The word "bridge" is doing you a disservice
Picture a bridge over a river: something drives onto it, crosses, and arrives on the other side. That mental model is roughly how most people imagine a crypto bridge working — you send USDC on Ethereum, it "goes" to Solana, and now you have USDC on Solana.
Nothing like that happens. Blockchains are closed systems. Ethereum has no way to read Solana's state, verify a Solana transaction, or send a message that Solana's validators will trust on their own. Each chain is its own island with its own ledger, its own validator set, and its own rules about what counts as truth. There is no wire connecting them.
So when you "bridge" an asset, the asset itself never leaves its home chain. What actually happens is closer to a hostage exchange than a crossing.
What actually happens: lock-and-mint
Here is the real mechanical sequence for moving, say, USDC from Ethereum to Solana:
- You send your USDC to a bridge smart contract on Ethereum.
- That contract locks the USDC — it sits there, untouched, as long as the bridge is functioning correctly.
- The bridge's off-chain infrastructure (validators, relayers, oracles, whatever the design uses) observes that the lock happened and passes a message to the destination chain.
- A corresponding contract on Solana mints a new token — call it "Wrapped USDC" or "USDC.sol" — and sends it to your Solana wallet.
That new token is not the same asset. It is a completely separate token contract, deployed independently on Solana, with its own supply, its own code, and its own trust assumptions. It has no cryptographic link back to the original USDC beyond the bridge's claim that for every unit of wrapped token in circulation, an equivalent unit of real USDC is locked on Ethereum. You are holding an IOU, not the underlying asset.
Redemption runs the sequence in reverse. To get your original USDC back, you send your wrapped tokens to the bridge contract on Solana, which burns them — permanently destroys them, reducing the wrapped supply. That burn event is what authorizes the Ethereum-side contract to unlock and release the original USDC back to you. Some bridges mint-and-burn on both sides instead of lock-and-mint (useful for a token native to neither chain), but the logic is the same: destroy the representation on one side to release the claim on the other.
The wrapped token is only worth anything because the bridge honors this exchange in both directions. Take away that promise and you're left holding a token that looks identical to the real thing but has nothing behind it.
Why bridges concentrate risk instead of spreading it
This is the part that makes bridges structurally dangerous in a way that, say, a decentralized exchange isn't. Every unit of wrapped asset in circulation is backed by collateral sitting in one place: the lock contract on the source chain. If a bridge has facilitated $2 billion of lock-and-mint activity, there is a single contract (or a small cluster of them) holding roughly $2 billion in assets.
That's an unusually concentrated target. Compare it to the assets sitting across thousands of individual wallets, or spread across a lending protocol's many collateral positions. A bridge contract is one address, one codebase, and often one set of keys, guarding the entire backing for every wrapped token issued through it. Break the contract, or compromise the keys that control it, and you don't just steal from one user — you drain the collateral backing an entire wrapped-asset supply across every chain it was minted on.
This is a large part of why bridge exploits have repeatedly ranked among the largest thefts in crypto's history, generically speaking — not because the underlying idea is uniquely flawed, but because the economics of "concentrate a huge pool of value behind one piece of infrastructure" are exactly the economics that attract attackers with the most resources and patience.
The trust models, and what you're actually relying on
Not all bridges make the same tradeoffs. It helps to think of them on a spectrum.
- Custodial / federated bridges. A known, fixed set of parties — often a multisig of some number of signers — controls the lock-and-mint process directly. When you bridge an asset, you are trusting that this specific group won't collude, won't get their keys compromised, and will keep operating indefinitely. This is simple to build and cheap to run, which is why it's common, but it concentrates trust in identifiable humans and their key management practices.
- Light-client / verification-based bridges. Instead of trusting a fixed group, the destination chain runs logic that cryptographically verifies proofs of what actually happened on the source chain — effectively letting one chain "read" the other's consensus in a verifiable way. This is closer to trustless, since there's no single party who can simply decide to mint or unlock fraudulently. It's also considerably more complex to build correctly and more expensive to operate, which is why it's less common than federated designs, especially for chains with very different architectures.
- Hybrid and optimistic models. Some bridges use a small set of watchers who can challenge fraudulent messages within a window, borrowing ideas from optimistic rollup design. This trades some of the cost of full verification for a delay period during which bad messages can theoretically be caught.
The practical question for any bridge you use isn't "is it decentralized" as a yes/no — it's "how many distinct things would need to fail or collude before my funds are at risk, and how well have those things been tested."
The depeg scenario, and why it's sneaky
Say a bridge's lock contract gets drained — through a code exploit, a compromised validator set, whatever the mechanism. The wrapped token on the destination chain doesn't disappear, and its contract doesn't throw errors. It keeps functioning exactly as before: transferable, tradeable, showing up in wallets with the same ticker and the same decimal places. The only thing that's changed is invisible to the token contract itself — the collateral that was supposed to back it is gone.
The market figures this out fast, usually well before any official announcement. The wrapped asset starts trading at a discount to the real thing on secondary markets, because holders start racing to exit before liquidity dries up further. A wrapped token that's supposed to be worth $1 might trade at $0.60 or lower, not because anything is wrong with the token contract, but because the promise behind it is broken. This is the bridge equivalent of a stablecoin depeg, and it can happen to an asset that most users never thought of as having "peg risk" at all — they just thought of it as USDC, or ETH, on a different chain.
This is also why wrapped-asset prices are worth checking against the native asset's price periodically if you're holding meaningful amounts, particularly on newer or lower-volume bridges. A persistent, growing discount on a supposedly 1:1 wrapped asset is a signal something is off with the backing, well before any official confirmation.
What to actually check before bridging real money
Treat bridging as a distinct risk decision from holding the asset itself — you're not just taking on the target chain's risk, you're taking on the bridge's risk on top of it. A few concrete things worth checking before moving anything beyond trivial amounts:
- Who or what controls the lock-and-mint process. Is it a multisig? How many signers, and who are they? Or is it a verification-based design — and if so, has the verification logic been through meaningful external review?
- How much value the bridge currently secures. A bridge holding a large amount of locked collateral is a bigger, more attractive target, and also a signal that a lot of other people have already made the same trust decision — useful information, but not a guarantee.
- How widely recognized the resulting wrapped asset is. A wrapped token that's deeply integrated across DEXs, lending markets, and other protocols on the destination chain is generally easier to exit even under stress, because there's real liquidity for it. An obscure wrapped variant with one thin trading pair can leave you stuck holding an asset nobody wants to buy, even if the bridge itself is fine.
None of this eliminates the risk — it just tells you roughly how much risk you're accepting and whether it's proportionate to what you're moving. For anything beyond a small, disposable amount, that's worth five minutes of checking before you click confirm, not after.