Adshares wADS bridge hack — May 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | May 16, 2026 |
| Target type | Cross-chain bridge |
| Loss | $628,000Price at time of incident |
| Recovered | $540,700 |
| Method | Other or undisclosedAdshares' bridge-minting address signed three wrapTo() calls citing Adshares-chain transactions that do not exist, minting about 1.2m unbacked wADS; how the minting process was made to accept them has not been published |
| Chains | Ethereum |
| Outcome | Settled as bug bounty |
What happened
Adshares, whose ADS token is wrapped onto Ethereum as wADS, lost about $628,000 on 15 May 2026 when its bridge minted 1,199,999.81 wADS with no backing on the Adshares chain, in three transactions between 20:32 and 20:48 UTC. Defimon Alerts reported it the next day.
According to Defimon, the bridge's minting address signed three wrapTo() calls citing transactions on the Adshares chain that do not exist, minting 99,999.93 wADS twice and 999,999.94 wADS to the attacker, who sold them through Uniswap for about 148.55 ETH and $305,000 of USDC. How the minting process was made to accept the requests has not been published.
This registry read the three mint transactions. Adshares offered on-chain to treat the attacker as a whitehat if 90% of the proceeds came back within 72 hours; PeckShield reported on 18 May that the attacker had returned 256 ETH, about $540,700 and some 86% of the total, to the project's deployer address. Defimon's $628,000 is recorded as the loss and the $540,700 as recovered.
Sources
- Defimon Alerts on XSecondary · retrieved 2026-10-06
- PANewsSecondary · retrieved 2026-10-06
- DeFiHackLabs exploit reconstructionSecondary · retrieved 2026-10-06
- Ethereum mint transaction, read by this registryOn-chain · retrieved 2026-10-06
Changes to this entry
- Recorded on 6 October 2026 in a backfill of 2026 incidents that this registry had missed, found through DeFiHackLabs' reproduction list. The amount was checked against the transaction receipt, read by this registry from a public node.
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Adshares wADS bridge hack — May 2026", iTokenly, accessed 2026-10-06, https://itokenly.com/hacks/adshares-wads-bridge-may-2026https://itokenly.com/hacks/adshares-wads-bridge-may-2026Permalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.