ChainConnect's EVM bridge compromised via unauthorized access; $650k drained across four chains in 23 transactions.
Security & Exploits ·
ChainConnect's EVM bridge fell victim to unauthorized access on 26 July 2026, forcing the platform to halt bridge operations immediately. The compromise resulted in approximately $650,000 in token withdrawals executed across Ethereum, BNB Chain, Avalanche C-Chain, and Polygon through 23 separate transactions.
According to security observations, a portion of the extracted funds was routed to Tornado Cash, a privacy mixer, while the remainder remains held at address 0xd86cbC1892BFDa05f3D7e6C17C71709b6AE957a5. The multi-chain nature of the theft and use of mixing services complicate recovery and fund tracing efforts.
Details remain sparse regarding the precise vector of unauthorized access, whether funds can be retrieved, and whether ChainConnect has identified the responsible party. The full scope of affected users and any ongoing investigation have not been disclosed.