We met at the bridge.
Not metaphorically - Moolah had picked a literal bridge, an arched stone footbridge over the small river that ran through the south end of Ueno Park, and she was sitting on the railing when we arrived, looking down into the water. The river was half-frozen at the edges. A single carp moved sluggishly under the ice in a darker channel of open water.
"I wanted us to be on a bridge," she said, "for what we're about to talk about."
"That's slightly on the nose," I said.
"Sometimes the metaphor and the place are the same thing. Today is one of those days."
We started walking. The stones were slick in places where the morning sun hadn't reached, and Dev nearly went down twice in the first thirty seconds. Moolah paused mid-bridge - at the highest point of the arch - and turned to face us.
"Today's lesson is about cross-chain bridges. They are the most dangerous structures in DeFi. They are also, by some measures, where the largest amount of money has ever been stolen on the blockchain. We are going to walk across this physical bridge slowly, while I tell you why."
"Lead on."
She turned and continued walking. We followed.
"First - the problem. There is not just one blockchain. There's Ethereum, which we've talked about most. There's Bitcoin. There's Solana, Avalanche, Polygon, Arbitrum, Base, dozens of others. Each is a separate world with its own ledger, rules, and users. They cannot talk to each other directly. A token sitting on Ethereum cannot move to Solana, because Solana's nodes do not run Ethereum's software, and Ethereum's nodes do not know that Solana exists."
"Like two cities on opposite sides of a river that doesn't have a bridge."
"Like two cities," Moolah agreed, "on different rivers, in different countries, where neither speaks the other's language. The blockchains are not just unconnected - they are mutually opaque. Each is a sealed room, in the sense we discussed last week, but now extended to entire networks. Ethereum cannot see what's happening on Solana. Solana cannot see Ethereum. There is no shared notebook between them."
She paused near the apex of the bridge. "And yet - people want to move tokens between chains. Maybe for cheaper gas. Maybe a chain has a protocol they want to use. Maybe they want to diversify across ecosystems. The demand is enormous. Billions of dollars of demand. So someone built bridges."
"How does a bridge work?"
"There are several designs, but the most common is lock-and-mint. Imagine you have a token on Ethereum. You want it on Solana. You send your token to a bridge contract on Ethereum. The bridge locks it up - your token is now sitting in the bridge's vault on the Ethereum side, frozen. Then, the bridge sends a message to its counterpart on Solana, which mints a wrapped version of the token - a Solana-native version that represents your locked Ethereum token. You now hold the wrapped version on Solana. The original is still in the vault on Ethereum, sleeping."
"And to come back?"
"You burn the wrapped version on Solana. The bridge sees the burn, sends a message back to Ethereum, and the Ethereum contract releases your original token from the vault. Lock and mint, then burn and release. The bridge holds the real asset. The wrapped version travels."
We had reached the far side of the bridge. Moolah stopped, turned, and looked back at the structure.
"Now," she said, "consider what the bridge is. At any given moment, the bridge contract on Ethereum is holding the entire collateral of every token that has ever crossed it and not yet come back. Sometimes hundreds of millions of dollars. Sometimes billions. All sitting in one place. All controlled by one set of code. All defended, in many cases, by a small group of operators who run the message-passing infrastructure."
"That sounds -"
"Like a target," Moolah said. "Yes. It is the most concentrated honeypot the industry has ever built. A single bridge can hold more value than most banks. And unlike a bank, it has no FDIC insurance, no security guards, no vault, no police. Just code, and a small set of operators, and the cryptographic signatures that say this message came from this validator. Compromise the validators, or the code, and you can drain the entire vault."
"Has that happened?"
"Many times. The list is long and unpleasant. There was a bridge called Wormhole, in early 2022 - about three hundred and twenty million dollars stolen, in a single afternoon, through a bug in how it verified messages from one chain to another. The hacker exploited the verification, minted wrapped tokens on one side without locking real tokens on the other, and walked away with the difference. Nomad, later that summer - about two hundred million, in what became known as the first decentralized hack, because the initial exploiter's transaction was so simple that hundreds of bystanders copied it within an hour and helped drain the bridge themselves. And there was -"
She paused. The tone shifted slightly.
"There was Ronin. We will get to Ronin properly in the spring. For now I will only say: it was a bridge. It had nine validators. Five of them were enough to authorize any transfer. The attackers, by means I will not yet explain, gained control of five validator keys. They authorized themselves a transfer of six hundred million dollars. The bridge sent the money. The validators were mostly run by one company. The bridge was, in a particular sense I will explain later, defended by exactly five doors, and the thieves had keys to all five."
Dev was looking at the river. "Why does anyone use bridges, then?"
"Because the alternative is worse. Without bridges, the chains are isolated, and every chain must duplicate every protocol from every other chain, and users are stuck wherever they happen to start. With bridges, the system has connective tissue. The connective tissue is dangerous, but it makes everything else possible. The bridges are the price of the multi-chain world."
"Are there safer designs?"
"There are several. Native bridges, run by the chains themselves rather than third parties - for example, the bridge between Ethereum and certain Layer 2s, which we'll discuss next week - tend to be safer because they're built on the same security model as the chain. Light client bridges, where one chain runs a small piece of the other chain's verification logic directly, are technically harder to attack but expensive to build and rare in practice. There is a category of newer bridges using more decentralized validator sets, fraud proofs, and cryptographic schemes that make them more resilient. The technology is improving. But the basic problem - that a bridge holds enormous reserves, and those reserves are a target - does not go away."
I wrote in the notebook. Bridges = lock and mint between chains. Hold enormous reserves. Most-hacked category in DeFi history. Wormhole, Nomad, Ronin - names. Safer designs exist; the basic risk does not.
"So what should I do, practically?"
"If you must use a bridge, use the canonical one - the one run by the chain you're going to, not a random third party. Use small amounts when possible. Don't leave funds on a chain you don't intend to use. And remember that wrapped assets are not the same as the original - if the bridge fails, the wrapped version becomes worthless even though the original still exists, locked forever in the dead vault. The wrapped version is, in some sense, only as solid as the bridge."
"Like a paper currency that's only worth as much as the gold in the vault that backs it."
Moolah looked at me with something close to satisfaction. "Yes. Exactly that. The wrapped token is a banknote. The bridge is the gold standard. The vault is the bridge contract. If the vault is robbed, the banknote becomes - what's the word - a ghost."
We had walked off the far side of the bridge by now and were standing on the path beyond. The bridge looked, from this side, exactly like every other bridge we had ever seen - small, arched, ordinary, unremarkable. A young couple was crossing it from the other direction, paying it no mind.
"That's the thing," Moolah said quietly. "Most bridges look ordinary, until they are robbed. Then everyone looks at them and asks how they were ever trusted. The answer is always the same. They were trusted because the alternative was inconvenience. People will accept a great deal of risk to avoid a little inconvenience. They always have. The Pony Express rode through hostile countries for the same reason. The convenience was the product. The risk was the price."
She slipped down to the riverbank, dipped a paw in the cold water, and looked at it as if checking the temperature.
"Same place next week?" I asked.
"Different place. Train station. Rush hour. Bring patience."
She slid down into the water before either of us could ask why a train station, and I tucked the notebook back into my coat pocket and turned to head home, the bridge behind us looking, against my will, slightly less ordinary than it had a half hour before.
Next: Layer 2 - Faster, Cheaper, More Complicated

