Wormhole returned its cross-chain network and Portal token bridge to service on February 3, 2022, after Jump Crypto supplied 120,000 ether to replace collateral compromised in an exploit. The recapitalization restored full backing for Wormhole-wrapped ETH, according to the protocol’s incident timeline, but it did not mean the attacker had returned the stolen assets.

The distinction mattered. Wormhole allowed assets and messages to move between otherwise separate blockchains, including Ethereum and Solana. Its wrapped ether on Solana was intended to represent ether held against it elsewhere. The exploit temporarily broke that relationship, creating a risk that applications accepting the wrapped asset could be left holding claims without matching collateral.

From exploit to recapitalization

Wormhole’s later official incident report placed the initial exploit at 18:24 UTC on February 2, 2022. It said an unidentified attacker exploited a vulnerability in the Solana-side contract and minted 120,000 uncollateralized Wormhole-wrapped ETH. The attacker then transferred 93,750 of those units through the bridge to Ethereum and redeemed them for native ETH, while the remainder was exchanged for assets on Solana.

The protocol’s contributors detected the discrepancy at 19:07 UTC and began an incident response. The report said safeguards were introduced during the early hours of February 3 and that the required governance approval was completed at 05:53 UTC. Consensus to restart the network was reached at 11:27 UTC.

At 13:08 UTC on February 3, Jump Crypto replenished the relevant contract with 120,000 ETH. Wormhole brought the network and Portal bridge back online at 13:29 UTC and publicly announced the restoration shortly afterward. Jump Crypto confirmed its role later on February 3.

Jump subsequently said it had decided to support the project soon after recognizing the exploit and had acquired 120,000 ETH in the open market before moving it to the bridge. That statement establishes the source and purpose of the replacement capital; it does not establish recovery of the attacker’s proceeds.

Why the intervention mattered

The refill prevented Wormhole’s wrapped ETH from remaining undercollateralized. That reduced the immediate danger that users would race to exit the asset or that Solana applications relying on it as collateral would inherit a balance-sheet shortfall.

The event also demonstrated how bridge security could transmit risk between networks. A defect in one chain’s verification path was capable of producing an apparently valid asset that could be redeemed against reserves on another chain. Wormhole’s recapitalization contained the immediate accounting problem, but it could not undo the verification failure that created it.

Contemporaneous dollar estimates were necessarily approximate. Chainalysis valued the 120,000-unit exploit at more than $320 million, while Elliptic placed it around $325 million. Those figures applied contemporaneous ETH prices to the asset quantity and varied with price timing and methodology; they were not proceeds established through a sale or a single official market close. Crypto trades continuously, and no universal closing price governed the calculation.

Elliptic reported that 93,750 ETH remained at the attacker’s Ethereum address at the time of its analysis. The continuing possession of those assets is why “restored” should be read as restored collateralization and service, not recovery from the attacker.

What was known on February 3

By the end of February 3, Wormhole had announced that the bridge was operational and fully backed, and Jump Crypto had acknowledged providing the replacement ETH. The protocol had not yet published its complete incident report, so the detailed technical sequence available on February 3 remained provisional.

Later context

Wormhole’s subsequent incident report supplied the precise UTC timeline and described the missing verification check. Jump Crypto’s February 11 explanation added that it had purchased the replacement ETH in the market. These later records clarify the February 3 development without changing what the restoration announcement established on that date.

Primary sourceWormhole — Wormhole Incident Report

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.