$46 Billion from 25 Cents: A Tour of Leaky Bridges
There is a structure in crypto that everyone calls a bridge. People walk across it, carry valuables over it, trust it with their savings. And roughly once a month it collapses with somebody on it.
In September 2026, someone took twenty-five cents worth of bitcoin and turned it into 46 billion counterfeit tokens. Face value of the print run: $46.1 billion. What actually walked away was around $336,000, because that is all the liquidity pools had to give.
Twenty-five cents. Let us walk through how that happens, calmly, without a single line of code.
A bridge is a coat check
No bridge moves anything anywhere. Blockchains cannot look at one another. Bitcoin does not know what happens on Ethereum, and Ethereum cannot read Solana. Each one is a sealed room with no windows.
So the industry settled on the coat check model. You hand your coat (your coins) to a vault on chain A. The attendant gives you a numbered ticket (a wrapped token) on chain B. The ticket keeps nobody warm, but it travels well and can be exchanged back for the coat.
Everything rests on one promise: there are exactly as many tickets as there are coats. Every bridge hack ever recorded, without exception, is a violation of that one equation. Somebody got a ticket without handing over a coat.
The attendant stands outside the building
Here is where it gets interesting. The vault sits on chain A. The machine that prints tickets sits on chain B. Between them there is no connection, because no connection physically exists.
So a middleman is required. A person, a server, a group of signers, a set of keys — somebody who looks at the vault and shouts through the wall: coat received, print the ticket. The machine believes him. It has no way to check.
That shout through the wall is the vulnerability. Not the vault, not the printing machine, but the layer in between. It is guarded by neither chain's consensus, because it is not part of a blockchain at all. Attackers stopped breaking blockchains a long time ago and now go straight for the verification machinery.
Which gives us a rule worth memorising: a wrapped token is exactly as sound as the weakest of three links. And the weakest one is always the attendant.
Four doors
There are surprisingly few doors. The diagram below is the whole route, with the entry points marked.
Red marks the attacker’s path: three ways in, one way out.
Door one: the coat that never existed. The attacker presents a receipt for a deposit that never happened. In May 2026 the Adshares bridge went down exactly this way: three mint calls were signed against transaction IDs that did not exist on the source chain, fake wrapped ADS was printed and dumped into pools, taking roughly $628,000. Earlier, in January 2022, someone called Qubit's deposit function with no funds attached at all, faked the event, passed validation and printed around 77,000 units of wrapped ether. Loss: $80 million.
Door two: the attendant was replaced. Nothing needs breaking here. You just take the keys. Ronin bridge, March 2022: using stolen private keys, two transactions carried out roughly 173,600 ETH and 25.5 million USDC, about $624 million. Still the industry record.
Door three: a check that checks nothing. Nomad bridge, August 2022, $190 million. After an upgrade, every message counted as already proven. What followed was unprecedented: the exploit required no technical skill whatsoever, the transactions sat in the open, and anyone could copy a successful withdrawal, swap in their own address and broadcast it — the bridge approved it automatically. Crypto Twitter found out, and within hours more than 300 addresses had joined the looting. The bridge was carried off by a crowd, like an abandoned shop.
The same door has a side entrance: a forgotten key with too much authority. In August 2026 someone minted roughly 14.9 billion unbacked SAND tokens belonging to The Sandbox; the face value of the counterfeit was put at close to $49 billion, nearly five times the real supply on Ethereum. No cryptography was broken. An administrative role simply had more power than it should have. Once an attacker holds a role like that, the entire mint logic becomes a blank cheque.
Door four is not a way in. It is the way out. A printed token is worth zero until it is sold. So the ending is always the same: immediate dumping into pools, conversion, mixer. A race against the clock.
Why the numbers look so strange
Notice the gap. Forty-six billion printed, three hundred and thirty-six thousand taken. Forty-nine billion in SAND printed, and almost none of it cashed out, because the team shut the bridge down in time.
The explanation is an uncomfortable one. What limits the damage is not the strength of the bridge but the depth of the pools on the day. The bridge was broken completely, down to the foundation. There simply were not 46 billion dollars of buyers around that evening.
Which leads to something every holder of wrapped assets should keep in mind: a flaw that drains two million today will drain a multiple of that tomorrow, once liquidity grows. It has not gone anywhere. It is waiting for volume.
Why this does not get fixed
You might assume these are teething problems the industry will outgrow. It does not outgrow them. Since 2022, bridge hacks have accounted for more than 69% of all funds stolen in DeFi, cumulatively over $2.8 billion. In 2022 alone Chainalysis counted roughly $2 billion across 13 separate incidents. Four years later, a run of bridge failures pushed total crypto theft for 2026 past $1.2 billion.
The reason for the repetition is simple. The four doors are not four separate bugs waiting to be patched one by one. They are one property of the design wearing four different names. A bridge must contain something capable of printing. As long as that thing exists, the only open question is which door they come through next: a forged receipt, a stolen key, an empty check, or a forgotten role.
Audits do not cure this. An audit inspects code, and what usually breaks is not the code but the party standing between the chains.
This cannot happen here
At this point an article is supposed to introduce the solution that elegantly avoids all of the above. We do not have a solution, and that is not a figure of speech.
AYA CORE does not build bridges. No wooden ones, no concrete ones, no suspension ones. There is no vault of ours on anyone else's chain, no attendant standing outside the chains, no machine printing tickets, and no wrapped version of AYA anywhere. The token lives in its own network, with its own post-quantum keys, and it does not relocate.
Which means the conversation about four doors simply does not apply to us. You cannot steal the key of a middleman who does not exist. You cannot forge a deposit receipt where deposits on foreign chains never occur. You cannot seize the mint role, because nobody in AYA can mint at all: the supply is fixed by the founding text and changes by no vote, no key and no upgrade.
We do not present this as a feat of engineering. We present it as a part we declined to install. The most reliable structure is the one that is not there. It does not rust, it does not get hijacked, and it does not collapse in September.
Want a wrapped AYA on another chain? Buy AYA and wrap it yourself, at your own risk and without our involvement. We take no part in it — not with advice, not with code, not with a signature. Precisely because we have been reading the news for the past four years.
AYA CORE is a post-quantum Layer-1 blockchain built from scratch in Rust. Read the documentation at portal.ayacoin.online/docs, verify what the network records through the public AYA CORE Explorer, and hold the keys yourself: the wallet runs at ayacoin.online and is available on the App Store and Google Play.
This article is educational and does not constitute financial or investment advice.
AYA CORE