Skip to content

October 3, 2026

CRYPTO·COINBEAT

Journalism for the digital-asset economy

Ratings / DeFi & Infrastructure

Best Cross-Chain Bridges

Ranked on trust assumptions first: who has to be honest for your funds to arrive, and what happened last time.

8 services ratedLast verified August 12, 2026Methodology

Trust assumptions
40%
Who must behave honestly for funds to arrive, and how many of them there are.
Exploit history
25%
Past incidents, root causes, and whether the design that failed has changed.
Speed & cost
20%
Time to finality and total cost including relayer and gas fees.
Coverage
15%
Chains and assets supported with real liquidity behind them.

The table at a glance

8 rated · top score 9.2 · tap a row for the full entry

  1. 01AcrossFast transfers where the risk sits with a solver, not with you9.2
  2. 02Chainlink CCIPInstitutional transfers where defence in depth matters more than speed8.8
  3. 03Hop ProtocolRollup-to-rollup transfers with a simple, legible model8.5
  4. 04AxelarBroad chain coverage with a proof-of-stake validator set8.4
  5. 05EverclearNetting flows rather than moving collateral8.2
  6. 06SynapseLong-tail chains that canonical routes ignore8.2
  7. 07LayerZero / StargateWidest chain coverage and unified liquidity7.8
  8. 08WormholeNon-EVM chains, especially Solana routes7.8
Editor’s pickRank 01

Across

Fast transfers where the risk sits with a solver, not with you

An intents design where relayers front the destination funds and are reimbursed later against a canonical settlement layer, so the user is not exposed to the bridging window. Fast, cheap, and no exploit history to date.

In its favour

  • Solvers absorb the bridging risk instead of the user
  • Very fast settlement with low fees
  • No security incidents since launch

Against it

  • Chain coverage is narrower than the messaging giants
  • Depends on solver capital being available for large transfers
  • Launched2021
  • ModelIntent-based, solver-fronted
  • IncidentsNone to date
Score9.2

The weighted mean of the 4 axes below — each read from the fact printed beside it.

Strongest
Trust assumptions9.4
Weakest
Coverage8.0

Scorecard — and what it was read from

Trust assumptions
9.4
Relayers pay the user on the destination chain from their own capital and are reimbursed later through a canonical settlement layer, so the user is not exposed during the bridging window; disputes resolve through an optimistic oracle.
Exploit history
9.4
No security incident affecting user funds on record since 2021; audits published.
Speed & cost
9.4
Delivery on major routes typically completes in seconds to minutes, with fees published per route as a relayer fee plus gas.
Coverage
8.0
Covers Ethereum and the major rollups; the chain list is narrower than the general messaging protocols.

Read the full Across review →

The rest of the table

Institutional transfers where defence in depth matters more than speed

A messaging protocol with an independent risk management network that can halt transfers it judges anomalous, plus rate limits per lane. Deliberately conservative, which shows up as slower and pricier transfers.

In its favour

  • Independent risk network can halt anomalous transfers
  • Per-lane rate limits cap the damage from any single failure
  • No security incidents since launch

Against it

  • Slower and more expensive than consumer-focused bridges
  • Node operator set is permissioned
  • Launched2023
  • ModelMessaging with independent risk network
  • IncidentsNone to date

Scorecard — and what it was read from

Trust assumptions
9.2
Messages are verified by a decentralised oracle network with a separate risk management network able to halt transfers, plus per-lane rate limits that cap what any single failure can move.
Exploit history
9.2
No security incident on record since the 2023 launch; audits published.
Speed & cost
7.6
Slower and more expensive than consumer bridges by design, with fees published per lane.
Coverage
8.4
Supported chain list is smaller than the largest messaging protocols but covers the major networks.

Full Chainlink CCIP review →

Score8.8

Rollup-to-rollup transfers with a simple, legible model

Uses bonded liquidity providers to front transfers between rollups and settles through canonical bridges, which keeps the trust model small and easy to explain. Coverage is limited to the Ethereum rollup ecosystem.

In its favour

  • Settles through canonical rollup bridges
  • Simple, legible trust model with bonded relayers
  • No exploit history

Against it

  • Limited to Ethereum and its rollups
  • Liquidity constraints on larger transfers
  • Launched2021
  • ModelBonded liquidity, canonical settlement
  • IncidentsNone

Scorecard — and what it was read from

Trust assumptions
8.8
Bonded liquidity providers front transfers between rollups and settle through the canonical bridges, so the fallback is the rollup's own security.
Exploit history
9.0
No exploit on record since 2021; audits published.
Speed & cost
8.4
Fast on supported rollup routes, with fees published as a bonder fee plus gas.
Coverage
7.0
Limited to Ethereum and its rollups.

Full Hop Protocol review →

Score8.5

Broad chain coverage with a proof-of-stake validator set

Secures cross-chain messages with its own proof-of-stake validator set rather than a multisig, which is a meaningfully better trust model at similar coverage. Validator concentration is the open question.

In its favour

  • Proof-of-stake validator set with economic security
  • Very wide chain coverage including non-EVM networks
  • No major exploit to date

Against it

  • Security ultimately depends on validator-set decentralisation
  • Transfers route through an intermediate chain, adding latency
  • Launched2022
  • ModelPoS validator network
  • IncidentsNone major

Scorecard — and what it was read from

Trust assumptions
8.6
Cross-chain messages are secured by a proof-of-stake validator set with publicly measurable stake distribution rather than by a fixed multisig.
Exploit history
8.0
No exploit of the core validator network on record; two 2026 incidents hit contracts connected to it — a modified receiving contract on Secret Network drained for $4.67m over seven days before anyone noticed, and roughly $3m taken from CrossCurve through spoofed cross-chain messages. Validator concentration is measurable on-chain.
Speed & cost
8.0
Routing through the intermediate chain adds its finality to the transfer time; fees published per route.
Coverage
9.2
Very wide chain coverage including non-EVM networks.

Full Axelar review →

Score8.4

Netting flows rather than moving collateral

Rebuilt from Connext into a clearing layer that nets opposing cross-chain flows instead of locking collateral, which removes the honeypot that most bridge exploits targeted. The model is newer and adoption is still building.

In its favour

  • Netting design avoids large pooled collateral
  • Long operating lineage with no user-fund exploit
  • Structurally different risk profile from lock-and-mint bridges

Against it

  • Newer clearing model with limited production history
  • Aimed at protocols and solvers more than end users
  • Launched2020 (as Connext)
  • ModelCross-chain netting and clearing
  • IncidentsNone affecting user funds

Scorecard — and what it was read from

Trust assumptions
8.4
Nets opposing cross-chain flows rather than locking a large collateral pool, which removes the concentrated honeypot that most bridge exploits targeted.
Exploit history
8.4
No exploit affecting user funds on record across its Connext lineage since 2020; audits published.
Speed & cost
7.8
Settlement is organised around netting epochs rather than instant delivery, so a one-off transfer is slower.
Coverage
7.6
Aimed at protocols and solvers; chain coverage is narrower than the messaging giants.

Full Everclear review →

Score8.2

Long-tail chains that canonical routes ignore

Broad coverage including smaller chains that better-secured bridges skip, using a liquidity-pool model with an optimistic verification layer. Useful reach, average trust assumptions.

In its favour

  • Covers many chains that canonical routes do not reach
  • Fast transfers backed by liquidity pools
  • No major protocol exploit

Against it

  • Validator and verification model is less robust than the leaders
  • Liquidity on smaller chains can be thin
  • Launched2021
  • ModelLiquidity pools with optimistic verification
  • IncidentsNone major

Scorecard — and what it was read from

Trust assumptions
7.8
Transfers are backed by liquidity pools with an optimistic verification layer and a permissioned validator set.
Exploit history
8.2
No major protocol exploit on record; audits published.
Speed & cost
8.6
Fast delivery with fees published per route; costs rise on thin routes.
Coverage
8.8
Covers many smaller chains that canonical routes do not reach.

Full Synapse review →

Score8.2

Widest chain coverage and unified liquidity

The most widely deployed messaging layer in crypto, with Stargate providing unified liquidity for transfers on top of it. Security depends on the configuration each application chooses, which is flexible for developers and opaque for users.

In its favour

  • Broadest chain coverage of any messaging protocol
  • Unified liquidity pools give predictable transfer pricing
  • No protocol-level exploit to date

Against it

  • An application's adapter configuration was the vector for the $292m Kelp exploit in April 2026
  • Security varies by application configuration and is hard for a user to inspect
  • Launched2022
  • ModelConfigurable messaging plus liquidity layer
  • IncidentsNone at protocol level

Scorecard — and what it was read from

Trust assumptions
7.2
Security depends on the verifier configuration each application chooses; the default set is documented, but an application can run a weaker one and the user cannot see which applies to their transfer. Kelp DAO's adapter ran a single-point verification setup, which is how $292m of unbacked rsETH was minted in April 2026.
Exploit history
6.8
No exploit of the messaging protocol's own contracts on record — and the largest DeFi loss of 2026 still came through an application's LayerZero adapter, which is exactly the risk this configurable design pushes onto integrators.
Speed & cost
9.0
Fast delivery with unified liquidity pools and fees published per route.
Coverage
9.6
Broadest chain coverage of any messaging protocol.

Full LayerZero / Stargate review →

Score7.8

Non-EVM chains, especially Solana routes

The best coverage of non-EVM ecosystems and the only serious option for several Solana routes, rebuilt substantially since its 2022 exploit. That incident, one of the largest in crypto history, still sets the ceiling on its score here.

In its favour

  • Unrivalled non-EVM chain coverage
  • Substantially rearchitected and heavily audited since 2022
  • Fast transfers with deep liquidity on major routes

Against it

  • Suffered one of the largest bridge exploits ever recorded
  • Guardian set is permissioned and relatively small
  • Launched2021
  • ModelGuardian-attested messaging
  • IncidentsMajor exploit in 2022, funds replaced

Scorecard — and what it was read from

Trust assumptions
7.6
Messages are attested by a guardian set of named operators — a permissioned quorum rather than an open validator set.
Exploit history
6.4
A February 2022 exploit minted roughly $320m of wrapped ETH on Solana through a signature-verification flaw; the funds were replaced by Jump Crypto and the codebase was substantially rearchitected and re-audited.
Speed & cost
8.8
Fast delivery on major routes with fees published per route.
Coverage
9.6
Unrivalled non-EVM coverage including Solana, Sui, Aptos and Cosmos-family chains.

Full Wormhole review →

Score7.8

↑ Back to the table at a glance

What the record supports

Across has the best risk model in the category — solvers front the capital, so the person carrying the bridging risk is not the user. CCIP and Axelar are the reasonable institutional answers. And 2026 restated the oldest rule in this table from a new angle: the year's largest DeFi loss came not from a bridge being drained but from a bridge being told to mint, through a verification setup an integrator had configured down to a single point. Bridge only what you are about to use, and never treat a bridge as a place to leave value.

A conclusion drawn from the facts above, and the only part of this page that is.

How a score is read

Each axis is read off the same five bands. They describe what is on the record, not how impressed we are.

9.0–10
Documented and independently verifiable
The claim is evidenced by a published record a third party can check — an attestation, an on-chain contract, a regulator's register — and nothing adverse is on file.
8.0–8.9
Documented, with gaps
Evidence exists but is partial, dated, or covers only part of what the axis measures.
7.0–7.9
Self-reported only
The operator publishes the information and no independent party has verified it.
6.0–6.9
Adverse event on record
A recorded incident, enforcement action or failure that has since been resolved, remediated or repaid.
Below 6
Undocumented or unresolved
No published evidence, or an incident with no resolution on the record. An absence of evidence is scored as an absence.

How we scored this table

Bridges have lost more user funds than any other category in crypto, and the losses clustered in one design: a large pool of collateral behind a small set of signers. The first fact recorded here is therefore the trust assumption — who must act honestly for funds to arrive, and how many of them there are.

Exploit history is recorded with amount, root cause and outcome, and weighted against what changed afterwards. A protocol drained through key management that then moved to a different trust model has a different record from one that patched a single bug.

Speed and cost are recorded from completed transfers on the main routes rather than from marketing claims, and coverage counts routes with liquidity actually available. Speed never offsets a weak trust assumption in the weighting.

  • Every score on this page carries the fact it was read from, printed beside the bar.
  • Designs where users can exit without permission are recorded as such.
  • Where security depends on a configuration each application chooses, that is recorded as a fact about the user's visibility.

What each axis records, and where the facts come from

Trust assumptions40%
Who must act honestly for funds to arrive — a multisig, a validator set, a solver or the chains themselves; how many parties that is; and whether a user can exit without permission.
Source: Deployed contract code and signer sets, validator documentation, protocol specifications.
Exploit history25%
Every recorded incident with amount, root cause and whether users were made whole, and whether the design that failed has since changed.
Source: Incident post-mortems, on-chain recovery records, subsequent audits.
Speed & cost20%
Observed time to delivery and total cost including relayer and gas fees on the main routes.
Source: Completed transfer records, published fee schedules.
Coverage15%
Chains and assets supported with liquidity actually available on the route.
Source: Protocol route lists, on-chain liquidity and quoted transfers.

Frequently asked questions

Why have bridges been exploited so often?+

Because most of them concentrate a large pool of collateral behind a small set of signers or an off-chain validator quorum. That is a single high-value target with a smaller attack surface than the chains it connects.

What does an intent-based bridge do differently?+

A solver pays you on the destination chain from their own capital and is reimbursed afterwards. The waiting risk sits with the solver rather than with you, which is a materially better position for the user.

Is the official bridge for a rollup safer?+

Usually yes for withdrawals, because it inherits the rollup's security rather than adding a third party. The cost is the challenge period — often a week on optimistic rollups — which is why fast third-party bridges exist at all.

How should I use bridges safely?+

Move what you need for the transaction you are about to make, prefer canonical routes when time allows, and never leave a balance sitting in a wrapped representation you would not want to hold if the bridge failed.

More in DeFi & Infrastructure