Bridgeless bridge exploited via duplicate hash submissions; bridge paused with ~14.41 ETHX locked; team offers whitehat settlement requiring 48-hour token burn.
Security & Exploits ·
A vulnerability in the Bridgeless bridge allowed a single account to exploit the system by submitting duplicate hash variations, resulting in the minting of 26 ETHX tokens across the Zano network from a deposit of 0.5015 ETH. The attacker subsequently burned 11.6 ETHX in attempted withdrawals before the bridge was paused, leaving approximately 14.41 ETHX locked in the affected wallet.
The exploit operated by circumventing hash validation—the attacker resubmitted the same transaction 52 times under different spellings of its cryptographic hash, each time triggering new token issuance. The bridge operators identified not only the primary account but also traced the funding sources behind it, signaling coordinated exploitation.
Rather than pursue enforcement, the Bridgeless team offered a whitehat settlement requiring the attacker to burn 9.409691 ETHX within 48 hours as a public burn transaction, with the remaining 5 ETHX retained as a bounty to be honored upon bridge resumption. The team stated the offer would be withdrawn after the deadline passed, leaving the resolution status and the full scope of affected accounts unclear pending the attacker's response.