Thirdweb Bridge Hack
Check if your address is affected.
thirdweb is a platform that offers tools for developers building blockchain apps. One of its products is a Bridge that helps move and swap tokens across chains, which developers could build into their apps and which users approved to spend their tokens. On 10 April 2025, thirdweb found a flaw that let outsiders misuse the token approvals given to its Bridge contracts. It paused the affected contract and rolled out a fix the same day, but an older deployment of the same code was never shut down and stayed vulnerable.
Attackers used that legacy contract to take about $34k in USDC on Ethereum, in three transactions between April and December 2025. After suspicious activity was reported on 10 December 2025, thirdweb confirmed the exploit and disabled the legacy contract on all supported chains the next day. Its incident report does not mention any reimbursement. thirdweb said its tools approve only the amount needed by default, so mainly users who had given larger or unlimited approvals were exposed.
The newer Bridge contract was fixed in April 2025 and the legacy one has since been disabled, but the approvals users gave to both of them are still active. If you ever approved either Bridge contract on any chain, revoking those approvals is the safest option. Revoking protects what is still in your wallet, but it does not recover tokens that were already taken.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →