Rainbow Bridge May 2022 fabricated-block attack attempt
An attacker attempted to submit a fabricated NEAR block to the Rainbow Bridge light client on Ethereum. A watchdog challenged the submission before funds could be released, and no bridge or user funds were reported lost.
Incident facts
- Incident title
- Rainbow Bridge May 2022 fabricated-block attack attempt
- Bridge
- Rainbow Bridge
- Incident date
- 2022-05-01
- Incident type
- Attempted Exploit
- Major incident
- Yes
- Affected chains
- Ethereum, NEAR
- Affected assets
- ETH, Unknown
- Attack category
- Fabricated Light Client Block
- Reported loss
- No user-fund loss reported
- Amount confidence
- High
- Loss amount basis
- Incident Reporting Based On The Aurora Labs CEO'S Public Account
- Recovery
- Not Required
- Reimbursement
- Not Applicable
- Restart
- Not Interrupted
- Current outcome
- Attack Thwarted
- Postmortem
- Partial
- Resolution
- Final outcome known
- Last reviewed
- 2026-06-15
- Last verified
- 2026-06-15
Amount and valuation
The attempted fabricated-block submission was challenged before funds were released. The attacker reportedly lost a 2.5 ETH bond.
The attacker's forfeited 2.5 ETH bond is not bridge or user loss.
Timeline events
May fabricated-block attempt challenged2022-05-01
A watchdog challenged a fabricated NEAR block before funds could be released; the attacker forfeited a 2.5 ETH bond.
The bond loss belongs to the attacker, not users or bridge reserves.
Evidence records
- Failed attack on NEAR Protocol Rainbow Bridge cost attacker 2.5 ETHBeInCrypto · Tier 2 · Medium reliability · secondary · 2022-05-02Claim scope: Incident Case
Contemporaneous report based on the operator's public account.
- Aurora Labs CEO account of the May Rainbow Bridge attack attemptAlex Shevchenko / Aurora Labs · Tier 1 · High reliability · primary · 2022-05-01Claim scope: Incident Case
Primary public incident thread.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- A dedicated long-form official postmortem was not located; the canonical account relies on the operator's public thread and contemporaneous reporting.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.