Bridge Services Incident Notice

Over the past few days, our monitoring systems detected unusual activity involving a team-managed wallet used in bridge operations.
Summary
- Our monitoring flagged suspicious behavior tied to a team-managed wallet.
- As a precaution, we disabled and recycled a set of related addresses and temporarily paused bridge services.
- A small number of transactions occurred during the window in question.
- We coordinated quickly with Binance after identifying that part of the flow touched their platform.
- Based on all information available at this time, no user funds were impacted, and we do not expect losses to materialize.
- This was not a protocol-level issue on DuskDS, and it does not affect the long-term security or architecture of the network.
What happened
Our monitoring and alerting detected behavior inconsistent with normal bridge operations, specifically involving a wallet managed by the team for operational purposes. As soon as this was detected, we treated the situation as security-critical and moved to contain risk before it could escalate.
During the response window, we identified a limited set of transactions connected to this activity. When we observed that part of the flow passed through Binance, we coordinated directly with their team to support the investigation and ensure the situation remained contained.
At this stage, and based on all available data and counterpart confirmations, no user funds were impacted.
Immediate actions taken
As soon as the activity was flagged, the team took precautionary action to reduce risk and prevent further exposure:
- Paused bridge services temporarily to stop any further bridging activity while we investigated
- Disabled and recycled a number of addresses associated with bridge operations
- Shipped a Web Wallet mitigation: a recipient blocklist that prevents transfers to known dangerous addresses (compromised / scam-related / sanctioned) and surfaces a clear blocking warning before a transaction can be submitted
- Coordinated with relevant external parties where the flow intersected centralized infrastructure
These actions were taken quickly to prioritize user safety and operational integrity.
Impact and scope
DuskDS mainnet has not been impacted. There was no protocol-level issue, and the network continues operating normally.
Bridge services remain temporarily paused while we complete a broader hardening pass.
While we did identify a small number of transactions during the incident window, we currently assess that users are not affected.
What we’re doing now
We’re completing a thorough security review across bridge and infrastructure components to strengthen operational security and remove any remaining risk before resuming services.
At a high level, this work includes:
- Confirming and tightening access controls across systems and services
- Strengthening monitoring, alerting, and operational safeguards
- Completing an additional hardening pass across bridge-related infrastructure
Bridge status and next steps
The bridge will remain temporarily closed until the review is concluded and we’re ready to safely resume operations. We’ll share a follow-up update once:
- the review is complete, and
- we have a confirmed plan and timeline for reopening bridge services and resuming the DuskEVM launch.
If you sent funds to the old bridge address
If you sent funds to the previously shared old BEP20 bridge address, please contact our support of Discord and include your transaction ID so the team can review your case.