Research summary
Portal warrants rejection. It is the token-bridging application built on Wormhole's messaging protocol and is secured by a 19-node Guardian network that requires 13-of-19 signatures to attest a transfer. On 2022-02-02, a Solana program signature-verification flaw let an attacker forge a Guardian attestation and mint 120,000 wETH, about $325M, with no real backing. This was one of the largest bridge hacks on record. The loss was made whole only because Jump Crypto, a Wormhole backer, recapitalized the bridge within days and later clawed back further funds through an extraordinary counter-exploit. That is not a repeatable institutional guarantee, and this registry does not treat an informal backer bailout as a substitute for controls strong enough to protect the protocol on their own. The post-incident additions are real structural improvements: a Global Accountant that cross-checks minted supply against locked collateral, and a Governor that rate-limits and can hold large transfers for up to 24 hours. The incident-free record since 2022 is also genuine, but these changes narrow the risk rather than eliminate the class of signature-forgery risk that remains part of this bridge design.
Observable review triggers
- Current Guardian-set composition and the specific authority controlling Guardian-set changes are independently confirmed
- Twelve consecutive months with no Guardian-quorum forgery or signature-verification incident, counted from this review's date
- The Global Accountant and Governor are confirmed live and correctly configured for the specific chain and asset pair a Ketju position would use
- A proposed-size redemption is demonstrated to clear within a documented maximum time, including the Governor's worst-case 24-hour hold
Facts on file
- Verdict
- Rejected
- Type
- Other
- Chains examined
- Ethereum
- Reviewed
- Last confirmed