Alephium TokenBridge approval keys compromised; attackers drain $815K and mint 13.76M unbacked ALPH tokens.
Security & Exploits ·
Attackers gained access to approval keys for Alephium's TokenBridge, enabling them to drain $815K and mint 13.76M ALPH tokens without authorization. The exploit did not require modification of contract code itself, suggesting the attackers obtained or exploited existing signature or permission mechanisms that govern token bridge operations.
The TokenBridge functions as a cross-chain mechanism for Alephium; compromise of its approval infrastructure created a pathway for unbacked token issuance and fund extraction. The newly minted ALPH tokens lacked corresponding collateral or legitimate backing, indicating a fundamental breach of the bridge's integrity and reserve mechanisms.
The scope of remediation and timeline for halting further exploitation remain unclear. No details have emerged regarding how the approval keys were initially compromised, whether other bridge functions or assets face ongoing risk, or what steps are underway to recover drained funds or address the unauthorized token inflation.