warp.green ERC-20 Bridge - Post-Mortem

post image

TL;DR: On August 23, 2026, warp.green’s ERC-20 Bridge application was drained of almost all USDC. The funds have been replenished as part of an agreement with Chia Network, Inc., and the protocol will resume in October 2026 after the fix is validated. After a thorough investigation, we were unable to link the attacker’s wallets to a real identity.

The Bug

The bug was located in the Chia-side warped (wrapped) ERC-20 CAT burner puzzle, which failed to assert that the TAIL of the CAT being burned is a wrapped TAIL. While the wrapped TAIL asserts the right inner puzzle is used when burning, a custom TAIL could be forged to bypass that constraint. An attacker used a custom TAIL of (q) (equivalent to (q . ()), a program that always succeeds and returns no conditions) to generate two messages that looked like warped USDC had been burned. From there, the underlying messaging protocol worked normally, and once enough confirmations had passed, the attacker relayed the messages to Base and Ethereum, draining the ERC20Bridge contracts.

Security

We’ve always regarded security as a priority, and as a result of continuous effort. For the protocol, security issues could arise from two main sources, validators and code.

To minimize the risk of validator key compromise, a frequent issue seen in many similar protocols, validators have been chosen as known teams in the Chia community with an ability to maintain highly secure operations. Everything the protocol does is locked by a 6-of-10 multisig, with sensitive operations (such as updating contract/puzzle implementations) using a cold-key multisig as opposed to the hot multisig employed for messages relays. To combat key loss, all validators sign an attestation every 4 weeks containing the header hash of a recent Chia block, thus proving they still have access to their cold keys.

We’ve also worked towards minimizing code risk. Chia Network, Inc. has reviewed our Chialisp puzzles before launch, and our Solidity contracts have gone through audits from Hacken and Zellic. We documented the protocol in detail and established a clear way to report security vulnerabilities. While efforts have been made to arrange a second Chialisp side audit with Chia Network, Inc.’s support, the plan has been repeatedly delayed due to outside circumstances, and the protocol has instead been kept in Beta until the incident. Additionally, we have received two reports from Chia Network, Inc. generated by their custom in-house AI security harness/scanner, on 23 April 2026 (4 months before the incident) and 5 June 2026 (<3 months before the incident). Each report was screened immediately (within minutes) for high-impact findings and then read in full within 24 hours. Neither flagged this bug or anything in the same class.

Forensics

During the forensics investigation immediately following the attack, we have mapped the flow of funds that allowed the exploit to take place. We have since confirmed this data with multiple external collaborators, and are making it public for transparency and in the hope that more eyes will be more likely to catch opsec errors.

Initial funds were traced to the Monero (XMR) blockchain, which makes further forensics difficult due to its fundamental measures to hide recipient/sender addresses and transaction amounts. From there, funds were bridged through wagyu[.]xyz to an Arbitrum address, and, later, to the main Ethereum address via the Across protocol. Using Mayan Finance, the same address was funded on Base, where it swapped some of its assets to warped Chia (wXCH). From there, the address used the bridge normally to send 1 wXCH to fund a Chia address, from which both drains were performed. Soon after the drains, all funds were converted to ETH and bridged to Ethereum, likely to prevent freezing based on reports from our team. The funds have since been transferred to Tornado Cash in several batches.

Because the initial transaction to Chia used the ‘Welcome kits’ feature of the bridge, which pays the transaction fee required to finish the bridging operation for eligible new accounts on Chia, we were able to recover the attacker’s public IP, as well as several browser fingerprints, on the day of the exploit. Unfortunately, further investigation revealed the IP belonged to Mullvad VPN, a VPN provider with a no-logs policy. The browser fingerprints are also too general to be used to determine additional details about the attacker. We have confirmed the pattern seen in the attack - melting ‘fake’ CATs to trigger the ERC-20 bridge contract to release tokens - does not appear to have been used before.

Timeline

This section contains the reconstructed timeline of major events. Times are UTC+3 (Romania), and all events take place in the year 2026.

  • Aug 23 07:52 - An attacker sent a malicious message draining 85,000 USDC to Base.
  • 08:07 - The message is relayed, and the attacker receives 85,000 USDC.
  • 08:20 - The same actor sends a 2nd message draining 8,000 USDC to Ethereum.
  • 08:34 - The 2nd message is relayed successfully.
  • 08:50 (approx.) - The lead validator, yakuhito, notices the two messages and starts investigating.
  • 09:00 - A notice reporting suspicious transactions and asking validators to pause message signing is sent on a private & secure validator chat.
  • 09:05 - A war room is created with jde5011, dns, maxim_goods, Rigidity, and Acevail.
  • 10:12 - We publicly post that we have identified 2 suspicious transactions.
  • 10:15 - The Chia-side bundle that drained 85,000 USDC on Base is isolated.
  • 11:07 - Initial attack path is decoded, and effort goes into ensuring the other major application that uses the messaging protocol, the CAT Bridge, is unaffected. The CAT Bridge holds >50% of total protocol TVL, so ensuring the funds are safe is a priority.
  • 11:44 - Validators are updated that an exploit was confirmed, that the damage appears limited to 93,000 USDC (the CAT Bridge is safe), and that a war room is investigating the incident.
  • 12:14 - SEAL 911 is contacted to help with incident response. They are a team of volunteers with extensive incident response experience.
  • 12:30 - We publicly post that we have confirmed the malicious transactions were part of an exploit of our protocol.
  • 12:42 - SEAL 911 recommends that we wait for 1-2 days before sending an on-chain message to the attacker. They also advise us to use this time to search for opsec errors in all attacker-related activity.
  • 13:20 - Attack reconstruction reveals that the attacker used the ‘Welcome kits’ feature of the bridge. The service’s server logs reveal an IP address, which, upon further investigation, is unfortunately determined to belong to Mullvad VPN.
  • 17:09 - A validator suggests we should post a more direct announcement that active wUSDC/wUSDC.b offers should be cancelled as soon as possible.
  • 17:24 - Under jde5011’s earlier guidance, a complaint is filed with FBI’s Internet Crime Complaint Center (IC3) about this incident.
  • 17:25 - The announcement that open offers should be cancelled is posted by dexie and re-tweeted by the official protocol account.
  • For the remainder of the day and up until 01:00 the next day (approx.), the forensics investigation continues. Logs of various services and sites are analyzed to uncover more information about the attacker. We isolate 4 User-Agent headers connected to the IP address discovered earlier, but they are not specific enough to help isolate other traffic. Reviewing all service activity over the past days does not lead to more information about the attacker.
  • Aug 24 07:54 - We started discussing viable paths for recovery in the war room.
  • 09:18 - We have publicly posted that the bug used in the exploit has been identified, and that we found no other malicious transactions using a similar mechanism.
  • 15:59 - The final draft for an on-chain message to be sent to the attacker is ready.
  • 17:33 - We publicly announce that we have sent an on-chain message to the attacker.
  • Aug 25 16:19 - We publicly notify users that the attacker sent some of the funds to Tornado Cash. This is an early indication they will not accept our offer of returning 90% of the funds in exchange for us considering their drains to be a whitehat rescue operation.
  • Aug 26 19:51 - We publicly post a clarification about the current situation following the concern of a few community members, which raised the issue of earlier messages not being direct enough.
  • Aug 27 21:34 - We publicly announce that we’re working on an agreement with Chia Network, Inc. to make users whole.
  • Sep 24 10:23 - We publicly announce that the agreement has been finalized and signed. As part of this agreement, missing ERC20Bridge funds were replenished on-chain, repegging wUSDC/wUSDC.b.

Moving Forward

We have evaluated multiple potential solutions to continue operations. As we would like to keep asset identifiers unchanged and avoid a re-deployment, we have opted for an off-chain fix. Validator software will be updated to perform additional validation on all transactions before signing. As part of these changes:

  • Only messages for supported applications, which can be fully validated, will be considered for signing.
  • App-specific checks will run before a message is signed.
  • A special message will be able to halt all validation immediately.

We will use the learnings from this incident, as well as those from the TibetSwap incident, which happened in the same week, to further secure our protocol moving forward.

These changes have been made available for public review here at the time this post-mortem was published. The code patch will be public for at least one week before being merged in order to allow for open review by the broader Chia community. Contributors who have already offered to help will also be asked to review the code during this window. After confirming the fixes, validators will update their software to the updated version, and the protocol will resume after a supermajority of validators has adopted the fix. We expect warp.green to be fully operational in October 2026.

Thanks

We would like to thank the following people for assistance in the war room created shortly after the hack:

  • Justin England (jde5011 - VP of Security at Chia Network, Inc.)
  • dns (founder of dexie.space; initial advisor of the project & validator)
  • Bram Vollebregt (maxim_goods - Senior Security Engineer at Chia Network, Inc.)
  • Brandon Haggstrom (Rigidity - creator of Sage wallet & chia-wallet-sdk; Software Engineer at Chia Network, Inc.)
  • Andreas Greimel (Acevail - founder of MintGarden; initial advisor of the project)

Additionally, we would like to thank more parties for assistance in incident response and the ensuing forensics investigation, including:

Lastly, we would like to thank all parties contributing to make the protocol secure, and specifically to Chia Network, Inc. for their additional support to make users whole.

Published on October 1, 2026