Rubic 2022 RBC/BRBC bridge wallet compromise
A private key for an administrative wallet used by Rubic's former RBC/BRBC bridge and staking rewards was compromised. Rubic reported that approximately 35 million RBC/BRBC were sold and that the former native bridge had already been disabled and replaced by an external bridge.
Incident facts
- Incident title
- Rubic 2022 RBC/BRBC bridge wallet compromise
- Bridge
- Rubic
- Incident date
- 2022-11-02
- Incident type
- Abnormal Transfers
- Major incident
- Yes
- Affected chains
- Ethereum, BNB Chain
- Affected assets
- RBC, BRBC, ETH
- Attack category
- Operator Or Governance Issue
- Reported loss
- 35 million RBC/BRBC sold; approximately 138 ETH proceeds reported
- Amount confidence
- Medium
- Loss amount basis
- Reported By Project
- Recovery
- Unknown
- Reimbursement
- Not Applicable
- Restart
- Replaced
- Current outcome
- Deprecated After Incident
- Postmortem
- Unclear
- Resolution
- Unresolved
- Last reviewed
- 2026-07-28
- Last verified
- 2026-07-28
Amount and valuation
Rubic reported approximately 35 million locked RBC corresponding to previously minted BRBC were sold and approximately 138 ETH proceeds remained in the attacker wallet. No canonical USD loss is assigned.
Token quantity, realized attacker proceeds, broken bridge collateral relationship, and market-price impact measure different scopes and are not collapsed into one USD figure.
approximately 35 million RBC/BRBC sold
Primary token-quantity claim.
approximately 138 ETH obtained and still held at the update time
Reported realized proceeds, not a canonical valuation of all released tokens.
Why this remains unresolved
- The final disposition of the attacker proceeds is not established in reviewed sources.
- A complete recovery outcome for the released RBC/BRBC supply is not established.
Timeline events
Rubic native RBC/BRBC bridge disabled2022-10
Rubic reported that its native RBC/BRBC bridge was disabled at the end of October and replaced in practice by an external bridge solution.
RBC/BRBC bridge wallet compromise occurred2022-11-02
Unauthorized actions using a compromised administrative-wallet private key released assets associated with the former RBC/BRBC bridge.
Rubic disclosed token sales and attacker proceeds2022-11-04
Rubic reported approximately 35 million RBC/BRBC sold and approximately 138 ETH proceeds remaining in the marked attacker wallet.
Rubic announced tokenomics relaunch after collateral break2022-11-29
Rubic stated that the additional RBC supply broke the RBC/BRBC collateral relationship and proposed relaunching the token with new tokenomics.
Evidence records
- Rubic Weekly Report 11/04/2022Rubic · Tier 1 · High reliability · primary · 2022-11-04Claim scope: Incident Case
Primary source for wallet scope, private-key cause, 35 million RBC/BRBC, 138 ETH proceeds, user-fund exclusion, and external-bridge replacement.
- Introducing the New Rubic Tokenomics — The Way ForwardRubic · Tier 1 · High reliability · primary · 2022-11-29Claim scope: Migration
Primary source for collateral break, increased supply, price effect, and token relaunch plan.
- Cross-chain bridge RBC — BRBC and BRBC tutorialRubic · Tier 1 · High reliability · primary · 2021-03Claim scope: Bridge Entity
Historical first-party bridge design and RBC/BRBC relationship context.
- Rubic Weekly Report 11/04/2022Rubic · Tier 1 · High reliability · primary · 2022-11-04Claim scope: Incident Case
Event-scoped primary copy supporting the RBC/BRBC administrative-wallet compromise, released assets, approximate amount, suspension, and migration response.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The exact USD value realized across all token sales is not established.
- The former bridge was already disabled before disclosure, but the exact final disablement day is reported only as the end of October.
- User swap and staking funds were reported safe; this record does not infer user reimbursement.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.