Qubit Finance disclosed on January 28, 2022 that its QBridge deposit function had been exploited, allowing an attacker to mint unbacked qXETH and withdraw assets from the protocol’s lending pools. Qubit disabled supplying, redeeming, borrowing, repaying and bridge operations while it investigated.
Contemporaneous security firms valued the withdrawn assets at approximately $80 million. That estimate made the incident one of the year’s largest decentralized-finance losses known as of January 28, but it was not an audited dollar balance. It depended on token prices and asset inventories observed around publication.
The chronology requires a qualification. Qubit’s report was published on January 28, while its UTC timeline placed the attack transactions late on January 27. The January 28 development was therefore the protocol’s public disclosure, technical explanation and emergency response to an exploit that had begun shortly before the UTC date changed.
Sixteen deposits without the expected assets
Qubit reported that 0.8887725 ETH reached the attacker’s account at 21:18:55 UTC on January 27. Between 21:34:01 and 21:50:41 UTC, the attacker submitted 16 deposit transactions to QBridge on Ethereum. Between 21:36:32 and 21:51:02 UTC, Qubit’s relayer submitted 16 corresponding `voteProposal` transactions to the bridge contract on Binance Smart Chain, then commonly abbreviated BSC.
Those messages caused qXETH to be minted on BSC. The attacker supplied that qXETH as collateral and withdrew liquid assets from Qubit. The critical problem was that the bridge accepted messages representing ETH deposits even though the expected value had not actually entered the Ethereum-side contract.
The timeline establishes the sequence reported by Qubit. It does not independently identify the person controlling the attacker address or prove any motive beyond the transaction pattern.
The zero-address failure
Qubit said the attacker called the general `deposit` function rather than the newer `depositETH` function. Inside `QBridgeHandler`, the relevant token address resolved to the zero address. The bridge’s `safeTransferFrom` operation did not fail when called against that address, so execution continued and emitted a deposit event despite no corresponding token transfer.
The protocol’s relayer treated those events as valid cross-chain deposits and authorized qXETH minting on BSC. CertiK and SlowMist independently described the same essential failure: the ordinary-token path did not reject the zero address, while the native-ETH and token deposit paths could produce the event used by the bridge’s downstream logic.
This was more than an isolated faulty call. The bridge converted an Ethereum-side validation failure into apparently valid collateral on another chain. Qubit’s lending market then accepted that collateral under its existing rules, allowing the attacker to remove assets with independent market value.
What the $80 million estimate measured
CertiK reported that the attacker obtained 77,162 qXETH, which it valued at $185 million, then used it to borrow and convert 15,688 wrapped ether valued at $37.6 million, 767 BTCB valued at $28.5 million, approximately $9.5 million in stablecoins, and roughly $5 million in CAKE, BUNNY and MDX.
Those reported components total approximately $80.6 million, a Coinburn calculation from CertiK’s rounded figures. The widely reported $80 million loss was therefore an approximate contemporaneous valuation of the assets removed, not the nominal value of the unbacked qXETH. Token prices could change continuously, and the cited reports did not provide a single synchronized pricing timestamp or an independently audited recovery value.
Emergency controls contained further activity
Qubit said on January 28 that it was tracking the exploiter, monitoring affected assets, cooperating with security and network partners including Binance, and offering the maximum bounty available under its program. Claims remained available, but the protocol’s principal lending and bridge functions were disabled until further notice.
The incident illustrated a structural bridge risk visible on January 28: validation, relaying, minting and lending could each behave as designed locally while their composition accepted collateral that was never funded. The event-day record established the exploit and immediate containment measures. It did not establish asset recovery, attacker attribution, reimbursement or the protocol’s eventual operating status.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

