MKT
S
Ranked #14

Socket / Bungee: cross-chain bridges rating breakdown

3.5/10
Rank #14 of 16

A router that finds you a route across many underlying bridges.

Researched by the ChainWatch Daily ratings deskMeasured How we rateSomething wrong? Tell us

A router that finds you a route across many underlying bridges.

How the score is built

Each criterion is scored 0–10 and weighted. The median column is the middle score across every entry in this ranking, so a row reads as a position rather than a number.

CriterionWhat we measuredWeightScoreCategory medianRankWeighted gap
Trust assumption—40%3411 of 16-0.40
The upgrade key—15%2312 of 16-0.15
Incidents — and did users get paid—25%4914 of 16-1.25
Audits and transparency—10%55.59 of 16-0.05
Cost and speed—10%5614 of 16-0.10

Measured 15 July 2026 · weights and method · decided by incidents — and did users get paid, worth -1.25 points against the median

Trust assumption: 3/10

Not a label — a number. Who, exactly, can move the money if they collude or are compromised? A canonical rollup bridge answers "nobody: Ethereum itself verifies the withdrawal, and the seven-day window is the period in which fraud can be proven". An external committee answers with a threshold, and that threshold IS the rating: Ronin was 5-of-9 and four of those keys sat on one company's servers. Harmony was 2-of-5. We publish the signer count and the threshold wherever they exist, and where a project will not state them, that silence is scored as the risk it is.

Scored 3 of 10 against a category median of 4, which places it 11th of 16 among cross-chain bridges on this criterion. At a 40% weight that is 0.40 points below the median contribution of the weighted total. The best score in the category is 10, the worst 2.

The upgrade key: 2/10

The assumption that quietly overrides the whitepaper. A bridge whose contracts can be upgraded by a small multisig HAS that multisig as its real trust model, whatever the architecture diagram says — and Nomad proves it: the bug that lost $186m was introduced BY an upgrade. So we ask who holds upgrade authority, and we score the answer rather than the design.

Scored 2 of 10 against a category median of 3, which places it 12th of 16 among cross-chain bridges on this criterion. At a 15% weight that is 0.15 points below the median contribution of the weighted total. The best score in the category is 7, the worst 1.

Incidents — and did users get paid: 4/10

Every exploit with its root cause, and then the column nobody else publishes: were users made whole, and is that INDEPENDENTLY confirmed or merely claimed? Read the results carefully, because they do not mean what people think. Reimbursement in this category has tracked the sponsor’s balance sheet, not the bridge’s security. That makes "they paid people back last time" close to worthless as a safety signal, and we score it accordingly.

Scored 4 of 10 against a category median of 9, which places it 14th of 16 among cross-chain bridges on this criterion. At a 25% weight that is 1.25 points below the median contribution of the weighted total. The best score in the category is 10, the worst 3.

Audits and transparency: 5/10

Named firms, dated reports, published. An unnamed audit is not an audit. Undisclosed validator counts are scored as undisclosed, not assumed benign.

Scored 5 of 10 against a category median of 5.5, which places it 9th of 16 among cross-chain bridges on this criterion. At a 10% weight that is 0.05 points below the median contribution of the weighted total. The best score in the category is 8, the worst 4.

Cost and speed: 5/10

Deliberately the smallest weight, and one qualification matters more than the number: we refuse to treat the canonical bridge’s seven-day withdrawal window as a defect. It is not a delay that clever engineering removed — it is the exact period during which Ethereum can be used to prove a withdrawal fraudulent. A fast bridge is fast for one reason: it substituted somebody’s signature for that proof.

Scored 5 of 10 against a category median of 6, which places it 14th of 16 among cross-chain bridges on this criterion. At a 10% weight that is 0.10 points below the median contribution of the weighted total. The best score in the category is 9, the worst 5.

Other measurements

risk added
the router’s own contract, on top of the bridge’s
SOURCED

Its nearest neighbours in this ranking

#EntryIncidents — and did users get paidHow it differs
12Synapse8Ahead by 4 on incidents — and did users get paid.
13Polygon PoS bridge9Ahead by 5 on incidents — and did users get paid.
15THORChain3Behind by 1 on incidents — and did users get paid.
16LI.FI / Jumper3Behind by 1 on incidents — and did users get paid.

Incidents priced into this score

  • 2024-01-16 — A newly added route in the bridging contract let an attacker drain funds from wallets holding infinite approvals to the router. [users made whole: claimed] [source]

Questions about this score

Are bridge aggregators safer because they find the best route?

+

No — they are strictly riskier, and neither major aggregator will tell you so. You inherit the underlying bridge's trust assumption and add the aggregator's own router contract to it. Both of the largest aggregator losses on record, Socket in January 2024 and LI.FI in July 2024, were exactly that router contract being exploited.

How do I use an aggregator more safely?

+

Never grant an infinite token approval to a router, and revoke approvals after use. Both aggregator exploits drained wallets that had approved unlimited spending to a router contract, which is what turned a contract bug into a wallet drain. Approve only the amount you are bridging.

No affiliate links — nothing on this page is for sale. ← Back to the cross-chain bridges ranking