ChainConnect bridge exploited on 26 July 2026; protocol offers 15% whitehat bounty for return of remaining 85% of stolen funds, threatening law enforcement escalation if refused.
Security & Exploits ·
On 26 July 2026, the ChainConnect bridge was exploited. In an on-chain message posted two days later, the protocol's bridge deployer signatory 0x68d447e2a4c6e7c1945725939a0cbcb4a67f9b30 offered the party controlling the stolen funds a 15% whitehat bounty to return the remaining 85% to a designated Ethereum address.
The proposal outlined conditional terms: if funds were returned, ChainConnect would publicly acknowledge the returner as a whitehat, recognize the 15% retention as a bounty for identifying the vulnerability, and forgo civil claims or independent identity-attribution efforts, subject to applicable law and third-party rights. The message emphasized that the protocol preferred this resolution and characterized it as reasonable for both sides.
The offer carried an implicit threat of escalation. ChainConnect stated that failure to return funds would trigger pursuit of all lawful recovery options, including notification to law-enforcement authorities and engagement of blockchain-investigation firms. The protocol claimed it had already circulated the relevant addresses to exchanges and analytics providers and that tracing efforts were underway. No public response or confirmation of fund recovery has been documented as of the time of writing.