June 24, 2022: Harmony confirms that its Horizon bridge — the cross-chain service moving assets between Ethereum and other networks — has been drained of roughly $100 million after attackers compromised the multisignature wallet controlling the bridge’s vault. The mechanics were as simple as they were devastating: Horizon’s bridge contracts were governed by a 2-of-5 multisig, meaning an attacker who obtained just two of the five keys could authorise arbitrary withdrawals — and that is exactly what happened, with transactions executed on the morning of June 23 (UTC) and disclosed by Harmony CEO Stephen Tse the following day. The crypto-security community’s response was less about the exploit sophistication than the design: a $100M+ custody surface protected by a 2-of-5 threshold had abandoned the security posture that multichain custody demands, and the theft joined a brutal 2021–2022 run of bridge hacks (Ronin’s $625M in March, Wormhole’s $325M in February) that collectively made cross-chain bridges the single richest attack surface in crypto. The laundering trail — Tornado Cash, later Railgun, eventual cash-out paths — and the January 2023 attribution tying the theft to Lazarus Group (the DPRK-linked cluster behind Ronin as well) completed the arc, turning Horizon from a breach story into a case study in custody-design failure and the state-actor economy of funding operations through bridge theft.
The Harmony Horizon bridge hack (June 23, 2022; disclosed June 24) drained ~$100 million in assorted crypto-assets (ETH, BNB, USDT, USDC, DAI and wrapper tokens) from the bridge’s custody by compromising the bridge’s controlling multisig wallet, configured as 2-of-5 — meaning the attacker needed only two of five keys (a threshold criticised as grossly insecure for nine-figure custody). The attacker executed unauthorised withdrawals across a dozen-plus transactions; Harmony’s CEO confirmed within a day and offered a $1M bounty, later a 10% “return for no questions” offer. Attribution: January 2023 — Harmony and the FBI formally attributed to Lazarus Group (DPRK), matching Elliptic/Chainalysis tracing of funds through Tornado Cash and Railgun to DPRK-linked cash-out patterns (the same cluster as Ronin, Axie’s $625M March 2022 bridge theft). Impact: investor losses partially socialised via Harmony treasury reimbursements (minted ONE to cover some user losses — itself controversial); Horizon bridge shut, later relaunched with redesigned custody (4-of-5+ thresholds, hardware-key ceremony, delayed-withdrawal timelocks and monitoring). 2026 lens: Horizon joined the 2022 bridge-hack wave that forced the industry to treat bridge validator sets as bank-vault-grade custody — post-2022 designs standardised on higher thresholds, MPC/hardware-signing ceremonies, withdrawal rate-limits and timelocks, and proof-of-reserve monitoring; and the DPRK attribution cemented bridge theft as a core state-funding channel (by 2023–2025, North Korea-linked actors accounted for billions in crypto theft, per UN and Chainalysis reporting). Defensive lessons generalise beyond crypto: threshold-custody design (2-of-5 for $100M was an unforced error), key ceremony hygiene (the compromise vector was never publicly pinned to exact key-theft mechanism, but the small, geographically/statically distributed signer set was the structural weakness), and transaction monitoring (the withdrawals were sequential and observable — rate-limiting and anomaly pause would have capped losses).
What happened
Horizon was Harmony’s cross-chain bridge, letting users move assets between Harmony’s network and Ethereum (plus BNB Chain and others via wrapped representations). Under the hood — as with most bridges of the era — this meant the bridge contract on each chain held custody of the real assets while a set of validator keys attested to cross-chain messages and authorised withdrawals. That validator set was a five-key multisig with a two-key threshold: any two signatures could move anything.
On June 23, 2022, the attacker(s) — having obtained two of the keys — executed a series of unauthorised withdrawals draining approximately $100 million across ETH, stablecoins, and wrapped assets. The transactions were sequential and on-chain; chain analysts and Harmony’s team detected within hours, and CEO Stephen Tse’s public disclosure came June 24 with the standard post-hack package: investigation launched, exchange partners notified, FBI engaged, bounties offered ($1M for the attacker’s return of funds, and a standing 10%-of-funds “white-hat” offer).
The design criticism arrived even faster than the post-mortems. A 2-of-5 threshold meant the security of $100M+ reduced to the security of any two laptops, HSMs, or hot-wallet setups in the validator set — and the structural weakness was that the signer set was small, static, and not architecturally separated. In January 2023, Harmony and the FBI formally attributed the theft to Lazarus Group, the DPRK-linked cluster by then notorious for the Ronin theft; blockchain-analytics tracing (Elliptic, Chainalysis) had followed the funds through Tornado Cash initially and Railgun later, matching established DPRK cash-out patterns. By then the bridge-hack accounting was grim: Ronin ($625M), Wormhole ($325M), Poly Network’s 2021 $611M (returned), and Horizon ($100M) — 2022’s bridge losses alone exceeded $2 billion, and the majority of the largest were custody-design failures rather than smart-contract bugs.
Cross-chain custody anatomy
Bridge trust model (2022-era, Horizon-class):
USERS
| deposit ETH/USDT/... |
v
ETHEREUM VAULT CONTRACT HARMONY SIDE
(custody of real assets) <--> bridge mint/burn
^ of wrapped assets
| withdrawal auth |
VALIDATOR MULTISIG (2-of-5!)
key1 key2 key3 key4 key5
\ | | | /
any TWO keys == full
control of vault
ATTACK (June 23 2022):
attacker obtains key_a + key_b
-> signs dozen+ withdrawals
-> $100M out in hours
(exact key-compromise mechanism
never publicly pinned; small
static signer set = structural
weakness)
LAUNDERING:
out to Ethereum -> Tornado Cash
-> later Railgun -> DPRK-linked
cash-out patterns
ATTRIBUTION: Jan 2023, Harmony+FBI
-> Lazarus Group (DPRK)
(same cluster as Ronin $625M)
WHAT WOULD HAVE CAPPED IT:
4-of-5+ threshold
hardware/MPC signing ceremony
withdrawal rate-limits
timelock + anomaly pause
Impact and numbers
| Metric | Value |
|---|---|
| Date of theft | June 23, 2022 (disclosed June 24) |
| Amount | ~$100 million (ETH, stablecoins, wrapped assets) |
| Victim | Harmony Horizon bridge (Ethereum ↔ Harmony/others) |
| Mechanism | Compromise of 2-of-5 validator multisig → unauthorised withdrawals |
| Attribution | Lazarus Group / DPRK (Harmony + FBI, January 2023) |
| Laundering | Tornado Cash, later Railgun; DPRK-linked cash-out patterns |
| Context | 2022 bridge losses > $2B total (Ronin $625M, Wormhole $325M, Horizon $100M…) |
| Aftermath | Bridge redesigned: higher thresholds, hardware-key ceremony, timelocks, monitoring; partial user reimbursement via treasury (contested) |
Timeline
| Date | Event |
|---|---|
| 2022-02 | Wormhole bridge loses $325M (signer-set/message-verification failure) |
| 2022-03 | Ronin bridge loses $625M to Lazarus (4-of-9 validator compromise — later attributed) |
| 2022-06-23 | Horizon bridge drained: two multisig keys compromised, ~$100M out |
| 2022-06-24 | Harmony discloses; $1M bounty, FBI engaged, exchanges notified |
| 2022 H2 | Funds traced through Tornado Cash; Railgun use later; partial treasury-based reimbursements |
| 2023-01 | Harmony and FBI attribute to Lazarus Group (DPRK) |
| 2023+ | Bridge designs standardise on higher thresholds, MPC/hardware ceremonies, rate-limits, timelocks |
Why it still matters in 2026
Because every layer of the event — the design error, the attacker, and the industry response — became permanent structure. On design: Horizon’s 2-of-5 threshold is now the textbook example of mispriced custody risk, and post-2022 bridge architecture treats the validator signer set as the core security object — thresholds sized to value, keys held in hardware/MPC with geographic and organisational separation, withdrawal rate-limits and timelocks that convert “keys compromised” from catastrophe into incident-with-cap. On the attacker: Lazarus’s bridge campaign (Ronin, Horizon, later others) made DPRK crypto theft a first-order national-security funding channel — by the mid-2020s, UN-expert-panel and Chainalysis reporting put North Korea-linked crypto theft in the billions annually, funding weapons programmes, and bridges and custody endpoints stayed among the richest targets. On industry response: the 2022 wave forced the standardisation that 2026’s cross-chain infrastructure runs on — proof-of-reserve attestation, independent validator sets beyond any single foundation’s control, and monitoring that would have caught Horizon’s sequential withdrawals mid-run. The general lesson travels beyond crypto: wherever a small static set of credentials authorises movement of large value, the system’s true security is the security of its weakest two members. Horizon priced that lesson at $100 million; every subsequent bridge design memo still cites it.
Detection and hardening takeaways
- Size thresholds to value, with margin. 2-of-5 for nine-figure custody (later 4-of-9 failing at Ronin) set the lesson: threshold schemes must be designed against realistic compromise correlation (what if two signers share infrastructure, geography, or personnel?), not against convenience. Post-2022 standard: no bridge or treasury moves eight-plus figures under fewer than four independent, hardware-protected signatures, with value-tiered levels above that.
- Ceremony and separation for signer keys. The Horizon compromise’s exact vector stayed undisclosed, but the structural surface — small, static, operationally similar keys — was the weakness. Hardware/MPC ceremonies, organisational and geographic separation of signers, and scheduled key rotation shrink the two-key-acquisition problem attackers actually solve.
- Rate-limit and timelock large movements. The drain executed as sequential on-chain withdrawals; bridge-class systems now ship withdrawal caps per epoch, timelocked large-exit queues, and circuit-breaker pauses on anomalous outflows — any one of which would have capped Horizon’s loss at a fraction of $100M.
- Monitor custody transactions like a bank watches its vault. Sequential high-value withdrawals from a bridge vault deserved real-time alerting with human-in-the-loop pause authority. Cross-chain systems in 2026 run continuous proof-of-reserve and outflow-anomaly detection precisely because 2022 proved the observable run takes hours — long enough to interrupt.
- Attributes state-actor risk to custody endpoints. The January 2023 attribution confirmed what tracing suspected: nation-state funding operations target the custody layer (Ronin, Horizon, exchange endpoints) precisely because value concentrates there and key compromise scales theft. Threat-model custody infrastructure against patient, resourced, targeted key-compromise — not opportunistic crime.
FAQ
Was this a smart-contract bug like earlier bridge hacks?
No — and that’s what made it instructive. Wormhole’s loss was a message-verification flaw; Ronin’s was validator-key compromise (social-engineering-infrastructure); Horizon’s was multisig-key compromise on a badly configured threshold. The contract behaved as designed; the design priced $100M of custody at two keys. The exploit sophistication was minimal once the keys were had — the security failure was architectural.
Did users get their money back?
Partially and controversially. Harmony used treasury funds (minting ONE, the network token) to reimburse a portion of Horizon losses — a socialisation choice that preserved some user balances but transferred the loss to token holders via dilution, and the coverage was not the full $100M. Full restitution never occurred; the DPRK attribution made recovery effectively nil.
How does Tornado Cash fit in?
As the initial laundering layer — the stolen funds were split and cycled through the mixer to sever tracing, with later movement through Railgun (a privacy-preserving protocol) as enforcement pressure around Tornado grew. The pattern was already DPRK-signature by mid-2022, which is why analytics firms (and, months later, the FBI attribution) converged on Lazarus: the cash-out topology matched their established playbook, and US sanctions on Tornado Cash in August 2022 were partly a response to exactly this class of state-linked laundering.
Are bridges safer now?
Structurally, yes — the 2022 wave forced it. Modern bridge designs deploy higher multisig thresholds with hardware-key ceremonies, MPC signing, rate-limits and timelocks on large withdrawals, independent validator sets, and proof-of-reserve monitoring. But the custody problem is permanent, not solved: value still concentrates at bridge endpoints, state actors still target them (the DPRK bridge/exchange theft campaigns continued through 2023–2025), and each new chain-interconnect pattern re-creates the “small credential set guards large value” junction Horizon made infamous.
