Cyber Incident Victim: Wormhole
Date:
Feb 2022
Location:
United States of America
Summary
Wormhole suffered a security exploit resulting in the theft of 120,000 wrapped Ethereum (wETH). The platform announced immediate measures to replenish the stolen ETH reserves to maintain the 1:1 backing of wETH and committed to restoring normal network operations promptly. No additional operational impacts or technical details of the exploit were disclosed in the initial statement.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On February 2, 2022, the Wormhole network suffered a security breach resulting in the exploitation of 120,000 wrapped Ethereum (wETH). The incident was publicly disclosed via Wormhole's official Twitter account at 10:25 pm that same day, confirming the unauthorized access and loss of funds. The organization immediately initiated emergency measures to address the exploit's financial impact, pledging to deposit equivalent ETH reserves within hours to maintain the 1:1 backing of wETH tokens. Operational recovery efforts commenced concurrently, with teams working to restore full network functionality while acknowledging service disruptions. No technical specifics regarding the attack vector or exploitation methodology were disclosed in the initial announcement, though the confirmation of stolen assets indicated a compromise of core bridging mechanisms.

The breach represented a direct financial loss equivalent to 120,000 ETH at prevailing valuations, necessitating substantial capital deployment to honor redemption guarantees for wETH holders. Service availability was severely impacted during the incident response period, with Wormhole explicitly acknowledging network downtime while recovery operations progressed. The organization committed to providing additional incident details in subsequent communications but did not specify timelines for comprehensive disclosure. No collateral impacts on interconnected protocols or secondary platforms were referenced in the initial statement. The public announcement emphasized operational transparency regarding the financial remediation process while deferring technical analysis of the breach until later updates.
