ChainConnect bridge exploit on July 26, 2026 — recovery team offers 15% whitehat bounty for return of remaining 85% of stolen funds, with threat of law enforcement escalation if funds are not returned.
Security & Exploits ·
ChainConnect, a bridge service, suffered an exploit on July 26, 2026. On July 29, the project posted an on-chain message to the address controlling the stolen funds, offering the attacker a 15% whitehat bounty if they return the remaining 85% to a designated Ethereum address.
The proposal outlines mutual incentives: ChainConnect pledges not to pursue civil claims or conduct identity-attribution efforts if the funds are restored, and will publicly recognize the attacker as a whitehat researcher. The message was signed from ChainConnect's recovery address and specifies that only responses signed by the attacker's address will be recognized as legitimate negotiation.
The outcome remains uncertain. ChainConnect has stated it will escalate to law enforcement and engage blockchain investigation firms if funds are not returned within an unspecified timeframe, though the attacker's response has not yet been disclosed. The effectiveness of recovery negotiations in bridge exploits of this scale has no set precedent in the material provided.