Commons Bridge 2026 proxy compromise
The Commons Bridge proxy on Base was compromised and approximately 18.45 million SYND were drained or controlled through the affected path. Public reporting placed realized sale proceeds around USD 330,000–400,000. Commons was later wound down and all users were automatically reimbursed with their SYND plus an additional 15 percent.
Incident facts
- Incident title
- Commons Bridge 2026 proxy compromise
- Bridge
- Commons Bridge
- Incident date
- 2026-04-29
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Base, Commons Chain, Ethereum
- Affected assets
- SYND
- Attack category
- Unknown
- Reported loss
- Approximately USD 330,000–400,000 realized proceeds
- Amount confidence
- Medium
- Loss amount basis
- Mixed Sources
- Recovery
- None
- Reimbursement
- Completed
- Restart
- Not Reopened
- Current outcome
- Dead After Incident
- Postmortem
- Unclear
- Resolution
- Final outcome known
- Last reviewed
- 2026-07-28
- Last verified
- 2026-07-28
Amount and valuation
Approximately 18.45 million SYND were reported drained or controlled through the compromised bridge proxy and sold for roughly USD 330,000–400,000.
Token quantity, realized attacker proceeds, user loss, market-price impact, and treasury-funded reimbursement measure different scopes and remain separate.
approximately 18.45 million SYNDapproximately USD 330,000–400,000 realized proceeds
Retained as a range rather than one exact USD amount.
Timeline events
Commons Bridge proxy compromised2026-04-29
The Commons Bridge proxy on Base was compromised, enabling unauthorized control or removal of approximately 18.45 million SYND.
Syndicate disclosed Commons Bridge compromise2026-04-29
Syndicate disclosed the bridge compromise, began tracing the attacker, and advised users not to provide liquidity during response.
Commons Bridge operations paused2026-04-29
Commons Bridge operation and related liquidity activity were paused during containment and investigation.
Syndicate began tracing and security investigation2026-04-29
Syndicate engaged security firms and began tracing attacker activity while assessing reserves and affected users.
Syndicate committed reserves for affected users2026-04-29
Syndicate stated that sufficient SYND reserves were available to help affected users while the incident response continued.
Commons users automatically reimbursed2026-05-21
The official shutdown page states that every SYND balance on Commons, including staked SYND and unclaimed rewards, was returned to the corresponding Base wallet plus an additional 15 percent.
Commons network and bridge wind-down announced2026-05-21
Syndicate announced the Commons wind-down alongside the Labs lifecycle update and reimbursement outcome.
The operator stated that the bridge compromise did not cause the separate Labs wind-down decision.
Commons Bridge permanently shut down2026-05-21
The official Commons page states that Commons has shut down and no user claim action is required.
Evidence records
- Syndicate Commons Bridge compromise statementSyndicate · Tier 1 · High reliability · primary · 2026-04-29Claim scope: Incident Case
Primary compromise, response, liquidity warning, and reserve-availability statement.
- Syndicate Labs wind-down and Commons reimbursement threadSyndicate · Tier 1 · High reliability · primary · 2026-05-21Claim scope: Shutdown
Primary source separating Labs wind-down cause from the compromise and reporting users made whole.
- Commons has shut downSyndicate · Tier 1 · High reliability · primary · 2026-05-21Claim scope: Reimbursement
Current official terminal page: all SYND returned automatically to Base wallets plus 15 percent; no user action required.
- Syndicate exploit linked to Commons Bridge compromiseThe Block · Tier 2 · High reliability · secondary · 2026-04-30Claim scope: Amount
Independent amount and attacker-sale context.
- Syndicate Commons Bridge Upgrade CompromiseDARKNAVY · Tier 2 · High reliability · secondary · 2026Claim scope: Incident Case
Technical privileged-upgrade-path interpretation retained as analysis rather than final primary-source root cause.
- Syndicate Labs to wind down operationsThe Block · Tier 2 · High reliability · secondary · 2026-05-21Claim scope: Shutdown
Independent operator-lifecycle and make-whole context.
- Syndicate Commons Bridge compromise statementSyndicate · Tier 1 · High reliability · primary · 2026-04-29Claim scope: Shutdown
Event-scoped duplicate supporting the Commons Bridge and liquidity pause during containment.
- Syndicate Commons Bridge compromise statementSyndicate · Tier 1 · High reliability · primary · 2026-04-29Claim scope: Reimbursement
Event-scoped duplicate supporting committed SYND reserves for affected users.
- Commons has shut downSyndicate · Tier 1 · High reliability · primary · 2026-05-21Claim scope: Reimbursement
Event-scoped duplicate supporting automatic reimbursement to Base wallets plus 15 percent.
- Syndicate Commons Bridge compromise statementSyndicate · Tier 1 · High reliability · primary · 2026-04-29Claim scope: Incident Case
Event-scoped primary copy supporting the Commons Bridge proxy compromise, approximate token amount, containment response, and pause.
- Syndicate Commons Bridge compromise statementSyndicate · Tier 1 · High reliability · primary · 2026-04-29Claim scope: Incident Case
Event-scoped primary copy supporting Syndicate's investigation, attacker tracing, liquidity warning, and reserve assessment.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- A first-party final technical postmortem was not located.
- Independent analysis attributes the incident to a privileged proxy-upgrade compromise, but BIR does not promote that narrow category as final without primary confirmation.
- The exact direct user-loss amount before treasury reimbursement is not separately established.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.