Incident case

BXH Cross-chain Bridge 2022 security incident

BXH states that its DeFi platform was hacked on September 21, 2022. Its later compensation notice explicitly includes users whose assets were lost in the cross-chain bridge, while keeping those losses distinct from LP positions and from a separate September 27 flash-loan attack.

reviewedcurrent

Incident facts

Incident title
BXH Cross-chain Bridge 2022 security incident
Bridge
BXH Cross-chain Bridge
Incident date
2022-09-21
Incident type
Exploit
Major incident
Yes
Affected chains
Avalanche, Unknown
Affected assets
Unknown
Attack category
Private Key Compromise
Reported loss
No reviewed first-party source supports one bridge-only USD loss total.
Amount confidence
High
Loss amount basis
First Party Compensation Material; Bridge Only Amount Intentionally Unresolved
Recovery
None Confirmed
Reimbursement
Announced
Restart
Not Reopened
Current outcome
Limited After Incident
Postmortem
Partial
Resolution
Unresolved
Last reviewed
2026-08-27
Last verified
2026-08-27

Amount and valuation

No reviewed first-party source supports one bridge-only USD loss total.

Mixed DeFi loss figures are not assigned to the bridge record.

Why this remains unresolved

Timeline events

  • BXH September 2022 security incident affects bridge positions2022-09-21

    BXH later identified the September 21 hack and explicitly included users with assets lost in cross-chain bridge positions in its compensation program.

    Exploit DisclosedHigh

    Separate September 27 flash-loan losses are not merged into this bridge incident.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.