ChainConnect bridge exploit on 26 July 2026 — project offers 15% whitehat bounty for return of remaining 85% of stolen funds, threatens law enforcement and exchange coordination if funds not returned.
Security & Exploits ·
ChainConnect issued an on-chain message on 28 July 2026 to the party controlling funds from a bridge exploit that occurred the previous day, offering a settlement proposal. The message, posted from an Ethereum address, proposes that the fund controller retain 15% of the recovered amount as a whitehat bounty in exchange for returning the remaining 85% to a designated address.
Under the terms laid out, ChainConnect would publicly acknowledge the returning party as a whitehat researcher, recognise the retained 15% as a vulnerability bounty, and forgo civil claims or independent identity-attribution efforts, subject to applicable law and third-party rights. The message frames this as the preferable resolution for both sides and invites a response signed from the controlling address to demonstrate control.
Should the funds not be returned, ChainConnect stated it will pursue all lawful recovery options, including notifying law-enforcement authorities and engaging blockchain-investigation firms. The relevant addresses have been circulated to exchanges and analytics providers, with tracing efforts underway. The outcome of these negotiations and whether the funds will be recovered remain unknown.