Incident case

Wormhole 2022 wrapped ETH mint exploit

In February 2022, Wormhole was exploited through a vulnerability that allowed unauthorized wrapped ETH minting on Solana. Public reporting described a loss of roughly $320 million, and the bridge deficit was later backfilled.

reviewedcurrent

Incident facts

Incident title
Wormhole 2022 wrapped ETH mint exploit
Bridge
Wormhole
Incident date
2022-02-02
Incident type
Exploit
Major incident
Yes
Affected chains
Solana, Ethereum
Affected assets
WETH
Attack category
Message Verification Failure
Reported loss
$320 million
Amount confidence
Medium
Loss amount basis
Public Reports And Secondary Summaries
Recovery
Not Applicable
Reimbursement
Completed
Restart
Reopened
Current outcome
Active After Incident
Postmortem
Unknown
Resolution
Final outcome known
Last reviewed
2026-07-28
Last verified
2026-07-28

Amount and valuation

Reported as roughly $320 million in public coverage.

Public reports commonly cite approximately $320 million; exact valuation depends on ETH price and source timing.

Timeline events

  • Wormhole exploit disclosed2022-02-02

    The Wormhole exploit became public after unauthorized wrapped ETH minting on Solana was identified.

    Exploit DisclosedHigh
  • Bridge deficit backfilled2022-02-03

    Public reporting described the Wormhole bridge deficit as backfilled after the exploit, enabling the record to track the incident as reimbursed/backfilled rather than unresolved.

    Reimbursement CompletedHigh

    Sponsor-funded deficit backfill is classified as completed reimbursement; it is not attacker-fund recovery.

  • Wormhole service restored after deficit backfill2022-02-03

    Wormhole announced that funds had been restored and the bridge service was operational again after the sponsor-funded deficit backfill.

    Bridge ReopenedHigh

    Reopening is recorded separately from the deficit-backfill reimbursement event.

  • Wormhole included in bridge-hack research context2025-01-06

    Later cross-chain bridge hack surveys use Wormhole as a major reference case for bridge exploit classification and loss-scale comparison.

    Research ContextMedium

    Used for context only, not as a primary incident source.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.