Avalanche Bridge
Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.
REJECTED ON A FOUR-PARTY COMMITTEE SMALLER THAN EVERY OTHER MULTI-PARTY BRIDGE THIS REGISTRY HAS REVIEWED. The Avalanche Bridge, Avalanche’s original Ethereum-to-C-Chain canonical bridge accessed through the Core wallet, secures transfers with only four ”Wardens” using an Intel SGX secure-enclave design; three of the four must report identical transaction data before the enclave mints or releases funds. That approval set is smaller than the already-rejected Gnosis Chain xDAI Stake Bridge’s 4-of-7 validators, and one of the four Wardens is Ava Labs itself, the same organization that built and operates the underlying network — a related-party concentration point none of this registry’s other reviewed bridges carry in the same form. It also adds a distinct hardware-trust dependency, Intel SGX attestation, on top of Warden honesty.
- The Warden committee expands materially, for example to seven or more independent parties, with no single approving party also operating the underlying network
- An independent, dated security audit of the current SGX enclave configuration and Warden software is published with no unresolved high-severity findings
- The bridge migrates to a design backed by an Ethereum-native fraud-proof or validity-proof system, removing dependence on Warden honesty and SGX hardware attestation
- Twelve consecutive months with no Warden-collusion, SGX side-channel, or enclave-compromise incident
The research file
Mechanism
This is Avalanche’s original Ethereum-to-C-Chain bridge, distinct from Avalanche’s newer Interchain Messaging primitive built for its own subnet ecosystem. Four Wardens — each running an indexing server plus AvalancheGo and Geth nodes — monitor both chains and relay transaction data into an Intel SGX secure enclave. The enclave’s private key is split via Shamir Secret Sharing across the four Wardens, so no single Warden holds it outright, but consensus among only three of the four is sufficient to act.
Control and governance
The four Wardens are Avascan, BwareLabs, Halborn, and Ava Labs itself — meaning one of the four parties securing the bridge is the same organization that built and operates the underlying network, a related-party concentration point this review flags directly. Approval requires three of the four Wardens, a 75% threshold of a four-member committee, reporting identical transaction data before the enclave mints or releases funds. That is a smaller total committee than the already-rejected Gnosis Chain xDAI Stake Bridge’s 4-of-7 validator set, and it layers a second, independent trust assumption on top of Warden honesty: the integrity of Intel SGX hardware attestation, a technology with a documented industry history of side-channel vulnerabilities, not confirmed exploited against this specific bridge but a standing structural dependency regardless.
Incident record
No confirmed exploit of this specific Avalanche Bridge was identified, including against a targeted check of the major 2026 bridge-hack wave already covered elsewhere in this registry, such as the Kelp DAO and Drift Protocol exploits, neither of which named this bridge. Absence of an incident is a bounded negative finding, not proof of durability, given the committee’s small size.
Exit
Transfers take roughly 10 to 15 minutes, dominated by Ethereum finality rather than any Avalanche-side delay — fast under normal conditions, but with no fraud-proof or validity-proof backstop the way rollup bridges have. Correctness rests entirely on three of four Wardens and SGX enclave attestation holding, not on an independent cryptographic or economic guarantee.
Comparison
Against Base, Arbitrum, and Optimism, all approved with limits in this registry and all inheriting Ethereum-native fraud-proof or validity-proof security, this bridge has no rollup-style proof system at all. Against the already-rejected Gnosis Chain xDAI Stake Bridge, this bridge’s 3-of-4 committee is smaller still, and its SGX hardware-trust layer is a distinct risk Gnosis’s bridge does not carry. One of the four approving parties being the network’s own operator is a related-party fact neither Gnosis’s nor the already-rejected Wormhole’s validator sets share in the same way.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- LI.FI — Avalanche Bridge: a deep dive · secondary · accessed 2026-08-17
Supports: Warden architecture, 3-of-4 threshold, Shamir Secret Sharing, withdrawal timing - Avalanche — Avalanche Bridge: secure cross-chain asset transfers using Intel SGX · primary · accessed 2026-08-17
Supports: Warden identities, SGX enclave design - Avalanche Builder Hub — bridge architecture · primary · accessed 2026-08-17
Supports: distinction from Interchain Messaging - Avalanche Builder Hub — bridge hacks · primary · accessed 2026-08-17
Supports: incident-pattern context - CCN — biggest DeFi hacks and exploits of 2026 · secondary · accessed 2026-08-17
Supports: confirms this bridge not named among major 2026 incidents
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Ethereum | Approved | sovereign | No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus. |