Bridge Services Incident Notice

bridge incident notice

Over the past few days, our monitoring systems detected unusual activity involving a team-managed wallet used in bridge operations.

Summary

  • Our monitoring flagged suspicious behavior tied to a team-managed wallet.
  • As a precaution, we disabled and recycled a set of related addresses and temporarily paused bridge services.
  • A small number of transactions occurred during the window in question.
  • We coordinated quickly with Binance after identifying that part of the flow touched their platform.
  • Based on all information available at this time, no user funds were impacted, and we do not expect losses to materialize.
  • This was not a protocol-level issue on DuskDS, and it does not affect the long-term security or architecture of the network.

What happened

Our monitoring and alerting detected behavior inconsistent with normal bridge operations, specifically involving a wallet managed by the team for operational purposes. As soon as this was detected, we treated the situation as security-critical and moved to contain risk before it could escalate.

During the response window, we identified a limited set of transactions connected to this activity. When we observed that part of the flow passed through Binance, we coordinated directly with their team to support the investigation and ensure the situation remained contained.

At this stage, and based on all available data and counterpart confirmations, no user funds were impacted.

Immediate actions taken

As soon as the activity was flagged, the team took precautionary action to reduce risk and prevent further exposure:

  • Paused bridge services temporarily to stop any further bridging activity while we investigated
  • Disabled and recycled a number of addresses associated with bridge operations
  • Shipped a Web Wallet mitigation: a recipient blocklist that prevents transfers to known dangerous addresses (compromised / scam-related / sanctioned) and surfaces a clear blocking warning before a transaction can be submitted
  • Coordinated with relevant external parties where the flow intersected centralized infrastructure

These actions were taken quickly to prioritize user safety and operational integrity.

Impact and scope

DuskDS mainnet has not been impacted. There was no protocol-level issue, and the network continues operating normally.

Bridge services remain temporarily paused while we complete a broader hardening pass.

While we did identify a small number of transactions during the incident window, we currently assess that users are not affected.

What we’re doing now

We’re completing a thorough security review across bridge and infrastructure components to strengthen operational security and remove any remaining risk before resuming services.

At a high level, this work includes:

  • Confirming and tightening access controls across systems and services
  • Strengthening monitoring, alerting, and operational safeguards
  • Completing an additional hardening pass across bridge-related infrastructure

Bridge status and next steps

The bridge will remain temporarily closed until the review is concluded and we’re ready to safely resume operations. We’ll share a follow-up update once:

  • the review is complete, and
  • we have a confirmed plan and timeline for reopening bridge services and resuming the DuskEVM launch.

If you sent funds to the old bridge address

If you sent funds to the previously shared old BEP20 bridge address, please contact our support of Discord and include your transaction ID so the team can review your case.