Incident case

QBridge 2022 zero-value deposit exploit

In January 2022, a logic flaw in QBridge allowed an attacker to submit deposit calls without transferring ETH, mint unbacked xETH on BNB Chain, and use that collateral to withdraw roughly $80 million from Qubit markets.

reviewedcurrent

Incident facts

Incident title
QBridge 2022 zero-value deposit exploit
Bridge
QBridge
Incident date
2022-01-27
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum, BNB Chain
Affected assets
BNB, WETH, WBTC, USDC, USDT
Attack category
Cross Chain Contract Exploit
Reported loss
$80 million stolen; $90.8 million later damage estimate
Amount confidence
High
Loss amount basis
Direct Stolen Asset Estimate Separated From Later Victim Damage Calculation
Recovery
Unknown
Reimbursement
In Progress
Restart
Not Reopened
Current outcome
Dead After Incident
Postmortem
Partial
Resolution
Unresolved
Last reviewed
2026-06-14
Last verified
2026-06-14

Amount and valuation

Security analysis described approximately $80 million in stolen assets, while Qubit later recalculated total affected-user damage at approximately $90.8 million.

The $80 million figure is the direct exploit-loss estimate. The $90.8 million figure is a later Qubit damage calculation and is retained as a distinct scope rather than replacing the stolen-asset estimate.

Why this remains unresolved

Timeline events

  • QBridge exploit disclosed and functions disabled2022-01-28

    Qubit Finance reported an exploit of the QBridge deposit function and disabled supply, redeem, borrow, repay, bridge, and bridge-redemption functions while investigating the incident.

    Exploit DisclosedHigh

    The exploit began late on January 27 UTC and was publicly documented on January 28.

  • Qubit compensation plan announced2022-02-08

    Team Mound announced that team-held tokens, debt-financed asset-management proceeds, protocol revenue, and any recovered funds would be directed toward community compensation.

    Compensation Plan AnnouncedHigh

    The announcement was a forward-looking plan and is not evidence of completed reimbursement.

  • Qubit governance transition to DAO announced2022-02-11

    The associated Bunny and Qubit protocols announced a move from development-team-led operation toward DAO governance after the exploit made the prior operating structure unsustainable.

    Governance Transition AnnouncedHigh

    The DAO announcement covered the wider Qubit and Bunny ecosystem and did not establish QBridge reopening.

  • Qubit lending markets reopened without confirmed QBridge reopening2022-02-22

    Qubit reopened new lending markets with zero initial liquidity and began compensation claims, while the reviewed announcement did not state that QBridge had resumed.

    Market ReopeningHigh

    This event explicitly separates protocol-market reopening from the bridge's terminal record.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Conflicting claims

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.