On 2 February 2022, at 18:24 UTC, an attacker exploited Wormhole’s Solana-side contract: a flaw in how guardian signatures were checked let them mint 120,000 Wormhole-wrapped ether that was not backed by ether locked on Ethereum — on the order of $320 million. They moved most of it back through the bridge and unwrapped it into native ETH. Wormhole paused relaying, patched the contract, and said the wrapped supply would be recapitalised. On 3 February, at 13:08 UTC, Jump Crypto — which had bought Wormhole’s developer, Certus One — deposited 120,000 ETH. The network came back the same afternoon. Incident length: about sixteen hours.
This is not Ronin (validator keys, March). It is not Poly Network (2021). A company choosing to refill a hole is solvency and reputation, not a protocol guarantee that the next bridge will do the same.
What happened
A bridge is a lock-and-mint: coins on one chain, IOUs on another, guardians who attest that the lock happened. If the attestation can be forged, the mint is fake and the remaining real reserves are now shared with extra paper. Holders of wrapped ether on Solana would have been left under-backed if nobody had filled the gap. Jump did.
Why it matters
If you used Wormhole, you got a reminder that “cross-chain” is a company stack with a bug surface, and that make-whole is a decision. If you did not, a Solana or ether candle is weather. See how crypto wallets actually work. See what is a blockchain, really, if a wrapped ticker still looks like the asset on the other side.
What happens next
A post-mortem, more bridge insurance talk, and a later, larger key-theft on Ronin. We will not rank remaining bridges. Nothing here is an instruction to bridge, unwrap, buy, or sell SOL or ether.




