Research
Why Wrapped-Asset Bridges Concentrate Failure
July 15, 2026

The first article in this series described how the largest crypto losses keep coming from the messaging layer of bridges rather than from broken token code. This article asks a harder question. Are these failures bad luck that better engineering will eventually fix, or are they a property of the design itself? The answer matters because it determines whether the right response is a more careful bridge or a different architecture. The evidence points to the second. The dominant lock and mint model does not merely carry risk. It concentrates risk by construction, turning a single breach into simultaneous insolvency across every chain the asset touches.

The Lock and Mint Model in Plain Terms

Recall the basic mechanism. To move an asset from chain A to chain B, you lock the original in a contract on chain A, and the bridge mints a wrapped representation on chain B. The wrapped token is a claim. It says, in effect, there is one real unit locked on chain A that this token can be redeemed for. As long as that statement is true, the wrapped token can trade, settle, and serve as collateral on chain B as if it were the real thing.

The entire value of the wrapped token therefore rests on two conditions holding at all times. First, the collateral on chain A must remain locked and intact. Second, the bridge must only ever mint new wrapped tokens when a genuine deposit has occurred. Break either condition and the wrapped supply on chain B exceeds the collateral backing it. At that moment every holder of the wrapped token is holding a fractional claim on a vault that no longer covers it, and there is no orderly way to decide whose claim is good.

Inheriting the Wrong Security

Here is the structural problem stated plainly. A wrapped asset does not inherit the security of the chain it lives on. It inherits the security of the bridge that minted it. A wrapped bitcoin on a smart contract chain is not protected by Bitcoin's proof of work or by the destination chain's consensus. It is protected only by whatever process decides when to mint and burn it, which is the validator or verifier set of the bridge.

This is the gap that catches institutions used to thinking in terms of issuer risk and custody risk. With a wrapped asset there is a third layer underneath both: the bridge's trust assumption. You can hold a perfectly sound underlying asset issued by a reputable party and custodied correctly, and still lose everything if the bridge that wrapped it for use elsewhere is compromised. The Kelp DAO drain in April 2026, roughly $292 million released by a forged cross-chain message through a single verifier, was exactly this failure mode. The staked ether was real. The representation moving across chains was only as sound as one attestation.

One Breach, Every Chain

What makes the wrapped model concentrate rather than merely carry risk is reach. Bridges exist to put an asset everywhere at once. A single wrapped asset is frequently minted across many destination chains from one pool of locked collateral. In the Kelp DAO case, the affected wrapped ether was reported stranded across roughly 20 chains. When the backing is compromised, the loss does not stay on one chain. Every wrapped copy on every chain becomes an unbacked claim simultaneously, and any protocol that accepted those copies as collateral inherits the hole.

This is the opposite of how risk is supposed to behave in a resilient system. A well-designed financial system isolates failures so that a problem in one venue does not automatically become a problem everywhere. The lock and mint bridge does the reverse. It takes a single point of failure, the backing pool and the validators guarding it, and propagates its compromise outward to every market that trusted the wrapped representation. One forged message does not cause one loss. It causes as many losses as there are chains and protocols downstream.

A Category Property, Not an Accident

If this were occasional misfortune, the incidents would be scattered randomly across attack types. They are not. The Chainalysis review of 2022 found roughly $2 billion stolen across 13 separate cross-chain bridge hacks, about 69 percent of everything stolen in crypto that year. The largest individual events, Ronin at roughly $625 million, Wormhole at about $320 million, and Nomad at roughly $190 million, were all failures of the mint authorization or the validator set, not of the wrapped token's own code. Four years later, PeckShield counted roughly $328.6 million drained from cross-chain bridges across eight major incidents in 2026, with the Kelp DAO event leading. The same mechanism keeps producing the same outcome because the mechanism is the cause.

When a single design accounts for the majority of losses in a category year after year, the conclusion is not that the engineers were careless. Many of these were well-funded, audited, reputable systems. The conclusion is that concentrating the integrity of an asset into a small trusted attestation layer, and then replicating that asset across many chains, is an inherently fragile arrangement. The wrapped token's convenience and its fragility are the same property viewed from two angles.

The Alternative Worth Naming

The contrast that follows from all of this is between an asset that is a copy and an asset that is native. A wrapped token is a synthetic copy whose integrity depends on a bridge. A native asset exists directly on its settlement layer, where its supply and ownership are recorded at the base of the chain rather than as a representation backed elsewhere. On a chain whose base layer tracks ownership explicitly, the supply of an asset can be audited directly, and there is no separate backing pool that can be drained out from under the holders.

That distinction is the hinge of this series. If the largest losses come from synthetic copies held behind a trusted validator set, then the durable fix is not a stronger validator set. It is not minting the copy in the first place. For a speculative token chasing presence on every chain, the trade that the wrapped model offers, maximum reach in exchange for concentrated trust, can look worthwhile. For a regulated stablecoin, a tokenized fund interest, or any instrument whose entire premise is a trustworthy record of who owns what, it is the wrong trade, because the thing being put at risk is the record itself.

The final article in this series takes up that alternative directly: what native settlement means in practice, how value can move between chains without a wrapped copy, and where Bitcoin-native infrastructure fits for institutions that cannot afford to have one forged message unwind their holdings.

‍

This article is for informational purposes only and does not constitute investment advice.

‍

Mintlayer Web Services provides Bitcoin-native issuance and settlement infrastructure that keeps assets native rather than wrapped behind a bridge. Learn more →

Discover more

Mintlayer $ML Migration Update: Final Deadline Confirmed, New Bridge and ERC20 Coming Next
Development

Mintlayer $ML Migration Update: Final Deadline Confirmed, New Bridge and ERC20 Coming Next

The final deadline for migrating the original ERC20 $ML token is confirmed for 1 November 2026 and will not be extended. In parallel, a new permanent bridge and a new ERC20 representation of $ML are on the way.

September 21, 2026
Your Address Checks Itself
Research

Your Address Checks Itself

One typo in a bech32 address gets caught, located, and corrected before signing. On 0x chains, almost any lowercase string is a valid address. Security at Mintlayer starts at the format level.

September 14, 2026
An Append-Only Attestation Layer for AI Decisions
Research

An Append-Only Attestation Layer for AI Decisions

Proofs and attestations only become evidence when they live somewhere an auditor can find them, with a timestamp nobody disputes and no way for the operator to revise the collection. Bitcoin-anchored infrastructure provides exactly that.

September 4, 2026
Explore all