ChainConnect's EVM bridge compromised via unauthorized access; $650k drained across four chains in 23 transactions.
Security & Exploits ·
On 26 July 2026, ChainConnect's EVM integration fell victim to unauthorized access, triggering an immediate pause of bridge operations. The compromise resulted in the drainage of approximately $650,000 in tokens across four blockchain networks—Ethereum, BNB Chain, Avalanche C-Chain, and Polygon—distributed across 23 separate transactions.
Following the theft, attackers moved a portion of the stolen funds through Tornado Cash, a privacy mixer. The remaining assets were consolidated at address 0xd86cbC1892BFDa05f3D7e6C17C71709b6AE957a5, with several associated addresses identified as those responsible for the exploit.
The precise mechanism of the unauthorized access—whether stemming from a smart contract vulnerability, compromised credentials, or another vector—has not yet been disclosed. Recovery prospects and a detailed post-mortem from ChainConnect remain pending, as does clarity on whether the paused bridge operations will be restored and under what conditions.