Incident case

ChainSwap July 10–11, 2021 quota exploit

A logic flaw in ChainSwap's cross-chain quota code allowed non-whitelisted addresses to increase bridge quota and affect 20 bridged assets. ChainSwap reported a combined value of approximately $4 million and took the bridge offline.

reviewedcurrent

Incident facts

Incident title
ChainSwap July 10–11, 2021 quota exploit
Bridge
ChainSwap
Incident date
2021-07-10
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum, BNB Chain, Unknown
Affected assets
Unknown
Attack category
Smart Contract Bug
Reported loss
Approximately $4 million
Amount confidence
High
Loss amount basis
Official ChainSwap Post Mortem
Recovery
None
Reimbursement
In Progress
Restart
Reopened
Current outcome
Active After Incident
Postmortem
Full
Resolution
Unresolved
Last reviewed
2026-06-15
Last verified
2026-06-15

Amount and valuation

ChainSwap's post-mortem described 20 affected assets with a combined value of approximately $4 million.

The official post-mortem is used for the canonical total.

Why this remains unresolved

Timeline events

  • Second July exploit affected 20 bridged assets2021-07-10

    A quota-logic flaw was exploited across 20 bridged assets, after which ChainSwap took the bridge offline and froze mapping tokens.

    Second Exploit And Bridge ShutdownHigh

    Official materials describe the incident across July 10–11 UTC.

  • ASAP token replacement and compensation plan documented2021-07-13

    ChainSwap described issuing a replacement token, using a pre-exploit snapshot, and compensating affected projects and holders after the second exploit.

    Token Replacement And CompensationHigh

    The event records the announced mechanism, not final completion.

  • ChainSwap bridge relaunched2021-08-20

    ChainSwap announced that the bridge was live again after the July incidents and remediation work.

    Bridge ReopenedHigh

    Event type normalized from legacy descriptive value bridge_relaunched.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.