SoK: Security and Privacy of Blockchain Interoperability
Andre Augusto, Rafael Belchior, Miguel Nuno Dias Alves Pupo Correia, Andre Vasconcelos, Luyao Zhang, Thomas Hardjono
IEEE Symposium on Security and Privacy 2024 · Day 3 · Continental Ballroom 6
Overview
Blockchain interoperability, the ability for disparate blockchain systems to communicate and exchange assets or data, is a cornerstone of the burgeoning Web3 ecosystem. However, this critical functionality has become a prominent target for malicious actors, leading to devastating financial losses. This talk, "SoK: Security and Privacy of Blockchain Interoperability," presented by Andre Augusto at IEEE S&P, delivers a comprehensive systematization of knowledge (SoK) on the inherent security and privacy challenges within this domain. The motivation for this extensive research is stark: since June 2021, an alarming $3.2 billion USD has been stolen from cross-chain bridges, averaging $3 million per day, highlighting a systemic and frequent problem rather than isolated incidents.

Key moments
- 0:00 Introduction and scale of cross-chain bridge hacks
- 1:35 Paper's proposed security and privacy model
- 2:09 Core definition of blockchain interoperability
- 3:15 Cross-chain solution security model layers
- 4:05 Key security properties and approaches
- 5:45 Key privacy properties and approaches
- 6:40 Insights: Security prioritizes over privacy in industry
- 8:10 Classification of vulnerabilities, privacy leaks, and attacks
SoK: Security and Privacy of Blockchain Interoperability
Speakers: Andre Augusto, Rafael Belchior, Miguel Nuno Dias Alves Pupo Correia, Andre Vasconcelos, Luyao Zhang, Thomas Hardjono
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=xFafCzSFZOM
Overview
Blockchain interoperability, the ability for disparate blockchain systems to communicate and exchange assets or data, is a cornerstone of the burgeoning Web3 ecosystem. However, this critical functionality has become a prominent target for malicious actors, leading to devastating financial losses. This talk, "SoK: Security and Privacy of Blockchain Interoperability," presented by Andre Augusto at IEEE S&P, delivers a comprehensive systematization of knowledge (SoK) on the inherent security and privacy challenges within this domain. The motivation for this extensive research is stark: since June 2021, an alarming $3.2 billion USD has been stolen from cross-chain bridges, averaging $3 million per day, highlighting a systemic and frequent problem rather than isolated incidents.
The speakers identify a significant gap in the current landscape: the security and, particularly, privacy aspects of blockchain interoperability are severely understudied. Existing guidelines for developers are often vague, leading to an ad-hoc proliferation of cross-chain solutions with widely varying architectural designs and security postures. To address this, the paper proposes a robust security and privacy model for cross-chain interactions, classifying interoperability mechanisms, analyzing real-world hacks, and outlining crucial future research directions. This work is vital for researchers, developers, and practitioners seeking to understand, build, and secure the interconnected blockchain future.
Background
▶ Watch: Introduction and scale of cross-chain bridge hacks (0:00)
The core concept of blockchain interoperability is defined as "the ability of a source blockchain to change the state of a target blockchain or vice versa, enabled by cross-chain transactions spanning a composition of blockchain systems." Essentially, it facilitates the seamless transfer of data or assets between different blockchains. The rapid growth of the Web3 ecosystem has led to a proliferation of distinct blockchain networks, each with its unique strengths, necessitating mechanisms to bridge these isolated environments.
Despite its importance, the field of blockchain interoperability is characterized by unstructured practices and a reliance on ad-hoc solutions. This lack of standardization contributes significantly to the observed security vulnerabilities and privacy shortcomings. The research presented in this SoK is based on an extensive analysis of 242 studies, including 58 retrieved from Google Scholar using relevant keywords, 10 audit reports, and a substantial 63 grey literature documents. The heavy reliance on grey literature underscores the nascent and often informal nature of development and knowledge-sharing within the blockchain and Web3 space. A critical observation from this background analysis is the severe neglect of privacy considerations, which are often not even clearly defined in the context of cross-chain transactions, alongside the prevalent security issues.
Key Findings
▶ Watch: Core definition of blockchain interoperability (2:09)
The research yielded several critical findings that illuminate the current state of blockchain interoperability:
Firstly, the paper successfully established a security model and a privacy model specifically tailored for cross-chain interactions. These models define relevant properties (e.g., Integrity, Accountability, Availability for security; Unlinkability, Anonymity, Confidentiality for privacy) and outline approaches to guarantee them. This foundational work provides a structured lens through which to evaluate and design interoperable systems.
Secondly, a comprehensive classification of 57 interoperability mechanisms from both academia and industry revealed a stark prioritization: security consistently takes precedence over privacy. Industry protocols, which collectively represent over 75% of the total value locked (TVL) in the market, often completely disregard privacy features. This imbalance is attributed to the considerable overhead that privacy-preserving features introduce, suggesting a significant trade-off between privacy and efficiency/scalability that developers are currently unwilling to make.
Thirdly, the study identified and classified a wide array of vulnerabilities, privacy leaks, and attacks across different architectural layers (Network, Protocol, Implementation, Operational). While theoretical research indicated a high incidence of vulnerabilities at the protocol layer, the analysis of 18 real-world cross-chain hacks presented a contrasting picture. A significant portion of actual exploits stemmed from vulnerabilities in the operational layer, particularly inadequate key management, which was responsible for a staggering $1.6 billion USD in stolen funds. This discrepancy highlights a critical disconnect between academic focus and practical exploit vectors.
Finally, the analysis of real-world incidents provided actionable insights into attacker methodologies and defensive shortcomings. It revealed a lack of incentives for vulnerability disclosure by white hats (only 1.5% of stolen funds were returned), the heightened risk associated with the lock-mint pattern in bridges (62% of value stolen from escrow accounts), and the frequent use of transaction mixers by attackers to launder funds. These findings collectively underscore the urgent need for more robust security practices, better incident response frameworks, and a re-evaluation of architectural choices in cross-chain solutions.
Technical Deep Dive
▶ Watch: Key security properties and approaches (4:05)
The core of this SoK lies in its proposed security and privacy models, which provide a structured framework for understanding and mitigating risks in blockchain interoperability.
The security model for cross-chain solutions dissects the architecture into four distinct layers:
- Network Layer: Encompasses the underlying consensus mechanisms of individual blockchains and their smart contract engines.
- Protocol Layer: Deals with the specific architecture of the interoperability solution itself, including trade-offs between security, decentralization, and performance.
- Implementation Layer: Focuses on the development of both on-chain and off-chain components.
- Operational Layer: Addresses critical aspects like key management, infrastructure monitoring, code upgrades, and incident response.
Based on the traditional CIA triad, the proposed security properties are Integrity, Accountability, and Availability.
- Integrity ensures the correctness of data and assets the system interacts with.
- Accountability holds participants responsible for their actions, whether good or malicious (e.g., integrity bridge attempts).
- Availability guarantees that processes and systems can reliably relay information and proofs between blockchains.
To achieve these properties, the paper identifies several security approaches:
- Centralized Parties: A single entity facilitates communication, offering simplicity but introducing a single point of failure.
- Validity Proofs: Mechanisms like zero-knowledge technology (e.g., Zero-Knowledge Proofs - ZKPs) cryptographically prove the correctness of a transaction without revealing underlying details.
- Fraud Proofs: Based on optimistic windows, where proofs are optimistically accepted, and watchers have a time window to challenge any relayed fraudulent data.
- Secret and Time-Based Logs: Often rely on off-chain communication channels and the security of cryptographic primitives used for direct party communication.
The privacy model addresses what a "private solution" means in this context, defining three key properties:
- Unlinkability: The ability to prevent an observer from linking transactions across different blockchains to the same cross-chain operation.
- Anonymity: Protecting the identity of users and operators involved in the interoperability solution.
- Confidentiality: Ensuring that the content of cross-chain transactions remains private and unreadable to unauthorized parties.
Privacy approaches explored include:
- Zero-Knowledge Proofs (ZKPs): Used to prove transaction validity without exposing details, contributing to unlinkability and confidentiality.
- Trusted Execution Environments (TEEs): Hardware-based secure enclaves that can execute code and process data in isolation, protecting confidentiality.
- Digital Signatures: Advanced forms like adapter signatures, blind signatures, and ring signatures can provide varying degrees of anonymity and unlinkability.
- Homomorphic Encryption (HE): Allows computations on encrypted data without decrypting it, preserving confidentiality during processing.
The classification of 57 interoperability mechanisms yielded crucial insights. Six industry protocols, holding 75% of the market's TVL, predominantly neglect privacy. This is largely due to the "considerable overhead" privacy-preserving features introduce, creating a trade-off with scalability and efficiency. Cross-chain unlinkability in asset and data transfer protocols is only achievable if the underlying chains themselves provide confidentiality (e.g., private chains or public chains with privacy features like Monero). For accountability, stake slashing mechanisms are the predominant trend, where participants risk losing staked assets for misbehavior. A smaller subset relies on legal identification via KYC (Know Your Customer) primitives, typically in more centralized frameworks.
Analyzing vulnerabilities, the paper categorized them by layer: Operational, Implementation, Protocol, and Network. While theoretical research indicated a high incidence of vulnerabilities in the protocol layer and privacy leaks in the implementation and protocol layers, a striking contrast emerged when examining real-world hacks. The operational layer, with only three theoretical vulnerabilities identified, was found to be a major source of exploits in practice, highlighting a significant blind spot in academic focus.
Demo / Proof of Concept
▶ Watch: Key privacy properties and approaches (5:45)
As a Systematization of Knowledge (SoK) paper, the talk focused on a comprehensive review, classification, and analysis of existing literature and real-world incidents. Therefore, no live demonstration or proof-of-concept exploit was presented during the session. The emphasis was on theoretical models, empirical data analysis, and deriving insights from past events.
Defensive Implications
▶ Watch: Classification of vulnerabilities, privacy leaks, and attacks (8:10)
The findings from this SoK offer critical guidance for developers, security architects, and defenders operating within the blockchain interoperability space. Addressing the identified vulnerabilities and shortcomings is paramount to preventing future billions in losses.
- Prioritize Robust Key Management: The most salient defensive implication is the urgent need to overhaul key management practices. With $1.6 billion stolen due to inadequate key management (an operational layer vulnerability), organizations must invest in secure, multi-party computation (MPC) based solutions, hardware security modules (HSMs), stringent access controls, and regular audits of key lifecycle management. This layer is a primary target and often the weakest link.
- Develop Proactive Monitoring Systems: The lack of timely incident discovery in many hacks underscores the necessity for proactive monitoring of cross-chain systems. This includes real-time transaction analysis, anomaly detection, and continuous integrity checks across all layers of the interoperability solution. Early detection of breach attempts or suspicious activities can significantly reduce the impact of an exploit.
- Establish Comprehensive Incident Response Frameworks: The current ad-hoc nature of incident response in cross-chain systems is unacceptable. Organizations must develop and regularly test generic incident response frameworks specifically tailored for cross-chain environments. These frameworks should detail steps for detection, containment, eradication, recovery, and post-mortem analysis, ensuring a coordinated and effective response to security incidents.
- Re-evaluate Architectural Patterns, Especially Lock-Mint: The lock-mint pattern in cross-chain bridges was identified as particularly risky, with 62% of stolen value drained from escrow accounts. Defenders should critically evaluate their choice of interoperability architecture. If lock-mint is unavoidable, then the security of the escrow (the "honey pot") must be paramount, potentially through multi-signature schemes, time-locks, and enhanced monitoring. Exploring alternative patterns that distribute risk or minimize the amount held in escrow could be beneficial.
- Address Privacy Deficiencies: While security often takes precedence, the neglect of privacy creates significant risks, especially for sensitive data or regulated assets. Developers should explore integrating privacy-preserving features like Zero-Knowledge Proofs (ZKPs), Trusted Execution Environments (TEEs), or advanced digital signatures, even if they introduce some overhead. Understanding that cross-chain unlinkability depends on the underlying chains' privacy features is crucial for realistic privacy guarantees.
- Contribute to and Adopt Standardization Efforts: The ad-hoc nature of solutions is a root cause of many problems. Engaging with standardization bodies like ISO and ITF to develop common protocols and best practices for blockchain interoperability will lead to more secure and resilient systems across the ecosystem. Adopting existing or emerging standards can reduce the surface area for novel attacks.
- Incentivize White Hat Disclosure: The low return rate of stolen funds by white hats suggests a need for better bug bounty programs and clearer incentives for responsible vulnerability disclosure. Establishing robust, well-funded programs can encourage ethical hackers to report vulnerabilities before they are exploited by malicious actors.
Key Takeaways
- Massive Financial Losses: Cross-chain bridges are a prime target, with over $3.2 billion USD stolen since June 2021, averaging $3 million per day, indicating a systemic security problem.
- Neglected Privacy: Privacy in blockchain interoperability is severely understudied and often completely neglected by industry protocols, leading to a significant trade-off with efficiency and scalability.
- Operational Layer Vulnerabilities are Critical: While theoretical research highlights protocol layer issues, real-world hacks predominantly exploit vulnerabilities in the operational layer, particularly inadequate key management, responsible for $1.6 billion in losses.
- Architectural Risks: The lock-mint pattern in cross-chain bridges is identified as particularly risky, with 62% of stolen value drained from escrow accounts.
- Poor Incident Response: There is a significant lack of proactive monitoring and robust incident response frameworks tailored for cross-chain systems, delaying discovery and increasing the impact of attacks.
- Mixers Facilitate Laundering: Attackers frequently use transaction mixers (5 times before, 11 times after attacks) to obfuscate fund origins and destinations, complicating recovery efforts.
About the Speaker(s)
The talk "SoK: Security and Privacy of Blockchain Interoperability" was presented by Andre Augusto. He is a co-author of the paper alongside Rafael Belchior, Miguel Nuno Dias Alves Pupo Correia, Andre Vasconcelos, Luyao Zhang, and Thomas Hardjono. The presentation at the IEEE S&P conference highlights their collective expertise and research contributions to the critical field of blockchain security and privacy.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This SoK is a critical, foundational analysis of blockchain interoperability's systemic security and privacy failures. It establishes robust models and brutally highlights the disconnect between academic focus and real-world operational layer exploits, providing indispensable, actionable insights for an area bleeding billions.
Heather Calloway (CISO) — MUST SEE
This SoK delivers a stark, evidence-based diagnosis of systemic security failures in blockchain interoperability. The $3.2 billion in losses, predominantly from operational vulnerabilities like key management, demands immediate executive action and a fundamental re-evaluation of accountability in this high-stakes domain. It provides clear, actionable guidance for security leaders.
→ Top-rated talks at IEEE Symposium on Security and Privacy 2024