twitter.com\/widgets.js\\\" charset=\\\"utf-8\\\"><\/script><\/p>\n<p>As noted in late 2021, Buterin described the role of ZK-Rollups in Ethereum scalability and proposed a method to lower transaction costs on L2.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ethereum founder Vitalik Buterin says he supports the concept of a multi-chain ecosystem, but is pessimistic about cross-chain bridges. He says they are vulnerable to 51% attacks.<\/p>\n","protected":false},"author":1,"featured_media":55570,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1210,200],"class_list":["post-55569","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cross-chain-protocols","tag-vitalik-buterin"],"aioseo_notices":[],"amp_enabled":true,"views":"58","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/55569","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=55569"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/55569\/revisions"}],"predecessor-version":[{"id":55571,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/55569\/revisions\/55571"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/55570"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=55569"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=55569"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=55569"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}