BNB Chain Token Hub hack — October 2022
Incident facts
| Date of incident | |
|---|---|
| Target type | Cross-chain bridge |
| Loss | $570,000,000Published estimates range $100,000,000 to $570,000,000Price at time of incident |
| Method | Signature verification flawForged IAVL Merkle proof allowed the attacker to mint 2 million BNB |
| Chains | BNB Chain |
| Outcome | Partially recovered |
What happened
The BSC Token Hub, the bridge between BNB Beacon Chain and BNB Smart Chain, was exploited on 6 October 2022. The attacker forged a Merkle proof accepted by the bridge's IAVL verification logic and minted two million BNB, worth about $570m, in two transactions.
What makes this incident hard to state in a single number is that most of the minted value never left. BNB Chain validators halted the network within hours, which stranded the majority of the tokens. Estimates of what the attacker actually moved off the chain sit between $100m and $110m, with a further $33.5m frozen by the USDT and USDC issuers and several hundred million rendered inaccessible.
Both figures circulate in coverage of the incident and both are recorded here: $570m as the value minted, and $100m as the lower bound of what was successfully extracted. Any total that includes this incident should say which of the two it is using.
Halting the chain to contain the loss was itself notable, and prompted a durable debate about how decentralised the validator set was.
Sources
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "BNB Chain Token Hub hack — October 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bnb-chain-token-hubhttps://itokenly.com/hacks/bnb-chain-token-hubPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.