Wormhole confirmed on February 2, 2022 that its cross-chain network had been exploited for 120,000 wrapped ether, or wETH. The protocol stopped operating while contributors investigated and said ether would be added to restore one-to-one backing. That assurance was also an acknowledgment of the immediate institutional problem: tokens presented as claims on ether no longer had enough corresponding collateral after the unauthorized transfers.
The event was unusually consequential even by the standards of decentralized-finance failures. Wormhole connected applications and liquidity across networks including Ethereum and Solana. Its design depended on a group of guardians attesting that an action had occurred on one chain before a corresponding representation could be created or released on another. The exploit demonstrated that a defect in the destination-chain verification path could defeat that model without compromising Ethereum itself.
What was established on February 2
Wormhole’s public updates first described maintenance for a potential exploit and later confirmed the 120,000-wETH figure. Contemporaneous blockchain-intelligence reporting from TRM Labs said approximately 93,750 of the affected units had been transferred to one Ethereum address. TRM characterized the attack as a bypass of a signature-verification step that allowed the attacker to spoof authority on Solana.
Dollar estimates were necessarily approximate. TRM valued 120,000 wrapped ether at more than $324 million in its February 2 report, while contemporaneous reporting elsewhere placed the amount near $323 million. Those figures were mark-to-market estimates for the ETH-linked instrument around the incident window, not sale proceeds, an audited accounting loss or a universal exchange closing price. Crypto trades continuously, and the cited reports did not disclose a common venue, price composite or precise valuation timestamp.
The distinction between the 120,000 wETH created on Solana and native ETH released on Ethereum also mattered. Wrapped assets are representations used by applications on another network. The incident did not create new native ether or alter Ethereum’s ledger rules. It caused Wormhole’s contracts to treat an unauthorized cross-chain message as valid, allowing unbacked wrapped units to be minted and part of their value to be redeemed against assets held on the Ethereum side.
Why the bridge model mattered
A bridge must translate events between blockchains that do not independently verify one another’s complete state. Users therefore depend on the bridge’s contracts, message-validation logic, upgrade process and operators in addition to the security of each underlying chain. On February 2, Wormhole’s confirmation showed that the bridge layer itself could become the point at which otherwise valid assets were put at risk.
The episode also exposed a collateral problem rather than only a temporary service outage. Unless the unauthorized assets were returned or the reserve gap was filled, holders and applications relying on Wormhole-wrapped ether faced uncertainty about redemption. Wormhole’s event-date statement promised replenishment, but on February 2 that remained a stated remediation plan rather than a completed, independently verified restoration.
Later context, clearly separated
Wormhole’s subsequently published incident report placed the unauthorized mint at 18:24 UTC on February 2. It said the attacker tricked the Solana-side contract into minting 120,000 uncollateralized Wormhole-wrapped ETH, sent 93,750 back to Ethereum for redemption and exchanged the remainder on Solana. The report attributed the failure to inadequate validation of the instruction-sysvar account used during signature verification.
Those technical details clarify the record but were not all established in Wormhole’s first public notice. Later protocol documentation cited the incident when explaining a governor mechanism intended to delay exceptionally large transfers. Neither the later repair nor replenishment should be projected backward as completed on February 2, when the confirmed facts were an exploit, a halted network, a 120,000-wETH shortfall and an announced plan to restore backing.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

