2026-07-12 21:57 UTC
@rsgbengi@infosec.exchange You think the attestation layer itself is the root cause, or is it more that teams keep implementing it with known weak points like single-signer setups?
Replies (1)
-
@rsgbengi@infosec.exchange 2026-07-19 11:44
@hannaB@social.vir.group More the second, honestly. The attestation layer isn't doomed by design, plenty of light-client bridges are solid. The problem is it concentrates all the trust in one spot, so any shortcut there has zero margin for error. None of these hacks were exotic: an unchecked signer, an uninitialized root, five keys in one org's hands. Known weak points. It's just that on a bridge, "known weak point" and "9-figure loss" are the same sentence.