Bridge Exploit History Checker
Free to download on every platform. Comes pre-installed on BotFone, BotPad and BotFlip — with extra free apps included.
About this app
WHAT IT DOES
Bridge Exploit History Checker searches a bridge contract against known exploit incidents and suspicious on-chain patterns before you use it. The tool checks a local database of historical bridge exploits — including Wormhole, Ronin, Multichain, Synapse, and others — to see if the protocol you are considering has been compromised before. It scans the contract bytecode for suspicious patterns like selfdestruct, upgradeable proxies, and owner-only controls that could indicate risk. The tool also analyzes the contract address and protocol name (if provided) to match against known exploit records, including the year of the exploit, the amount lost, and a description of what happened. The tool then uses AI to generate a plain-language security assessment: whether the bridge has a history of exploits, what happened, when it occurred, what the impact was, whether suspicious patterns are present, and a clear recommendation on whether to use the bridge. Results include a risk level (Low, Medium, High, Critical), exploit history details, suspicious pattern flags, and a comprehensive AI-generated security assessment. The tool operates entirely read-only — no transactions are sent, no signatures are required. The AI assessment is designed to inform your decision before you approve any bridge transaction.
HOW TO USE
Connect your EVM wallet using the "Connect" button in the header. Select the network where the bridge contract is deployed from the dropdown menu. Enter the bridge contract address you wish to analyze. Optionally enter the protocol name if you know it — this helps the tool match against its exploit database more accurately. Click "Check exploit history" to begin the analysis. The tool searches the exploit database for matching protocol names, scans the contract bytecode for suspicious patterns, and sends the data to the AI for a security assessment. Results appear within seconds, showing the bridge contract, chain, risk level, exploit history details, suspicious pattern flags, and a comprehensive AI-generated security assessment written in clear, conversational language.
EXPLOIT DATABASE MATCHING AND PATTERN-BASED ANOMALY DETECTION
The tool uses a dual-layer approach to assess bridge security. First, it checks the user-provided protocol name (and attempts protocol detection from bytecode patterns) against a curated database of known bridge exploits. The database includes major incidents like Wormhole ($325M, 2022), Ronin ($625M, 2022), Multichain/Anycall ($8M, 2022), Synapse ($8M, 2021), as well as bridges with no known exploits (Across, Stargate, Hop, Arbitrum, Optimism, Axelar, Connext, Celer) to provide context. For each matching protocol, the tool displays the incident details — year, amount lost, and description — helping you understand the historical risk. Second, the tool scans the contract bytecode for suspicious patterns including selfdestruct (which can destroy the contract), delegatecall with implementation storage (upgradeable proxy patterns that can change logic), and owner-only controls (centralized control risk). The tool also checks for unusual address patterns that might indicate impersonation. The AI receives all this data and is prompted to explain the bridge's historical exploit exposure in plain language, assess whether the bridge appears actively maintained or abandoned, and provide a risk level with a clear recommendation. The AI is also instructed to state plainly what it cannot verify — that it checks on-chain patterns and known exploit databases, not the bridge's current operational status, off-chain security, undiscovered vulnerabilities, or future exploit risk.
WHAT IT CANNOT SEE
This tool cannot detect off-chain exploits or social engineering attacks — only checks for known on-chain exploit patterns and historical records. It cannot verify that the contract has not been upgraded since an exploit was fixed or that the current code is safe — a bridge may have been exploited in the past and subsequently patched. The exploit database may not include all incidents — the tool only knows about exploits that have been recorded in its database. The tool cannot detect undiscovered vulnerabilities or predict future exploits — a clean history does not guarantee future security. Legitimate contracts may have suspicious-looking transactions that are not exploits — large outflows or unusual patterns can occur for legitimate reasons. The tool cannot detect if the bridge is currently under attack or compromised. The tool cannot verify the bridge's operational status or maintenance. The tool cannot detect validator compromises or off-chain infrastructure failures. The tool cannot verify that the bridge's team is legitimate or trustworthy.
PLEASE NOTE
Bridge Exploit History Checker supports EVM-compatible chains only (Ethereum, BSC, Polygon, Arbitrum, Optimism, Avalanche, and others). The tool is read-only and never requests wallet signatures or transaction approvals. Security assessments are AI-generated from on-chain data and known exploit records — always verify bridge security through official project channels and independent research. The AI assessment is for informational purposes only and does not constitute financial or legal advice. A history of no exploits does not guarantee safety — always conduct your own due diligence before using any bridge. If a bridge has been exploited before, verify that the exploit has been fully patched and that the bridge team has implemented appropriate security measures.