Wormhole 2022 wrapped ETH mint exploit
In February 2022, Wormhole was exploited through a vulnerability that allowed unauthorized wrapped ETH minting on Solana. Public reporting described a loss of roughly $320 million, and the bridge deficit was later backfilled.
Incident facts
- Incident title
- Wormhole 2022 wrapped ETH mint exploit
- Bridge
- Wormhole
- Incident date
- 2022-02-02
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Solana, Ethereum
- Affected assets
- WETH
- Attack category
- Message Verification Failure
- Reported loss
- $320 million
- Amount confidence
- Medium
- Loss amount basis
- Public Reports And Secondary Summaries
- Recovery
- Not Applicable
- Reimbursement
- Completed
- Restart
- Reopened
- Current outcome
- Active After Incident
- Postmortem
- Unknown
- Resolution
- Final outcome known
- Last reviewed
- 2026-07-28
- Last verified
- 2026-07-28
Amount and valuation
Reported as roughly $320 million in public coverage.
Public reports commonly cite approximately $320 million; exact valuation depends on ETH price and source timing.
120,000 ETHabout $320 million
Used as the display loss amount in this seed record.
Timeline events
Wormhole exploit disclosed2022-02-02
The Wormhole exploit became public after unauthorized wrapped ETH minting on Solana was identified.
Bridge deficit backfilled2022-02-03
Public reporting described the Wormhole bridge deficit as backfilled after the exploit, enabling the record to track the incident as reimbursed/backfilled rather than unresolved.
Sponsor-funded deficit backfill is classified as completed reimbursement; it is not attacker-fund recovery.
Wormhole service restored after deficit backfill2022-02-03
Wormhole announced that funds had been restored and the bridge service was operational again after the sponsor-funded deficit backfill.
Reopening is recorded separately from the deficit-backfill reimbursement event.
Wormhole included in bridge-hack research context2025-01-06
Later cross-chain bridge hack surveys use Wormhole as a major reference case for bridge exploit classification and loss-scale comparison.
Used for context only, not as a primary incident source.
Evidence records
- Security News This Week: A $320 Million Crypto Hack Sends the DeFi World ReelingWired · Tier 2 · High reliability · secondary · 2022-02-05Claim scope: Incident Case
Used for the initial public loss framing of the Wormhole exploit.
- Crypto's biggest hacks and heists after $1.5 billion theft from BybitReuters · Tier 2 · High reliability · secondary · 2025-02-24Claim scope: Reimbursement
Used for later retrospective context that funds were replaced/backfilled.
- The Largest Cryptocurrency Hacks So FarInvestopedia · Tier 2 · Medium reliability · secondary · 2018-07-06Claim scope: Amount
Used as a secondary reference for loss scale and replenishment context.
- SoK: A Review of Cross-Chain Bridge Hacks in 2023arXiv · Tier 2 · Medium reliability · secondary · 2025-01-06Claim scope: Incident Case
Research context for bridge-hack classification and Wormhole as a reference case.
- Wormhole acknowledged the network exploitWormhole · Tier 1 · High reliability · primary · 2022-02-02Claim scope: Incident Case
Primary contemporaneous acknowledgement of the incident.
- Wormhole announced restoration of funds and serviceWormhole · Tier 1 · High reliability · primary · 2022-02-03Claim scope: Restart
Primary statement that funds had been restored and Wormhole was back up.
- Wormhole announced restoration of funds and serviceWormhole · Tier 1 · High reliability · primary · 2022-02-03Claim scope: Restart
Duplicate official source retained as a separate event-scoped evidence record for service restoration.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- This seed record does not yet include a full technical root-cause timeline.
- Exact loss valuation varies by source and valuation date.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.