ความเสี่ยงด้านความปลอดภัยของบริดจ์
ช่องโหว่ที่พบบ่อย
ความเสี่ยงด้านความปลอดภัยของบริดจ์ เป็นบทเรียน Web3 & DApp Development Fundamentals ฟรีบน CoddyKit นี่คือบทเรียนที่ 3 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Web3 & DApp Development Fundamentals และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Web3 & DApp Development Fundamentals มีบทเรียนทั้งหมด 4 บทเรียน
บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ
Bridges Are High-Value Targets
Bridges hold enormous locked value, making them prime targets. Some of the largest crypto hacks in history were bridge exploits.
Understanding the common failure modes is essential for builders and users.
Compromised Signer Keys
Federated and multisig bridges depend on private keys held by validators. If enough keys are stolen, attackers can forge transfers and mint unbacked tokens.
The Ronin bridge hack (over $600M) stemmed from compromised validator keys.
Insufficient Validation
A frequent bug is failing to properly verify the proof or message of a transfer.
If the destination contract accepts a forged or replayed proof, an attacker can mint tokens that were never locked.
// VULNERABLE: missing real verification
function mint(bytes proof, uint amt) {
// forgot to actually verify proof!
token.mint(msg.sender, amt);
}Signature Verification Flaws
The Wormhole exploit (~$320M) came from a flaw that let an attacker spoof the guardian signature check.
Any weakness in how signatures or proofs are validated can be catastrophic.
Replay Attacks
A replay attack resubmits a valid message to claim funds multiple times.
Bridges must track processed message IDs (a nonce or hash) and reject duplicates.
require(!processed[messageId], "replay");
processed[messageId] = true;Fake Deposit Events
If a bridge trusts events without verifying they came from the real source contract, attackers can emit fake deposit events.
The bridge then releases funds for deposits that never happened.
Upgradeable Contract Risks
Many bridges are upgradeable via proxies. A compromised admin key can push a malicious upgrade that drains funds.
Timelocks and multisig admin controls reduce — but do not eliminate — this risk.
Smart Contract Bugs
Reentrancy, integer issues, and logic errors plague bridge contracts just like any DeFi protocol.
Because bridges concentrate so much value, a single bug can be devastating.
Wrapped Asset De-Pegging
If a bridge is exploited, the wrapped tokens it issued lose their backing and can crash to near zero.
Holders of bridged assets bear this risk even if they never interacted with the exploit directly.
Mitigations and Best Practices
To reduce bridge risk:
- Prefer trust-minimized (light client / ZK) designs
- Enforce strict proof verification and replay protection
- Add rate limits and circuit breakers
- Use timelocked, multisig-guarded upgrades and audits
Putting It Together
Bridge exploits usually trace to compromised keys, weak validation, signature flaws, replay attacks, or fake events. The biggest hacks in crypto have been bridges.
Trust-minimized designs and rigorous verification are the best defenses. Next: messaging protocols.
Quick Check
Test your bridge security knowledge.
Recap: Bridge Security Risks
You learned the common exploits:
- Compromised signer keys (Ronin)
- Signature/proof verification flaws (Wormhole)
- Replay attacks and fake events
- Upgradeable contract and general smart-contract bugs
- Mitigate with trust-minimized designs, replay protection, rate limits, audits
Next: messaging protocols.
คำถามที่พบบ่อย
บทเรียน “ความเสี่ยงด้านความปลอดภัยของบริดจ์” ฟรีหรือไม่
ใช่ — ข้อความเต็มของ “ความเสี่ยงด้านความปลอดภัยของบริดจ์” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Web3 & DApp Development Fundamentals ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Web3 & DApp Development Fundamentals มีบทเรียนทั้งหมด 4 บทเรียน
คุณจะเรียนรู้อะไรในบทเรียน “ความเสี่ยงด้านความปลอดภัยของบริดจ์”
ช่องโหว่ที่พบบ่อย คุณปฏิบัติ Web3 & DApp Development Fundamentals ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน
คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Web3 & DApp Development Fundamentals หรือไม่
ไม่จำเป็นต้องมีประสบการณ์มาก่อน Web3 & DApp Development Fundamentals บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 3 จากทั้งหมด 4 บทเรียน
บทเรียน “ความเสี่ยงด้านความปลอดภัยของบริดจ์” ใช้เวลานานแค่ไหน
บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย
ฉันเขียนและรันโค้ดในบทเรียน Web3 & DApp Development Fundamentals นี้ได้ไหม
ได้ บทเรียน Web3 & DApp Development Fundamentals ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ
บทเรียนทั้งหมดในหลักสูตรนี้
- แนวคิดข้ามเชน
- สถาปัตยกรรมบริดจ์
- ความเสี่ยงด้านความปลอดภัยของบริดจ์
- โพรโทคอลการส่งข้อความ