Harmony Incident Analysis
2022-06-24 • Certi K •
https://www.certik.com/ko/resources/blog/2QRuMEEZAWHx0f16kz43uC-harmony-incident-analysis
CertiK analyzes the June 23, 2022 Harmony Horizon Bridge exploit, estimating losses of about $97 million from multiple attack transactions across the bridge between Harmony and Ethereum. The attacker obtained control sufficient to make the MultiSigWallet owner submit and confirm transactions, including a 13,100 ETH transfer, and repeated the process against ERC20Manager contracts to drain ETH, USDC, WBTC, USDT, DAI, BUSD, AAG, FXS, SUSHI, AAVE, WETH, and FRAX. CertiK notes that the stolen assets remained in the exploiter address at publication and frames the incident as another major cross-chain bridge failure after Ronin and Wormhole. The report emphasizes that if private keys were compromised through phishing or social engineering, bridge security reviews must include key-management, operational-security, penetration-testing, and red-team coverage beyond smart-contract auditing.