Rainbow Bridge August 2022 fabricated-block attack attempt
An attacker submitted a fabricated NEAR block to the Rainbow Bridge contract with a 5 ETH safe deposit. Automated watchdogs challenged the transaction in under approximately 31 seconds; no user funds were reported lost and the attacker forfeited the deposit.
Incident facts
- Incident title
- Rainbow Bridge August 2022 fabricated-block attack attempt
- Bridge
- Rainbow Bridge
- Incident date
- 2022-08-20
- Incident type
- Attempted Exploit
- Major incident
- Yes
- Affected chains
- Ethereum, NEAR
- Affected assets
- ETH, Unknown
- Attack category
- Fabricated Light Client Block
- Reported loss
- No user-fund loss reported
- Amount confidence
- High
- Loss amount basis
- Contemporaneous Reporting Quoting The Aurora Labs CEO
- Recovery
- Not Required
- Reimbursement
- Not Applicable
- Restart
- Not Interrupted
- Current outcome
- Attack Thwarted
- Postmortem
- Partial
- Resolution
- Final outcome known
- Last reviewed
- 2026-06-15
- Last verified
- 2026-06-15
Amount and valuation
The fabricated-block attempt was challenged before bridge funds were released. The attacker lost a 5 ETH safe deposit.
The attacker's forfeited 5 ETH deposit is recorded separately and is not bridge or user loss.
Timeline events
August fabricated-block attempt blocked automatically2022-08-20
Watchdogs challenged a fabricated NEAR block in under approximately 31 seconds; the attacker forfeited a 5 ETH safe deposit.
The deposit loss belongs to the attacker, not users or bridge reserves.
Evidence records
- Hackers Lose 5 Ether While Trying to Attack Near Protocol's Rainbow BridgeCoinDesk · Tier 2 · High reliability · secondary · 2022-08-23Claim scope: Incident Case
Describes the sub-31-second challenge.
- Aurora Labs CEO account of the August Rainbow Bridge attack attemptAlex Shevchenko / Aurora Labs · Tier 1 · High reliability · primary · 2022-08-22Claim scope: Incident Case
Primary public incident thread.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- A dedicated long-form official postmortem was not located; the canonical account relies on the operator's public thread and contemporaneous reporting.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.