Skip to content
Incident record

Wormhole Signature Verification Exploit, February 2022: What Happened & What to Check

A flaw in Wormhole's Solana signature verification let an attacker mint 120,000 wETH without depositing collateral. Jump Crypto replaced the shortfall.

Resolved Discovered Disclosed
Share X in @
Schematic of the Wormhole incident showing the bridge exploit stage as the failure point.
Schematic of the Wormhole incident showing the bridge exploit stage as the failure point.

At a glance

AFFECTED ENTITY
Wormhole
CHAIN(S)
Ethereum, Solana
REPORTED LOSS
120,000 wETH(Wormhole, 3 Feb 2022)
OFFICIAL RESPONSE
wormholecrypto.medium.com

Verifying that verification happened

Wormhole’s security model rests on a guardian set whose signatures attest that a deposit occurred on the source chain. The Solana-side contract was responsible for checking those signatures before minting wrapped assets. The flaw allowed that check to be satisfied without genuine guardian approval — so the contract minted 120,000 wETH against a deposit that had never been made.

Collateralisation is a claim until you check it

The practical exposure for a user was subtle. Wrapped assets on Solana continued to function normally; nothing visibly broke for a holder. What had changed was that the wrapped supply exceeded the collateral backing it. Had the shortfall not been covered, the peg would have been the thing that failed, and holders would have discovered the problem at the moment they tried to redeem.

This is the honest lesson of the incident, and it is uncomfortable: solvency was restored by a sponsor’s balance sheet. Wrapped-asset holders were made whole by a discretionary act. When evaluating any wrapped or bridged asset, the question is what happens if the backer declines — because that is the scenario the wrapper is supposed to survive on its own.

Timeline

Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.

  1. The exploit is executed and detected; Wormhole takes the bridge down and publicly confirms the incident. Wormhole
  2. Wormhole publishes its incident report; the 120,000 ETH shortfall is replaced and the bridge is restored. Wormhole

What to check

Wormhole published a written incident report, linked below, with the technical detail of the verification flaw and the remediation.

Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.

Sources

  1. Wormhole, Wormhole Incident Report — 02/02/22 (3 Feb 2022)

Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.

Last verified by Conisec Staff.