The first article in this series described how the largest crypto losses keep coming from the messaging layer of bridges rather than from broken token code. This article asks a harder question. Are these failures bad luck that better engineering will eventually fix, or are they a property of the design itself? The answer matters because it determines whether the right response is a more careful bridge or a different architecture. The evidence points to the second. The dominant lock and mint model does not merely carry risk. It concentrates risk by construction, turning a single breach into simultaneous insolvency across every chain the asset touches.
The Lock and Mint Model in Plain Terms
Recall the basic mechanism. To move an asset from chain A to chain B, you lock the original in a contract on chain A, and the bridge mints a wrapped representation on chain B. The wrapped token is a claim. It says, in effect, there is one real unit locked on chain A that this token can be redeemed for. As long as that statement is true, the wrapped token can trade, settle, and serve as collateral on chain B as if it were the real thing.
The entire value of the wrapped token therefore rests on two conditions holding at all times. First, the collateral on chain A must remain locked and intact. Second, the bridge must only ever mint new wrapped tokens when a genuine deposit has occurred. Break either condition and the wrapped supply on chain B exceeds the collateral backing it. At that moment every holder of the wrapped token is holding a fractional claim on a vault that no longer covers it, and there is no orderly way to decide whose claim is good.
Inheriting the Wrong Security
Here is the structural problem stated plainly. A wrapped asset does not inherit the security of the chain it lives on. It inherits the security of the bridge that minted it. A wrapped bitcoin on a smart contract chain is not protected by Bitcoin's proof of work or by the destination chain's consensus. It is protected only by whatever process decides when to mint and burn it, which is the validator or verifier set of the bridge.
This is the gap that catches institutions used to thinking in terms of issuer risk and custody risk. With a wrapped asset there is a third layer underneath both: the bridge's trust assumption. You can hold a perfectly sound underlying asset issued by a reputable party and custodied correctly, and still lose everything if the bridge that wrapped it for use elsewhere is compromised. The Kelp DAO drain in April 2026, roughly $292 million released by a forged cross-chain message through a single verifier, was exactly this failure mode. The staked ether was real. The representation moving across chains was only as sound as one attestation.
One Breach, Every Chain
What makes the wrapped model concentrate rather than merely carry risk is reach. Bridges exist to put an asset everywhere at once. A single wrapped asset is frequently minted across many destination chains from one pool of locked collateral. In the Kelp DAO case, the affected wrapped ether was reported stranded across roughly 20 chains. When the backing is compromised, the loss does not stay on one chain. Every wrapped copy on every chain becomes an unbacked claim simultaneously, and any protocol that accepted those copies as collateral inherits the hole.
This is the opposite of how risk is supposed to behave in a resilient system. A well-designed financial system isolates failures so that a problem in one venue does not automatically become a problem everywhere. The lock and mint bridge does the reverse. It takes a single point of failure, the backing pool and the validators guarding it, and propagates its compromise outward to every market that trusted the wrapped representation. One forged message does not cause one loss. It causes as many losses as there are chains and protocols downstream.
A Category Property, Not an Accident
If this were occasional misfortune, the incidents would be scattered randomly across attack types. They are not. The Chainalysis review of 2022 found roughly $2 billion stolen across 13 separate cross-chain bridge hacks, about 69 percent of everything stolen in crypto that year. The largest individual events, Ronin at roughly $625 million, Wormhole at about $320 million, and Nomad at roughly $190 million, were all failures of the mint authorization or the validator set, not of the wrapped token's own code. Four years later, PeckShield counted roughly $328.6 million drained from cross-chain bridges across eight major incidents in 2026, with the Kelp DAO event leading. The same mechanism keeps producing the same outcome because the mechanism is the cause.
When a single design accounts for the majority of losses in a category year after year, the conclusion is not that the engineers were careless. Many of these were well-funded, audited, reputable systems. The conclusion is that concentrating the integrity of an asset into a small trusted attestation layer, and then replicating that asset across many chains, is an inherently fragile arrangement. The wrapped token's convenience and its fragility are the same property viewed from two angles.
The Alternative Worth Naming
The contrast that follows from all of this is between an asset that is a copy and an asset that is native. A wrapped token is a synthetic copy whose integrity depends on a bridge. A native asset exists directly on its settlement layer, where its supply and ownership are recorded at the base of the chain rather than as a representation backed elsewhere. On a chain whose base layer tracks ownership explicitly, the supply of an asset can be audited directly, and there is no separate backing pool that can be drained out from under the holders.
That distinction is the hinge of this series. If the largest losses come from synthetic copies held behind a trusted validator set, then the durable fix is not a stronger validator set. It is not minting the copy in the first place. For a speculative token chasing presence on every chain, the trade that the wrapped model offers, maximum reach in exchange for concentrated trust, can look worthwhile. For a regulated stablecoin, a tokenized fund interest, or any instrument whose entire premise is a trustworthy record of who owns what, it is the wrong trade, because the thing being put at risk is the record itself.
The final article in this series takes up that alternative directly: what native settlement means in practice, how value can move between chains without a wrapped copy, and where Bitcoin-native infrastructure fits for institutions that cannot afford to have one forged message unwind their holdings.
This article is for informational purposes only and does not constitute investment advice.
Mintlayer Web Services provides Bitcoin-native issuance and settlement infrastructure that keeps assets native rather than wrapped behind a bridge. Learn more →