ChainSwap July 10–11, 2021 quota exploit
A logic flaw in ChainSwap's cross-chain quota code allowed non-whitelisted addresses to increase bridge quota and affect 20 bridged assets. ChainSwap reported a combined value of approximately $4 million and took the bridge offline.
Incident facts
- Incident title
- ChainSwap July 10–11, 2021 quota exploit
- Bridge
- ChainSwap
- Incident date
- 2021-07-10
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ethereum, BNB Chain, Unknown
- Affected assets
- Unknown
- Attack category
- Smart Contract Bug
- Reported loss
- Approximately $4 million
- Amount confidence
- High
- Loss amount basis
- Official ChainSwap Post Mortem
- Recovery
- None
- Reimbursement
- In Progress
- Restart
- Reopened
- Current outcome
- Active After Incident
- Postmortem
- Full
- Resolution
- Unresolved
- Last reviewed
- 2026-06-15
- Last verified
- 2026-06-15
Amount and valuation
ChainSwap's post-mortem described 20 affected assets with a combined value of approximately $4 million.
The official post-mortem is used for the canonical total.
20 assets affectedapproximately $4 million
Canonical incident estimate.
Why this remains unresolved
- The team described compensation as mostly finished, but final completion for all affected projects and holders is not established.
Timeline events
Second July exploit affected 20 bridged assets2021-07-10
A quota-logic flaw was exploited across 20 bridged assets, after which ChainSwap took the bridge offline and froze mapping tokens.
Official materials describe the incident across July 10–11 UTC.
ASAP token replacement and compensation plan documented2021-07-13
ChainSwap described issuing a replacement token, using a pre-exploit snapshot, and compensating affected projects and holders after the second exploit.
The event records the announced mechanism, not final completion.
ChainSwap bridge relaunched2021-08-20
ChainSwap announced that the bridge was live again after the July incidents and remediation work.
Event type normalized from legacy descriptive value bridge_relaunched.
Evidence records
- ChainSwap Exploit 11 July 2021 Post-MortemChainSwap · Tier 1 · High reliability · primary · 2021-07-12Claim scope: Incident Case
Primary technical and compensation account for the second July exploit.
- ASAP token important updateChainSwap · Tier 1 · High reliability · primary · 2021-07-13Claim scope: Reimbursement
Primary source for the ASAP replacement-token and airdrop mechanism.
- ChainSwap re-launch, we are liveChainSwap · Tier 1 · High reliability · primary · 2021-08-20Claim scope: Restart
Primary relaunch announcement.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The incident crossed July 10–11 UTC in official descriptions.
- Final compensation completion requires later review.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.