A cross-chain bridge lets value move between blockchains that cannot communicate directly. It does this by locking or destroying an asset on the source chain and issuing a representation of it on the destination chain. The representation is a claim on the bridge, and its worth depends entirely on the bridge continuing to honour it.
Why blockchains cannot talk to each other
Each blockchain is a self-contained record. Its validators agree on its own state and have no way to observe any other chain. A token on one network cannot be sent to another network, because the receiving network has no mechanism for learning that anything happened elsewhere.
This is not an oversight. A blockchain's guarantees come from every participant verifying the same history. Accepting an assertion about a different chain means accepting something the network cannot itself verify, and that is precisely where trust has to be introduced.
So the phrase "moving a token across chains" describes an outcome, not a mechanism. Nothing crosses.
What actually happens
The dominant pattern is lock and mint. The asset is locked in a contract or an account on the source chain, and a matching quantity of a new token is issued on the destination chain. To go back, the destination token is destroyed and the original released.
A variant is burn and mint, where the asset is destroyed on the source chain rather than held.
A third approach avoids issuance entirely. Liquidity pools on both chains let a user deposit on one side and withdraw a corresponding asset already held on the other. No new token is created; the constraint becomes whether the pool holds enough.
In each case someone or something must attest that the source-side event occurred. That attestation is performed by validators, a multi-signature group, or a set of key-holders operating the bridge. That set of parties is the bridge's security model, and everything that has gone wrong with bridges has gone wrong there, not in the chains on either side, which have generally continued operating correctly throughout.
Why bridges became the largest theft target
In August 2022 Chainalysis estimated that about $2bn had been stolen across 13 separate cross-chain bridge hacks, most of it that year, and that bridge attacks accounted for 69% of all funds stolen in 2022 up to that point (Chainalysis, Cross-Chain Bridge Hacks Emerge as Top Security Risk, 2 August 2022). The two largest individual losses were the Ronin bridge at approximately $624m and Wormhole at approximately $320m.
The reason is structural rather than incidental. A bridge holds the locked assets of everyone who has crossed it, in one place, secured by a mechanism that is usually simpler than the chains on either side. It is a concentrated store of value with a smaller attack surface protecting it than the networks it connects.
The failures have overwhelmingly been failures of the attestation layer: compromised validator keys, signature verification that could be bypassed, or a multi-signature threshold small enough to be reached by an attacker.
The problem has not gone away with time. Bridge and related protocol compromises have continued to account for a substantial share of stolen value in the years since, though figures for later periods vary between trackers and we do not cite one here.
What you are holding after you bridge
A claim, not the asset.
The token you hold on the destination chain is a new token, issued by the bridge, whose value rests on the expectation that the bridge will release the original when asked. If the bridge is compromised and the locked assets are taken, the representation remains on the destination chain and becomes worth nothing. The chain will still report your balance accurately. The balance will simply be a record of a claim against something that is gone.
This has a direct consequence for tokenised real-world assets. If a token represents an interest in a company, and that token is bridged, what exists on the far side is a claim on a bridge that holds a token that represents an interest in a company. Whether the company's register recognises the holder on the far side is a question of company law, and the answer is frequently no. Before bridging an instrument, establish who the issuer treats as the holder, and see what a tokenised instrument actually is for why the register, not the ledger, governs.
Questions to ask about any bridge
Who attests, and how many of them are there? A threshold of five of nine known parties is a different proposition from two of three anonymous ones.
What happens if the attesters disappear? Is there a path to recovering the locked assets without them, or are they the only route?
How much is locked? The value held is the size of the prize. A bridge holding a large balance is under continuous, well-resourced attack.
Has the code been reviewed, by whom, and when? And has it changed since.
Is there an upgrade mechanism, and who controls it? A bridge that can be upgraded can be changed by whoever holds that power.
What is the recourse if it fails? Usually none. It is better to know that in advance than to discover it afterwards.
When you do not need a bridge
Most tokenisation programmes do not need one, and the cheapest way to manage bridge risk is not to take it.
An asset issued on one chain, held by holders on that chain, transferred on that chain and redeemed on that chain never encounters a bridge. The pressure to bridge usually comes from wanting access to activity on another network. For a single-issuer instrument with restricted transferability, that is frequently not a real requirement on inspection.
If holders need to arrive from elsewhere, the simpler pattern is to let them convert at the edge and hold the instrument natively on its own chain. The conversion risk is then a transaction they choose to make, not a permanent property of the instrument.
Trusty Digital issues on Algorand by default and does not operate a bridge. Where a programme genuinely requires multi-chain presence, that is a structural decision to make deliberately, with the questions to ask about any bridge answered first.
The short version
A bridge does not move a token between chains, because that is not a thing that can happen. It locks an asset on one side and issues a claim on the other, and the claim is only as good as the parties operating it.
That design concentrates value behind a mechanism weaker than the chains it joins, which is why, by Chainalysis's estimate, bridge attacks accounted for 69% of the funds stolen in 2022 up to August that year.
Bridges are useful and sometimes necessary. They are not neutral infrastructure, and the honest way to describe one is by naming who is trusted and what happens when that trust fails.
This article is general information, not legal, tax or investment advice.