DeFi & Stablecoins
Best Crypto Bridges
Historically the single most exploited class of infrastructure in crypto. Custody carries 45% here for the same reason it does on hardware wallets: this is where the money is stolen.
All 4 compared
Sorted by computed score. Column headers carry this category's weighting; the highest score in each pillar is marked. Tap a name for the full assessment.
| # | Service | Score | Custody45% | Cost15% | Regulation5% | Performance25% | Access10% |
|---|---|---|---|---|---|---|---|
| 01 | Chainlink CCIPIssuer-controlled token transfers across 80+ chains, cheapest at size | 8.2Strong | 8.4 — best in table | 7.6 | 7.4 — best in table | 8.4 — best in table | 8.2 |
| 02 | AcrossFast transfers with relayers fronting the capital−1 penalty | 7.2Solid | 7.4 | 8.2 — best in table | 6.2 | 8.0 | 8.4 — best in table |
| 03 | WormholeIssuers taking a native token multichain, if you accept the guardian model | 7.1Solid | 6.4 | 7.6 | 6.0 | 7.8 | 7.8 |
| 04 | Hop ProtocolNothing new: a sound design that now looks close to dormant | 6.2Adequate | 8.0 | 6.4 | 6.0 | 4.0 | 3.0 |
The assessments
what each score rests on- 018.2/10
Chainlink CCIP
Best for issuer-controlled token transfers across 80+ chains, cheapest at size
Company file: Chainlink, owners, incidents →Strong◆ Sources checked · 27 Sept 2026Cross-chain transfers carried by Chainlink’s oracle networks, with the token issuer keeping control of its contract and per-lane rate limits. The separate Risk Management Network that was sold as an independent check no longer runs its automated role; pausing a chain is now a manual decision by the CCIP owner. Flat fees make it cheap for large transfers and relatively dear for small ones.
Pillar scores
- Custody & Security45%
- 8.4
- Cost & Fee Transparency15%
- 7.6
- Regulation & Legal Standing5%
- 7.4
- Performance & Reliability25%
- 8.4
- Access & Support10%
- 8.2
Strengths
- The token issuer, not the bridge, owns the token contract and its rate limits
- No exploit of CCIP contracts on record
- 80+ chains and published, flat fees
Against it
- The Risk Management Network no longer runs automatically; pausing is manual
- Operators are selected by Chainlink Labs rather than open to anyone
- Flat fees make small transfers relatively expensive
Full assessment of Chainlink CCIP →strong · 8.2/10 - 027.2/10
Across
Best for fast transfers with relayers fronting the capital
Company file: Across Protocol, owners, incidents →Solid◆ Sources checked · 27 Sept 2026An intent-based design where relayers front the capital and wait for settlement themselves, rather than locking user funds in a bridge contract for the duration. The record is no longer clean: DefiLlama lists a $4.5M exploit of the Solana deployment on 17 Jul 2026, and Across had published no post-mortem by 27 Sep 2026. In 2026 the protocol also moved from a DAO to a US company, Across, Inc.
Pillar scores
- Custody & Security45%
- 7.4
- Cost & Fee Transparency15%
- 8.2
- Regulation & Legal Standing5%
- 6.2
- Performance & Reliability25%
- 8.0
- Access & Support10%
- 8.4
Deductions applied
- −0.5Material fact undisclosed. The operator publishes nothing at all on a question this rubric asks — no fee schedule, no reserve or audit disclosure, no named operating entity. Silence is a finding, and it is scored as one.
Strengths
- Relayers front the capital, so there is no large pool of user funds in transit
- Fills in about two seconds on supported routes
- Fees quoted up front with each component documented
Against it
- $4.5M exploit of the Solana deployment on 17 Jul 2026, with no post-mortem published
- Hub-pool liquidity down about 91% from its Dec 2024 peak
- Now owned by a private company; ACX governance ends 8 Jan 2027
Full assessment of Across →solid · 7.2/10 - 037.1/10
Wormhole
Best for issuers taking a native token multichain, if you accept the guardian model
Company file: Wormhole, owners, incidents →Solid◆ Sources checked · 27 Sept 2026Connects 45+ chains and is the standard many issuers use to keep one native token on several of them. Security rests on 19 Guardian companies, 13 of which must sign, and in February 2022 a signature verification flaw let an attacker mint 120,000 wrapped ETH, about $326m. The hole was covered by the backer rather than by users, which matters — but the model that allowed it is still the model.
Pillar scores
- Custody & Security45%
- 6.4
- Cost & Fee Transparency15%
- 7.6
- Regulation & Legal Standing5%
- 6.0
- Performance & Reliability25%
- 7.8
- Access & Support10%
- 7.8
Strengths
- 45+ connected chains and the NTT standard for native multichain tokens
- Users were made whole after the 2022 exploit
- 29 audits and outflow limits added since
Against it
- Security rests on a permissioned guardian set — the model that failed in 2022
- Suffered one of the largest exploits in crypto history
- More than a dozen networks dropped in 2025–26; wrapped tokens on them can be stranded
Full assessment of Wormhole →solid · 7.1/10 - 046.2/10
Hop Protocol
Best for nothing new: a sound design that now looks close to dormant
Company file: Hop Protocol, owners, incidents →Adequate◆ Sources checked · 27 Sept 2026Settles through the canonical rollup bridges with bonded liquidity providers and has no exploit on record, but the product around it has largely gone. On 27 Sep 2026 hop.exchange served an Indonesian gambling site, the app subdomain returned an error, liquidity was about $3.9M against a $149M peak, and v2 was still on testnet. Never connect a wallet on the hop.exchange domain.
Pillar scores
- Custody & Security45%
- 8.0
- Cost & Fee Transparency15%
- 6.4
- Regulation & Legal Standing5%
- 6.0
- Performance & Reliability25%
- 4.0
- Access & Support10%
- 3.0
Strengths
- Inherits canonical rollup bridge security instead of inventing a trust model
- No exploit on record
- Fees documented in the docs
Against it
- hop.exchange now serves an unrelated gambling site — never connect a wallet or sign there
- Liquidity down about 97% from peak; thin pools mean real slippage
- v2 never left testnet and development has stalled
Full assessment of Hop Protocol →adequate · 6.2/10
Bridges are the most exploited class of infrastructure in crypto — Ronin, Wormhole, Nomad, Harmony, Multichain, with losses running into billions. Custody carries forty-five per cent here for the same reason it does on hardware wallets: this is where the money actually gets stolen, and the mechanism is almost always the validator or multisig set rather than clever maths.
Frequently asked questions
Why are bridges exploited so much more than anything else?+
Because they concentrate value behind a trust assumption that is usually much weaker than the chains they connect. A bridge holding a billion dollars secured by a five-of-nine multisig is a billion-dollar prize behind a five-key lock. Almost every large bridge loss traces to the validator or key set, not to a subtle flaw in the cryptography.
Does being made whole after an exploit count in a bridge’s favour?+
A little, and less than people assume. It shows the operator has resources and chose to use them, which is worth something. It does not fix the design that permitted the exploit, and it is not a property you can rely on next time — a backer’s willingness to write a cheque is not a security guarantee.
Is there a safer way to move between chains?+
Using a chain’s canonical bridge, when you can wait for it. Canonical bridges inherit the security of the chains themselves rather than adding a new trust assumption. Third-party bridges exist because canonical ones are slow — you are paying for speed with security, and it is worth knowing that is the trade being made.
Assessed by
By James Park
NFT & Web3 Gaming Analyst · September 27, 2026