QBridge 2022 zero-value deposit exploit
In January 2022, a logic flaw in QBridge allowed an attacker to submit deposit calls without transferring ETH, mint unbacked xETH on BNB Chain, and use that collateral to withdraw roughly $80 million from Qubit markets.
Incident facts
- Incident title
- QBridge 2022 zero-value deposit exploit
- Bridge
- QBridge
- Incident date
- 2022-01-27
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ethereum, BNB Chain
- Affected assets
- BNB, WETH, WBTC, USDC, USDT
- Attack category
- Cross Chain Contract Exploit
- Reported loss
- $80 million stolen; $90.8 million later damage estimate
- Amount confidence
- High
- Loss amount basis
- Direct Stolen Asset Estimate Separated From Later Victim Damage Calculation
- Recovery
- Unknown
- Reimbursement
- In Progress
- Restart
- Not Reopened
- Current outcome
- Dead After Incident
- Postmortem
- Partial
- Resolution
- Unresolved
- Last reviewed
- 2026-06-14
- Last verified
- 2026-06-14
Amount and valuation
Security analysis described approximately $80 million in stolen assets, while Qubit later recalculated total affected-user damage at approximately $90.8 million.
The $80 million figure is the direct exploit-loss estimate. The $90.8 million figure is a later Qubit damage calculation and is retained as a distinct scope rather than replacing the stolen-asset estimate.
assets withdrawn after unbacked xETH mintingapproximately $80 million
Canonical display amount for the direct exploit loss.
updated amount of damage across affected usersapproximately $90.8 million
Later damage calculation; not treated as the direct stolen-asset amount.
Why this remains unresolved
- Complete recovery of the stolen assets is not established.
- Completion of the announced compensation plan is not established.
- Reviewed reopening notices covered Qubit markets but did not establish QBridge reopening.
Timeline events
QBridge exploit disclosed and functions disabled2022-01-28
Qubit Finance reported an exploit of the QBridge deposit function and disabled supply, redeem, borrow, repay, bridge, and bridge-redemption functions while investigating the incident.
The exploit began late on January 27 UTC and was publicly documented on January 28.
Qubit compensation plan announced2022-02-08
Team Mound announced that team-held tokens, debt-financed asset-management proceeds, protocol revenue, and any recovered funds would be directed toward community compensation.
The announcement was a forward-looking plan and is not evidence of completed reimbursement.
Qubit governance transition to DAO announced2022-02-11
The associated Bunny and Qubit protocols announced a move from development-team-led operation toward DAO governance after the exploit made the prior operating structure unsustainable.
The DAO announcement covered the wider Qubit and Bunny ecosystem and did not establish QBridge reopening.
Qubit lending markets reopened without confirmed QBridge reopening2022-02-22
Qubit reopened new lending markets with zero initial liquidity and began compensation claims, while the reviewed announcement did not state that QBridge had resumed.
This event explicitly separates protocol-market reopening from the bridge's terminal record.
Evidence records
- Protocol Exploit ReportQubit Finance · Tier 1 · High reliability · primary · 2022-01-28Claim scope: Incident Case
Primary source for the exploit timeline, deposit-function logic flaw, and disabling of QBridge and lending functions.
- Qubit Bridge Collapse Exploited to the Tune of $80 MillionCertiK · Tier 1 · High reliability · secondary · 2022-01-28Claim scope: Amount
Technical security analysis supporting the approximately $80 million direct-loss estimate and zero-value deposit logic.
- Our Compensation Plan 1Qubit Finance · Tier 1 · High reliability · primary · 2022-02-08Claim scope: Reimbursement
Primary source for the announced compensation structure, $10 million initial target tranche, and continuing asset-recovery efforts.
- The Next Chapter: DAOBunny Finance / Team Mound · Tier 1 · High reliability · primary · 2022-02-11Claim scope: Shutdown
Official same-operator ecosystem source for the transition of Qubit and Bunny protocols toward DAO governance and the end of the prior scaled development structure.
- Qubit Markets ReopeningQubit Finance · Tier 1 · High reliability · primary · 2022-02-22Claim scope: Restart
Primary source for new lending-market reopening, compensation-claim commencement, and the updated $90.8 million damage estimate; it does not state that QBridge reopened.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The final amount distributed through compensation mechanisms requires further review.
- The final disposition of the attacker's assets requires later source-specific investigation.
- The current operating status of Qubit lending markets should not be used as evidence that QBridge resumed.
Conflicting claims
Loss amount scope
Reported values: Approximately $80 million directly stolen · Approximately $90.8 million later affected-user damage estimate
Current treatment: Retain both because they measure different scopes; use $80 million as the direct exploit-loss display amount.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.