Screen the bridge contract and the destination wallet before you send funds cross-chain - a bridge transaction can carry contamination you never chose to touch.
On August 1, 2022, one bug in Nomad's cross-chain bridge let anyone copy the same exploit transaction and drain funds straight from the contract. Almost 300 different wallets walked away with pieces of the $190 million taken that day. Some of them set out to steal it. Plenty just copied a transaction they saw trending and figured it was free money. Every one of those addresses carries that bridge exploit in its history now, and it shows up the moment anyone runs a screening check against it.
Most bridge users never touch an exploit directly. But the same mechanics that let 300 strangers loot Nomad in an afternoon - shared contracts, pooled liquidity, wrapped assets minted against a reserve you can't see - are what quietly link an honest transfer to funds you've never heard of. Run this checklist before you bridge, not after a deposit gets held for review.
Before you start
A bridge doesn't move your original tokens across chains. It locks them on the source chain and mints a wrapped equivalent on the destination chain, backed by whatever sits in that bridge's reserve contract. If the reserve is fine, nobody notices. If the reserve is compromised or drained - Multichain's contracts moved $126 million out with no explanation in July 2023, freezing transfers mid-flight - your wrapped asset inherits that mess the second it lands in your wallet.
The same pooled-liquidity design means a bridge contract that has processed a hack payout, a mixer withdrawal, or an OFAC-listed address shares that history with everyone who used it around the same time. Screening tools read proximity on-chain, not intent. Being three transactions away from a designated address reads as exposure whether you knew about it or not.
Four checks stand between a bridge transfer and a flagged wallet: screen the destination, check the bridge's history, confirm the reserve, then screen again after.
The checklist
Run these in order, before you approve the transfer, not after the wrapped tokens show up.
Screen the destination wallet you're bridging into, on the destination chain itself, not just the source chain.
A wallet clean on Ethereum can still carry exposure on Base, Arbitrum, or wherever the tokens are headed.
Check the bridge contract's own history for a prior hack, exploit, or governance freeze.
Nomad, Multichain, Wormhole, and Ronin all have public incident histories - look before you assume popular means safe.
Confirm the bridge's reserve is fully collateralized before moving anything above a small test amount.
Some bridges publish reserve dashboards; if one doesn't, that's a signal on its own.
Send a small test transfer first and screen the wrapped token you receive before sending the rest.
Wrapped assets from a compromised reserve can trade below face value, or freeze outright.
Screen your own source wallet for prior exposure before you bridge, not just the destination.
A bridge transaction pairs your two addresses in every future trace - clean up exposure before you create that link.
Check whether the receiving exchange or protocol accepts bridged assets from that specific bridge.
Some platforms flag every deposit routed through a bridge tied to a past exploit, regardless of your own history.
Re-screen the destination wallet after the transfer confirms, before you move the funds anywhere else.
A clean pre-check doesn't account for what else touched that bridge contract in the minutes around your transaction.
Why does a clean bridge transfer still get flagged?
Most people run the destination address through Etherscan before bridging and call that due diligence. That shows raw transaction history - what moved, when, from where - and nothing about sanctions exposure, mixer contact, or stolen-funds history layered across six other chains. Screen the wallet with Plastron instead, and get one risk score that covers all of it before you commit funds.
Chainalysis puts the scale of the problem plainly: bridge protocols received $743.8 million in crypto from illicit addresses in 2023, up from $312.2 million the year before - a 138 percent jump, much of it routed through the same bridge contracts everyday users rely on. Plastron's labeled address set carries 3,901 entries pulled from real scam, hack, and sanctions cases, including 121 tied specifically to bridge and protocol hack exploits, plus the full 780-address OFAC sanctions list checked on every scan. None of that history announces itself in a wallet's balance. It only shows up when something checks for it.
Plastron's dataset: 3,901 labeled addresses, 121 tied to bridge and protocol hack exploits, plus the full 780-address OFAC sanctions list checked on every scan.
Proximity isn't guilt. It isn't nothing, either. Compliance teams downstream don't know your intentions - they only see what the graph shows.
What do you do if you already bridged something risky?
Stop moving the funds again first. Every additional hop adds another link for a screening tool to trace, and moving fast rarely outruns a flag that's already attached to an address. Screen the wallet you bridged into and read exactly what triggered the exposure - a specific incident, a mixer hop, a sanctioned counterparty - rather than guessing.
If the exposure traces back to the bridge contract itself rather than anything you did, document that: the bridge's own incident disclosure, the transaction hash, and the timestamp. Exchanges reviewing a hold usually want to see the exposure sits at the protocol layer, not in your wallet's own transaction history. If it's a false positive from bridge-wide contamination, that paper trail is what gets a hold lifted instead of extended.
FAQ
Does bridging crypto always increase a wallet's risk score?
No. Screening tools weigh proximity and severity, not the act of bridging itself. A transfer through a bridge with a clean incident history and no contact with flagged addresses around your transaction shouldn't move your score much at all. The risk comes from which bridge, when, and what else touched that contract nearby - not from cross-chain movement on its own.
Can you undo a bridge transaction if the destination wallet turns out to be risky?
Not on-chain. Bridge transfers are final once confirmed, the same as any other blockchain transaction. What you can do is stop, screen before sending the remainder of your funds, and route the next transfer to a fresh wallet if the one you used already shows exposure - keeping the problem from compounding.
Do all bridges carry the same contamination risk?
No. A bridge's risk profile depends on its security history, how its reserve is collateralized, and how much volume from hacked or sanctioned addresses has passed through it. Ronin, Nomad, Wormhole, and Multichain all show up in incident trackers for different reasons - some for pure exploits, some for operational failures. Checking a specific bridge's history takes minutes and tells you more than its brand name does.
Does a wallet-screening tool see exposure on every chain a bridge touches?
Only if it's built to. Plastron screens Ethereum plus six other EVM chains - Arbitrum, Base, Optimism, Polygon, BNB Chain, and Avalanche - so a bridge transfer between any of those shows up on both ends of the trip, not just the chain you started from.
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.