← Latest papers
💻 computer science

Exploiting Liquidity Exhaustion Attacks in Intent-Based Cross-Chain Bridges

This paper identifies and analyzes a new class of "liquidity exhaustion attacks" against intent-based cross-chain bridges, demonstrating through a large-scale simulation of 3.5 million intents that protocols like deBridge are vulnerable to profitable rational attacks while others face availability risks under Byzantine conditions, ultimately proposing an optimized strategy that significantly reduces attack costs.

Original authors: André Augusto, Christof Ferreira Torres, André Vasconcelos, Miguel Correia

Published 2026-02-23
📖 6 min read🧠 Deep dive

Original authors: André Augusto, Christof Ferreira Torres, André Vasconcelos, Miguel Correia

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine a world where you want to send money from one country to another instantly. In the old banking system, you'd have to wait days for the money to clear. But in the new "Intent-Based" crypto world, you just say, "I want to send $100 to my friend in Japan," and a special group of people called Solvers instantly hand over the cash to your friend.

Here's the catch: The Solvers have to use their own money to pay your friend immediately. They only get their money back from the original bank later, after a security check that takes some time.

This paper is about a new way to hack this system by draining the Solvers' wallets so they run out of cash and can't help anyone else.

The Cast of Characters

  • The User: You, just trying to move your crypto.
  • The Solver: Think of them as a high-speed courier or a pawn shop owner. They have a vault of cash ready to lend out instantly. They make a tiny profit on every deal.
  • The Bridge: The digital highway connecting different blockchains (like Solana to Ethereum).
  • The Attacker: A hacker who wants to either steal money or just cause chaos.

The Attack: "The Liquidity Exhaustion"

Imagine a busy pawn shop (the Solver) that has $10,000 in cash in the register. They lend money to customers instantly, but they don't get paid back for 2 hours.

The Attack Strategy:
A hacker walks in and starts asking for loans.

  1. The Flood: The hacker submits hundreds of fake or real requests to borrow money, all at once.
  2. The Drain: The pawn shop lends out all its $10,000 to the hacker.
  3. The Lock: Now the pawn shop is empty. The hacker's money is "locked" in the system, waiting for the 2-hour security check to finish before the pawn shop gets paid back.
  4. The Chaos: While the pawn shop is waiting for its money back, honest customers walk in and ask for loans. The pawn shop has to say, "Sorry, we're out of cash." The honest customers' transactions fail or get stuck.

The hacker wins in two ways:

  • Rational Attack (Profit): The hacker borrows the money, sells it, and makes a profit before the system realizes what's happening.
  • Byzantine Attack (Chaos): The hacker doesn't care about profit; they just want to shut down the pawn shop so no one else can use it.

What the Researchers Found

The authors looked at 3.5 million real transactions across three major crypto bridges (Mayan, Across, and deBridge) to see how this plays out in the real world.

1. The "DeBridge" is Vulnerable (The High-Interest Pawn Shop)

  • Scenario: This bridge pays its Solvers a decent profit (about 1.1%).
  • Result: It's like a pawn shop with a high profit margin. Because the profit is good, hackers can easily find a way to borrow the money, make a profit, and leave the shop empty. The researchers found that in many cases, this attack would actually make the hacker money.

2. The "Across" Bridge is a Fortress (The Low-Margin Giant)

  • Scenario: This bridge pays Solvers almost nothing (0.018%), but it has a massive vault of cash ($8.9 million).
  • Result: It's like a giant bank with a tiny profit margin. Even if a hacker tries to drain it, the cost to do so is too high, and the profit is too low to be worth it. The bank is too big and the profit too small for the attack to work.

3. The "Mayan Swift" is a Mixed Bag

  • Scenario: It's somewhere in the middle.
  • Result: Usually safe, but if the market gets crazy (stress test), or if the hacker targets specific small transactions, they can sometimes find a way to drain the liquidity.

The "Targeted" Hack (The Sniper)

The researchers also found a smarter way to attack. Instead of trying to drain the entire vault, the hacker looks at who is competing for the money.

  • Analogy: Imagine a poker game. Usually, 10 people are playing. But if you only bet on a specific type of hand (e.g., "Aces only"), maybe only 2 people are playing that hand.
  • The Hack: The attacker realizes that for small transactions, only a few Solvers are interested. So, instead of needing $10,000 to drain the whole system, they only need $1,000 to drain the specific Solvers who care about small transactions.
  • Impact: This reduced the cost of the attack by up to 90%. It's like breaking into a house by picking a small window instead of smashing the front door.

Why Should You Care?

You might think, "If the hacker loses money, why does it matter?"

  1. Service Outages: Even if the hacker doesn't make a profit, they can shut down the bridge for everyone else. Imagine your bank suddenly saying, "We can't process any transfers for the next hour."
  2. The Domino Effect: Many apps (like crypto exchanges) rely on these bridges. If the bridge breaks, those apps break too.
  3. Trust Issues: If people think a bridge is unreliable, they stop using it, and the whole ecosystem suffers.

The Solution?

The paper suggests a few ways to fix this:

  • Pay Solvers Less (But More): If the profit margin is too high, it attracts hackers. If it's too low, no one wants to be a Solver. We need a "Goldilocks" zone.
  • Get Paid Back Faster: If the security check takes 2 hours, the attack window is 2 hours. If we can get it down to 10 minutes, the hacker has less time to cause damage.
  • More Solvers: If you have 100 Solvers instead of 5, it's much harder to drain everyone's wallet at once.
  • Auto-Replenish: Solvers should have a robot that automatically puts more cash in the vault the moment it gets low, so there's no "empty" moment to exploit.

The Bottom Line

This paper reveals that in the new world of instant crypto bridges, running out of cash is a security risk. Just like a bank can be robbed not by breaking the vault, but by tricking the teller into giving away all the cash at once, these bridges can be "robbed" by flooding them with requests. The fix isn't just better code; it's better economics and faster payment systems.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →