The threshold was the vulnerability
Horizon required two signatures out of five. That is a very low bar for a bridge holding roughly $100m: an attacker needs to compromise two key-holders, not a majority. There is no exploit code to analyse here, because none was needed.
Compare with Ronin
The Ronin compromise three months earlier had a nominally stronger five-of-nine threshold that was effectively one organisation. Harmony’s was honestly two-of-five. Both failed the same way: the number of signatures required was smaller than it appeared, or simply too small.
When assessing a bridge, the threshold is public information. So is whether the signers are genuinely independent. Those two facts tell you more than any audit badge.
Timeline
Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.
- Harmony confirms the Horizon bridge has been exploited and identifies the affected addresses. Harmony
What to check
Harmony published incident statements and recovery proposals on its own channels; those are the authoritative record.
Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.
Sources
- Harmony, Horizon bridge incident statements (23 Jun 2022)
Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.
Last verified by Conisec Staff.