Incident case

ChainConnect 2026 Alien Proxy callback exploit

On July 26, 2026, missing sender verification in a ChainConnect Alien Proxy callback enabled unbacked Alien TIP-3 minting and bridging to Ethereum. ChainConnect paused and patched affected deployments. Venom later reported 82.9% (~USD 615,000) returned and 17.1% retained as a whitehat bounty; post-incident reopening remains unverified.

reviewedcurrent

Incident facts

Incident title
ChainConnect 2026 Alien Proxy callback exploit
Bridge
ChainConnect
Incident date
2026-07-26
Incident type
Exploit
Major incident
Yes
Affected chains
Venom, Ethereum
Affected assets
Unknown
Attack category
Smart Contract Bug
Reported loss
SlowMist reports an approximately USD 650,000 incident estimate. Venom separately reports ~USD 615,000 as the returned 82.9%; BIR does not treat either as an exact canonical gross loss because claim scope and valuation timing differ.
Amount confidence
Disputed
Loss amount basis
Reported By Security Firm
Recovery
Partial Recovery
Reimbursement
Unknown
Restart
Paused
Current outcome
Unknown
Postmortem
Available
Resolution
Unresolved
Last reviewed
2026-08-19
Last verified
2026-08-19

Amount and valuation

SlowMist reports an approximately USD 650,000 incident estimate. Venom separately reports ~USD 615,000 as the returned 82.9%; BIR does not treat either as an exact canonical gross loss because claim scope and valuation timing differ.

Keep the secondary approximately-USD-650k gross estimate separate from the first-party approximately-USD-615k returned valuation and 17.1% bounty. They are different claim scopes and are not arithmetically reconciled.

Why this remains unresolved

Timeline events

  • ChainConnect callback flaw exploited and bridge operations paused2026-07-26

    Venom and ChainConnect reported an application-level ChainConnect incident involving missing sender verification in an Alien Proxy callback. The incident enabled unauthorized unbacked token minting and movement through the standard bridge flow; ChainConnect paused bridge operations while investigating. BIR does not classify this as a Venom network, relay, validator-key, or privileged-key compromise.

    Exploit OccurredHigh

    Safe high-level description only; no exploit reproduction detail is included.

  • ChainConnect records partial fund return and whitehat bounty settlement2026-07-31

    ChainConnect-authored recovery messaging recorded a 280 ETH return transaction on July 31. Venom later summarized the recovery as 82.9% of affected funds, approximately USD 615,000, returned with 17.1% retained as a whitehat bounty. This is attacker-fund recovery and bounty evidence, not proof of completed user reimbursement or bridge reopening.

    Funds ReturnedHigh

    The return valuation, return ratio, bounty share, and 280 ETH transaction are retained as separate supported observations rather than collapsed into one inferred gross-loss calculation.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.