I assumed a bridge hack meant someone found a bug in the code, a flaw in the cryptography, something a security audit missed. Dusk's own post-mortem on its January bridge incident describes something else.
On January 16, an attacker compromised a signing wallet used by the Dusk-to-EVM bridge, moving funds directly on Dusk before routing part of it onward to BNB Smart Chain. Dusk shut the bridge down mid-attack, which is what caused a final, roughly 8.9 million DUSK transfer attempt to fail.
This was not a consensus failure or a protocol exploit. Dusk says the direct cause was key compromise, and that the old design let the signing wallet, event handling, and network connectivity all operate inside one path. The weakness was concentrated operational authority, not weak cryptography.
The redesign that followed comes down to one sentence buried in the post-mortem: "ingestion is no longer equivalent to spending." Seeing that an event happened and having the authority to release funds because of it used to be the same step. Now they're not. Event ingestion gets checkpointed and queued as a job; a separate, explicit process actually moves funds against it.
"A protocol can work as designed while the operational layer around it gives one compromised path too much authority."
What I'd actually want to see: confirmation that the redesigned bridge actually keeps event ingestion and fund release on separate paths in practice, not just in the post-mortem's description of the new architecture.
#dusk $DUSK @Dusk
On January 16, an attacker compromised a signing wallet used by the Dusk-to-EVM bridge, moving funds directly on Dusk before routing part of it onward to BNB Smart Chain. Dusk shut the bridge down mid-attack, which is what caused a final, roughly 8.9 million DUSK transfer attempt to fail.
This was not a consensus failure or a protocol exploit. Dusk says the direct cause was key compromise, and that the old design let the signing wallet, event handling, and network connectivity all operate inside one path. The weakness was concentrated operational authority, not weak cryptography.
The redesign that followed comes down to one sentence buried in the post-mortem: "ingestion is no longer equivalent to spending." Seeing that an event happened and having the authority to release funds because of it used to be the same step. Now they're not. Event ingestion gets checkpointed and queued as a job; a separate, explicit process actually moves funds against it.
"A protocol can work as designed while the operational layer around it gives one compromised path too much authority."
What I'd actually want to see: confirmation that the redesigned bridge actually keeps event ingestion and fund release on separate paths in practice, not just in the post-mortem's description of the new architecture.
#dusk $DUSK @Dusk
