ChainConnect bridge exploit on July 26, 2026 — project publicly offers whitehat 15% bounty to recover 85% of stolen funds, warns of law-enforcement escalation if funds not returned.
Security & Exploits ·
ChainConnect announced a settlement proposal on July 28, 2026, following a bridge exploit two days earlier, offering the party in control of the stolen funds a 15% whitehat bounty if 85% is returned to a designated Ethereum address. The onchain message, posted from the project's verified address, frames the arrangement as a mutual resolution path, promising public acknowledgment and immunity from civil claims and identity-attribution efforts in exchange for fund recovery.
The proposal carries explicit escalation terms: if funds are not returned, ChainConnect stated it will pursue "all lawful recovery options," including notification to law-enforcement authorities and engagement of blockchain-investigation firms. The message notes that relevant addresses have already been circulated to exchanges and analytics providers and that tracing efforts are underway, signaling active progress on recovery attempts.
The onchain communication requires the fund controller to respond from their address and sign a message to prove control, establishing a direct negotiation channel. It remains unclear whether the party has engaged with the proposal or whether additional recovery steps have been initiated since the July 28 message was posted.