ChainSwap hack — July 2021
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | July 11, 2021 |
| Target type | Cross-chain bridge |
| Loss | $4,400,000Published estimates range $4,000,000 to $8,000,000Price at time of incident |
| Method | Access control flawChainSwap's cross-chain bridge minted wrapped partner-project tokens on Ethereum and BNB Chain against a per-address transfer quota. ChainSwap described a logical flaw in the quota code that let addresses which were never whitelisted have their quota increased automatically. SphereX's later analysis found the signature check itself functioned correctly; the failure was that the verified proxy pointed at an unverified implementation contract deployed about a week before the attack, whose authQuotaOf() returned an effectively unlimited quota (10^22) for any address instead of zero. The code visible on Etherscan was not the code being executed. |
| Chains | Ethereum, BNB Chain |
| Outcome | Partially recovered |
What happened
ChainSwap ran a cross-chain bridge that minted wrapped versions of partner-project tokens on Ethereum and BNB Chain. An attacker minted and withdrew wrapped tokens belonging to around 16 to 20 partner projects, among them Antimatter, Blank, Corra, Dafi, Nord Finance, Option Room, Oro, Peri, Razor Network, Rocks, Umbrella Network, Unifarm, Unido, Vortex, Wilder World and ChainSwap's own ASAP. Accounts differ on the day. Razor Network, a direct victim, dated the start at about 20:00 UTC on 10 July 2021; ChainSwap titled its own post-mortem 11 July, and SphereX, Crypto Briefing and Lossless all date the incident 11 July.
ChainSwap attributed the loss to a logical flaw in the cross-chain quota code that allowed non-whitelisted addresses to have their transfer quota raised automatically. SphereX's later analysis narrowed it further: signature verification worked, but the proxy routed to an unverified implementation contract deployed about a week earlier, whose authQuotaOf() function granted any address an effectively unlimited quota. The verified code on Etherscan was not the code being run.
The published figures diverge sharply. ChainSwap's post-mortem put the loss at around $4 million. SphereX put it at $4.4 million. Contemporaneous reporting by Crypto Briefing and Lossless used roughly $8 million, closer to the notional pre-crash value of the minted tokens. The scale of the price damage is disputed: Crypto Briefing's worst case was Antimatter's MATTER at 68.8%, while Lossless described a 99% plunge in affected tokens and put ChainSwap's own ASAP at 96.7% below its all-time high.
This was ChainSwap's second breach in nine days; an incident on 2 July cost about $800,000. After 10 July it froze the bridge and shut down nodes, compensated some partner projects — Razor Network confirmed receiving 48,475 USDC against a 121,187 DAI loss — and several projects redeployed their tokens.
Sources
- ChainSwapPrimary · retrieved 2026-08-01
- Razor NetworkPrimary · retrieved 2026-08-01
- SphereX TechnologiesSecondary · retrieved 2026-08-01
- Crypto BriefingSecondary · retrieved 2026-08-01
- LosslessSecondary · retrieved 2026-08-01
Official post-mortem: https://chain-swap.medium.com/chainswap-exploit-11-july-2021-post-mortem-6e4e346e5a32
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "ChainSwap hack — July 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/chainswaphttps://itokenly.com/hacks/chainswapPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.