ChainConnect 2026 Alien Proxy callback exploit
On July 26, 2026, missing sender verification in a ChainConnect Alien Proxy callback enabled unbacked Alien TIP-3 minting and bridging to Ethereum. ChainConnect paused and patched affected deployments. Venom later reported 82.9% (~USD 615,000) returned and 17.1% retained as a whitehat bounty; post-incident reopening remains unverified.
Incident facts
- Incident title
- ChainConnect 2026 Alien Proxy callback exploit
- Bridge
- ChainConnect
- Incident date
- 2026-07-26
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Venom, Ethereum
- Affected assets
- Unknown
- Attack category
- Smart Contract Bug
- Reported loss
- SlowMist reports an approximately USD 650,000 incident estimate. Venom separately reports ~USD 615,000 as the returned 82.9%; BIR does not treat either as an exact canonical gross loss because claim scope and valuation timing differ.
- Amount confidence
- Disputed
- Loss amount basis
- Reported By Security Firm
- Recovery
- Partial Recovery
- Reimbursement
- Unknown
- Restart
- Paused
- Current outcome
- Unknown
- Postmortem
- Available
- Resolution
- Unresolved
- Last reviewed
- 2026-08-19
- Last verified
- 2026-08-19
Amount and valuation
SlowMist reports an approximately USD 650,000 incident estimate. Venom separately reports ~USD 615,000 as the returned 82.9%; BIR does not treat either as an exact canonical gross loss because claim scope and valuation timing differ.
Keep the secondary approximately-USD-650k gross estimate separate from the first-party approximately-USD-615k returned valuation and 17.1% bounty. They are different claim scopes and are not arithmetically reconciled.
approximately USD 650,000 incident estimateapproximately USD 650,000
Secondary security-database estimate retained as a claim, not promoted to reported_loss_usd.
Why this remains unresolved
- A single first-party gross USD loss figure has not been established.
- The approximately USD 650,000 secondary gross estimate and approximately USD 615,000 first-party returned valuation use different claim scopes and are not silently reconciled.
- Affected-user or bridge-liability reimbursement is not established by the reviewed return and bounty evidence.
- A dated post-incident bridge reopening or later terminal outcome has not been established.
Timeline events
ChainConnect callback flaw exploited and bridge operations paused2026-07-26
Venom and ChainConnect reported an application-level ChainConnect incident involving missing sender verification in an Alien Proxy callback. The incident enabled unauthorized unbacked token minting and movement through the standard bridge flow; ChainConnect paused bridge operations while investigating. BIR does not classify this as a Venom network, relay, validator-key, or privileged-key compromise.
Safe high-level description only; no exploit reproduction detail is included.
ChainConnect records partial fund return and whitehat bounty settlement2026-07-31
ChainConnect-authored recovery messaging recorded a 280 ETH return transaction on July 31. Venom later summarized the recovery as 82.9% of affected funds, approximately USD 615,000, returned with 17.1% retained as a whitehat bounty. This is attacker-fund recovery and bounty evidence, not proof of completed user reimbursement or bridge reopening.
The return valuation, return ratio, bounty share, and 280 ETH transaction are retained as separate supported observations rather than collapsed into one inferred gross-loss calculation.
Evidence records
- ChainConnect Security IncidentChainConnect · Tier 1 · High reliability · primary · 2026-07Claim scope: Incident Case
First-party ChainConnect incident notice supporting the EVM integration breach, bridge-contract liquidity drain, bridge pause, and statement that connected wallets/accounts were not compromised.
- ChainConnect security incident updateVenom Foundation · Tier 1 · High reliability · primary · 2026-07-28Claim scope: Incident Case
Affected-ecosystem first-party update supporting temporary suspension of ChainConnect bridge operations and separating the incident from compromise of the Venom network.
- Post-mortem: ChainConnect security incidentVenom Foundation · Tier 1 · High reliability · primary · 2026-08-01Claim scope: Recovery
First-party ecosystem post-mortem summary supporting the July 26 incident date, missing sender verification in the Alien Proxy callback, scope exclusions, patch, 82.9% (~USD 615k) return, and 17.1% bounty.
- ChainConnect incident post-mortemChainConnect · Tier 1 · High reliability · primary · 2026-08Claim scope: Event
Direct first-party ChainConnect post-mortem URL referenced by Venom. Publication precision remains conservative because the reviewed public rendering did not independently expose a stable exact day.
- ChainConnect recovery messages and return trackingDefimon · Tier 2 · High reliability · secondary · 2026-07-31Claim scope: Recovery
Independent on-chain monitoring preserving ChainConnect-authored whitehat negotiation and return messages, including identification of the July 31 return transaction.
- ChainConnect 280 ETH return transactionEtherscan · Tier 2 · High reliability · secondary · 2026-07-31Claim scope: Recovery
Transaction reference identified by ChainConnect-authored recovery messaging as the 280 ETH return. BIR does not infer a full gross-loss amount from this transaction.
- ChainConnect bridge incident entrySlowMist · Tier 2 · High reliability · secondary · 2026-07Claim scope: Amount
Secondary security-database entry supporting an approximately USD 650k incident estimate. The figure remains a claim and is not promoted to canonical reported_loss_usd because first-party recovery valuation uses a different scope.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The exact gross loss and valuation basis remain unresolved.
- The exact composition of drained EVM-side assets is not promoted from the reviewed evidence into a normalized asset list.
- The July 16 maintenance-complete statement predates the July 26 incident and is not post-incident reopen evidence.
- Final reimbursement and current incident-affected route status remain unverified.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.