Incident case

Dusk to EVM Bridge 2026 signing-wallet compromise

An unauthorized actor gained access to a Dusk signing wallet used by the bridge, stole DUSK directly on Dusk, and moved part of the stolen amount through the bridge to BNB Smart Chain. Dusk states this was a bridge-wallet compromise, not a Dusk consensus failure or protocol exploit.

reviewedcurrent

Incident facts

Incident title
Dusk to EVM Bridge 2026 signing-wallet compromise
Bridge
Dusk to EVM Bridge
Incident date
2026-01-16
Incident type
Exploit
Major incident
Yes
Affected chains
Unknown, BNB Chain
Affected assets
Unknown
Attack category
Validator Key Compromise
Reported loss
The reviewed first-party post-mortem enumerates stolen DUSK amounts but does not establish a canonical USD loss total.
Amount confidence
Unknown
Loss amount basis
Reported By Project
Recovery
Unknown
Reimbursement
Unknown
Restart
Unknown
Current outcome
Active After Incident
Postmortem
Available
Resolution
Unresolved
Last reviewed
2026-09-03
Last verified
2026-09-03

Amount and valuation

The reviewed first-party post-mortem enumerates stolen DUSK amounts but does not establish a canonical USD loss total.

BIR does not invent a USD valuation from the token quantities in the post-mortem.

Why this remains unresolved

Timeline events

  • Dusk bridge signing wallet compromised2026-01-16

    An unauthorized actor gained access to the Dusk bridge signing wallet and stole DUSK, with part of the stolen amount moved through the bridge to BNB Smart Chain.

    Exploit OccurredHigh

    First-party post-mortem explicitly excludes a Dusk consensus failure or protocol exploit.

  • Dusk bridge shut down during containment2026-01-16

    Dusk shut the bridge down at 23:12 UTC after an internal compromise report, causing a later 8.91 million DUSK bridge attempt to fail.

    Bridge PausedHigh

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.