What is Wormhole (W)?
π New to this? Just start reading at the top β it begins in plain English and gets more detailed as you scroll. Jump to any level:
π’ The simple version
Plain English β no jargon. Start here.
Wormhole is a cross-chain messaging and bridge protocol connecting 30+ blockchain ecosystems β it is the dominant bridge between Ethereum and Solana, uses 19 "Guardian" validators (major crypto institutions) for security, and is notable for suffering a $320M exploit in February 2022 that was fully covered by Jump Crypto.
Wormhole's role in the ecosystem
Wormhole is the primary infrastructure for bridging assets between Ethereum and Solana β two ecosystems that don't share native interoperability. Wrapped WBTC, USDC, and USDT on Solana that come from Ethereum commonly flow through Wormhole. Beyond Solana, Wormhole connects Ethereum, BSC, Polygon, Avalanche, Terra Classic, Cosmos, and 20+ other chains. Its cross-chain messaging capability (not just asset transfers but arbitrary message passing) makes it infrastructure-level technology used by other protocols and applications.
W is Wormhole's governance token launched in April 2024 via a large airdrop to ecosystem participants across its connected chains β one of the most broadly distributed airdrops ever, given Wormhole's multi-chain presence.
The $320M exploit β February 2022
In February 2022, an attacker exploited a vulnerability in Wormhole's Solana contracts. The bug: a signature verification bypass allowed the attacker to mint 120,000 wrapped ETH (wETH) on Solana without depositing real ETH on Ethereum. The attacker then bridged this synthetic wETH back to Ethereum, draining real ETH from Wormhole's Ethereum vault. Total loss: $320 million in ETH β the largest single bridge exploit in history at the time. Jump Crypto (Wormhole's primary backer) repaid the full $320M within hours, preventing any user from losing funds.
Is W legal in India?
Yes. W qualifies as a Virtual Digital Asset (VDA) under Indian law. 30% tax on gains and 1% TDS applies. Always consult a tax professional.
π‘ A bit more detail
For when you want to go a little deeper.
Guardian network security model
Wormhole's 19 Guardians are a set of large, reputable crypto organisations who run full nodes on all connected chains and sign cross-chain messages. The list has included Jump Crypto, Everstake, Staked, Certus One, Figment, and others. A message is valid when 13/19 (2/3) Guardians sign it. This is a relatively small, trusted validator set β more centralised than Axelar's ~75 validators or LayerZero's configurable model, but backed by organisations with significant reputational stakes. The 19 Guardians are chosen for institutional reliability rather than decentralisation breadth.
Wormhole post-exploit improvements
After the $320M exploit, Wormhole conducted extensive security audits, established a $10M bug bounty programme (one of crypto's largest), and implemented additional verification layers. The protocol has not suffered a major exploit since. Jump Crypto's full repayment demonstrated institutional backing but also highlighted the centralisation of the security model β one entity covering $320M is possible only because of Jump's scale. Wormhole's W token and broader governance aim to eventually decentralise control beyond Jump's influence.
The February 2022 signature verification bypass exploit drained $320M in ETH from Wormhole's Ethereum vault. Jump Crypto repaid the full amount β no user lost funds. The patch was deployed within 24 hours. The bug has since been patched and extensively audited. This history is material β understand it when assessing cross-chain bridge risk. Live data: CoinGecko
π£ The full technical picture
For the technically curious.
Key facts
- Token: W (governance, launched April 2024 via large multi-chain airdrop)
- Function: Cross-chain messaging + bridge (EthereumβSolana primary)
- Security: 19 Guardian validators (13/19 threshold)
- Chains: 30+ including Ethereum, Solana, BSC, Polygon, Avalanche, Cosmos
- Feb 2022: $320M exploit (signature bypass) β Jump Crypto repaid full amount
- Post-exploit: Extensive audits, $10M bug bounty, no major exploit since
- Backer: Jump Crypto (primary), Multicoin Capital
- vs LayerZero: 19 fixed Guardians vs configurable oracle/relayer
- vs Axelar: 19 Guardians vs ~75 staked validators
The signature bypass vulnerability
The February 2022 Wormhole exploit exploited a deprecated Solana function. Wormhole's Solana program called solana_program::sysvar::instructions to verify that a secp256k1 signature verification instruction had been run (required to validate Guardian signatures). However, the program failed to check that this was the current transaction's instruction β the attacker provided a crafted account that satisfied the check without actual signature verification. The attacker then called the "complete_wrapped" function, which minted 120,000 whETH without the corresponding ETH deposit. The fix: strict account ownership checks to prevent substituting crafted accounts for system accounts.