BXH Cross-chain Bridge 2022 security incident
BXH states that its DeFi platform was hacked on September 21, 2022. Its later compensation notice explicitly includes users whose assets were lost in the cross-chain bridge, while keeping those losses distinct from LP positions and from a separate September 27 flash-loan attack.
Incident facts
- Incident title
- BXH Cross-chain Bridge 2022 security incident
- Bridge
- BXH Cross-chain Bridge
- Incident date
- 2022-09-21
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Avalanche, Unknown
- Affected assets
- Unknown
- Attack category
- Private Key Compromise
- Reported loss
- No reviewed first-party source supports one bridge-only USD loss total.
- Amount confidence
- High
- Loss amount basis
- First Party Compensation Material; Bridge Only Amount Intentionally Unresolved
- Recovery
- None Confirmed
- Reimbursement
- Announced
- Restart
- Not Reopened
- Current outcome
- Limited After Incident
- Postmortem
- Partial
- Resolution
- Unresolved
- Last reviewed
- 2026-08-27
- Last verified
- 2026-08-27
Amount and valuation
No reviewed first-party source supports one bridge-only USD loss total.
Mixed DeFi loss figures are not assigned to the bridge record.
Why this remains unresolved
- Final bridge-user compensation completion is not established by the reviewed evidence.
- A bridge-only loss total is not established.
Timeline events
BXH September 2022 security incident affects bridge positions2022-09-21
BXH later identified the September 21 hack and explicitly included users with assets lost in cross-chain bridge positions in its compensation program.
Separate September 27 flash-loan losses are not merged into this bridge incident.
Evidence records
- BXH latest announcement on compensation programBXH · Tier 1 · High reliability · primary · 2022-09-30Claim scope: Incident Case
First-party BXH notice stating the DeFi platform was hacked on September 21, announcing DeFi exit, and explicitly including cross-chain bridge losses in the compensation program.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- Bridge-only stolen-value total is not established.
- Final compensation completion for cross-chain bridge positions is not established.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.