MKT

Ratings · Where the money actually dies

Cross-chain bridges

The largest thefts in the history of crypto happened here, and every other comparison ranks bridges on speed and fees. We rank them on the two questions that decide whether you lose everything: who can take your money if they collude, and when it went wrong, did anyone actually get paid back.

SAFEST

No committee at all. Ethereum verifies your withdrawal, and the 7-day window is the security — not a defect that faster bridges removed.

BEST IF YOU CANNOT WAIT

A bonded relayer fronts your funds and eats the 7-day settlement risk instead of you. That is a real transfer of risk, not a removal of it.

BEST FOR USDC

Burn-and-mint of native USDC, so there is no wrapped asset and no new counterparty — you already trust Circle by holding USDC at all.

What we did · July 15, 2026We read the contracts and the docs for the signer count and the threshold, found out who holds the upgrade key, and then went through every major exploit asking the question the other pages skip: did anyone actually get their money back, and who paid for it?

“THEY PAID USERS BACK LAST TIME” IS NOT A SAFETY SIGNAL

Whether people got their money back has had almost nothing to do with the bridge’s security, and almost everything to do with whether a rich, identifiable company happened to be standing behind it.

  • Ronin, $625m — repaid, because Sky Mavis raised $150m, led by Binance.
  • Wormhole, $325m — repaid, because Jump Crypto put 120,000 ETH of its own balance sheet in, within a day.
  • Poly Network, $611m — returned, because the thief changed his mind.
  • Multichain, $126m — no sponsor. Never repaid. The MPC keys were on the CEO’s personal cloud account, and he was detained in China.
  • Harmony, ~$100m — the reimbursement plan was withdrawn after backlash. Four years later, no confirmable make-whole exists.

It is a measure of somebody else’s balance sheet, and it predicts nothing about your money. Which is why the trust assumption carries 40% of the score on this page and the incident record carries 25%.

One regulator has finally broken the pattern

In December 2025 the FTC forced Nomad’s operator, Illusory Systems, to return recovered funds to users and submit to independent biennial security assessments. It is the first time a US regulator has compelled a bridge operator to repay — and it is the first sign that whether you get your money back might one day stop depending on whether your bridge had a generous parent company.

The ranking

#NAMESCORE

Click any row for the quick read, or open a company for its full profile and per-criterion scores. Measured July 15, 2026. How we rate.

HOW WE SCORED THIS — CRITERIA AND WEIGHTS+

Bridges are where the largest sums in crypto have been stolen. Every other comparison ranks them on speed and fees. We rank them on the only two questions that decide whether you lose everything: who can take your money if they collude, and when it went wrong, did anyone actually get paid back.

Trust assumption · 40% · level A

Not a label — a number. Who, exactly, can move the money if they collude or are compromised? A canonical rollup bridge answers "nobody: Ethereum itself verifies the withdrawal, and the seven-day window is the period in which fraud can be proven". An external committee answers with a threshold, and that threshold IS the rating: Ronin was 5-of-9 and four of those keys sat on one company's servers. Harmony was 2-of-5. We publish the signer count and the threshold wherever they exist, and where a project will not state them, that silence is scored as the risk it is.

The upgrade key · 15% · level A

The assumption that quietly overrides the whitepaper. A bridge whose contracts can be upgraded by a small multisig HAS that multisig as its real trust model, whatever the architecture diagram says — and Nomad proves it: the bug that lost $186m was introduced BY an upgrade. So we ask who holds upgrade authority, and we score the answer rather than the design.

Incidents — and did users get paid · 25% · level A

Every exploit with its root cause, and then the column nobody else publishes: were users made whole, and is that INDEPENDENTLY confirmed or merely claimed? Read the results carefully, because they do not mean what people think. Reimbursement in this category has tracked the sponsor’s balance sheet, not the bridge’s security. That makes "they paid people back last time" close to worthless as a safety signal, and we score it accordingly.

Audits and transparency · 10% · level A

Named firms, dated reports, published. An unnamed audit is not an audit. Undisclosed validator counts are scored as undisclosed, not assumed benign.

Cost and speed · 10% · level A

Deliberately the smallest weight, and one qualification matters more than the number: we refuse to treat the canonical bridge’s seven-day withdrawal window as a defect. It is not a delay that clever engineering removed — it is the exact period during which Ethereum can be used to prove a withdrawal fraudulent. A fast bridge is fast for one reason: it substituted somebody’s signature for that proof.

DISQUALIFIERS FOR THIS CATEGORY
  • — User funds never returned after an exploit, with no ongoing effort to return them.
  • — Validator or signer keys under the effective control of a single individual.

Weights sum to 100. If we cannot verify a criterion, we delete it rather than score it on impressions — read the methodology.

WE LOOKED AT 32. 5 DID NOT MAKE IT — HERE IS WHO, AND WHY

  • Multichain — Defunct. $126m in unauthorised outflows in July 2023, never repaid to anyone. It marketed itself as a decentralised MPC network; in reality the MPC nodes ran under the CEO’s personal cloud account, and when he was detained in China the team discovered it had lost access entirely. Anyone who tells you "MPC" means "decentralised" should be shown this. [source]
  • Harmony Horizon — Defunct. A 2-of-5 multisig protecting roughly $100m — any two keys could send the money anywhere, and two keys were compromised. The 100% reimbursement plan was withdrawn after community backlash, and four years later we can find no confirmable make-whole. [source]
  • Orbit Chain — $81m taken on 31 December 2023 after 7 of its 10 multisig signers were compromised. We found the project warning users about scam "reimbursement" offers rather than running a real one. [source]
  • Nomad — Defunct after its $186m exploit. Worth knowing why it is not simply forgotten: in December 2025 the FTC forced its operator, Illusory Systems, to return recovered funds to users and submit to biennial independent security assessments — the first time a US regulator has compelled a bridge operator to repay. That precedent may finally decouple the question of who gets paid back from the question of who happens to have a generous sponsor. [source]
  • Ronin Bridge (legacy) — Deprecated in April 2025 — over $450m was migrated to Chainlink CCIP, and Ronin became an OP Stack L2 in May 2026. It is in this list because it is the case that defines the category: 5-of-9, with four keys on Sky Mavis servers and a fifth obtained from the Axie DAO. $625m. Users were repaid because Sky Mavis raised $150m to repay them — not because the bridge was safe. [source]

Is there a free alternative?

For most people, most of the time, the answer is: use the canonical bridge and wait a week.

The seven-day withdrawal window on Arbitrum, Optimism and Base is not a defect that clever third-party bridges engineered away. It is the exact period during which Ethereum itself can be used to prove that a withdrawal is fraudulent. A fast bridge is fast for precisely one reason — it has substituted somebody’s signature for that proof. And note what this means for deposits: going INTO an L2, the canonical bridge takes minutes and has no challenge window at all, so there is literally no speed argument for using anything else. Ever. If you are coming out and cannot wait a week, prefer a design where a bonded relayer fronts your funds and eats the delay for you — Across and Hop — over a committee holding your money. If you are moving USDC, Circle’s CCTP adds no counterparty you do not already trust by holding USDC in the first place. No affiliate-funded bridge aggregator will ever lead with “just use the canonical bridge”, for the simple reason that the canonical bridge pays no referral fee. That is the entire economics of why every other page in this category ranks on speed.

What changed since last time

  • 2026-07-15Category published.The largest thefts in crypto history happened here, and every comparison ranks on speed and fees.
  • 2026-07-15THORChain moved down after its 15 May 2026 exploit.An attacker bonded in as a node operator, was churned into the active set, and exploited the threshold-signature scheme from inside. Most bridge comparisons have not updated for this at all.

Questions

What is the safest way to bridge?+

Use the canonical bridge and wait. For deposits INTO an L2 there is not even a trade-off to think about — the canonical bridge takes minutes and has no challenge window, so there is no speed argument for using anything else, ever. For withdrawals, the seven-day window on Arbitrum, Optimism and Base is not a delay that clever bridges engineered away: it is the exact period during which Ethereum itself can be used to prove that a withdrawal is fraudulent. A fast bridge is fast for one reason — it substituted somebody’s signature for that proof.

Is the Polygon bridge canonical, like Arbitrum’s?+

No, and this is the single most under-reported risk in mainstream crypto. Per Polygon’s own documentation, the PoS contracts on Ethereum are controlled by a 5-of-9 multisig — the same threshold that lost Ronin $625 million. Most people think of "the Polygon bridge" the way they think of the Arbitrum bridge, as something Ethereum itself secures. It is not. It is nine keys, five of which are enough, and they can update the contracts holding the money. It has never been exploited. Ronin had never been exploited either, right up until it was.

Bridge X reimbursed its users after a hack. Doesn’t that make it safe?+

No — and this is the finding that reframes the whole category. Reimbursement has tracked the sponsor’s balance sheet, not the bridge’s security. Sky Mavis raised $150m, led by Binance, to repay Ronin. Jump Crypto put 120,000 ETH of its own money into Wormhole’s hole within about a day. Binance halted an entire blockchain to strand the BNB Bridge mint. Where there was no rich sponsor, people simply lost the money: Multichain’s $126m was never repaid to anyone. And in the largest case of all, Poly Network’s $611m came back only because the thief changed his mind. "They made users whole last time" is a measure of somebody else’s generosity, and it is worthless as a prediction.

Are bridge aggregators safer, since they find the best route?+

They are strictly riskier, and neither of them will tell you so. An aggregator gives you the underlying bridge’s trust assumption PLUS its own router contract to trust. LI.FI lost $11.6m in July 2024 and Socket lost $3.3m in January 2024 — to the same root cause, six months apart: a newly added route in their own router draining wallets that had granted it infinite approvals. Neither exploit was a failure of any bridge they route through. The aggregator was the vulnerability. Never grant an infinite approval to a router.

Does "MPC" mean a bridge is decentralised?+

Multichain marketed itself as a decentralised MPC network. When its CEO was detained in China in 2023, the team discovered it had lost access to the MPC nodes entirely — because they were running under his personal cloud account. The "decentralised validator network" was one man’s login. $126 million, never repaid to anyone. And in May 2026, THORChain — a genuinely bonded, genuinely distributed MPC design — was drained by an attacker who simply posted a bond, joined the validator set, and attacked the signature scheme from inside it. An MPC committee is only as safe as its ability to keep attackers out of the committee.

How this is funded

It is not. There are no affiliate links on this page or anywhere on this site, no paid placements, and no sponsored positions. Nobody in this table can buy a place in it, accelerate their inclusion, or influence a score — and none of them paid us anything, because there is nothing here to buy. The full policy.