It arrived at 2:14 a.m. Vienna time, as a screenshot in a direct message. A junior analyst I had mentored through the support circles of 2022 sent me a compensation notice from DYORSWAP, a cross-chain bridge I had never audited and, more tellingly, had never once seen referenced in the bridge research threads I follow weekly. Her question was the only question that mattered: is this real, and how much of it will I actually see?
I read it four times. On the first pass I noted the 40% figure. On the second I noticed the 5 ETH threshold. By the fourth pass I understood that the notice's most important content was everything that was not on the page. No loss amount. No root cause. No attacker address. No audit reference. No reserve statement. No legal entity, no jurisdiction, and no snapshot block height. A document whose entire purpose is to restore confidence had been written in a way that disclosed almost nothing about the event that destroyed it.
That absence is the story — and the story isn't in the token, it's in the trust.
To see why, you need the comparison set. Bridge incidents have a short, well-documented history, and the compensation notices that followed them fall into exactly two families. Family one: the bridge had a balance sheet behind it. When Wormhole lost roughly $326 million in February 2022, Jump Crypto replaced 120,000 ETH within weeks and the bridge kept operating. When Ronin lost about $624 million in March 2022, Sky Mavis raised capital and Binance contributed, and users were eventually made whole over a long, painful, publicly tracked process. When Poly Network was drained of more than $600 million in August 2021, the attacker returned essentially everything, which is the cheapest possible resolution and also the least repeatable.
Family two: the bridge had nothing behind it. Nomad lost roughly $190 million in August 2022 in the strangest exploit of that cycle — a one-line initialization failure that let anyone copy the attacker's transaction. Nomad did run a genuine recovery effort: a whitehat bounty, a pro-rata distribution, months of work. Users eventually recovered a majority of their funds. And the bridge still went to functionally zero and stayed there. The money came back. The flow never did.
Bridges deserve this level of scrutiny for a structural reason that regulators have now noticed in writing. A bridge is the only common piece of infrastructure in this industry that must hold custody of assets while remaining simultaneously reachable from multiple execution environments, which means its attack surface is the union of every chain it connects rather than the intersection. The Financial Action Task Force has flagged cross-chain services specifically for money-laundering exposure. The practical consequence is that bridges now sit at the meeting point of the two hardest problems in the space — custody and compliance — while frequently being run by the smallest teams. That asymmetry is exactly why a notice like this one should be read slowly.
That distinction between money and flow is the frame I bring to every post-incident notice, and it took a few years of reading these documents to build it. Based on my audit experience going back to the 2020 elastic-supply protocols, the discipline is to read a compensation notice as a balance sheet and an operations plan, not as a press release. What it promises matters less than what it implies about what the issuer had available and what it chose to withhold. Judged against that standard, the DYORSWAP notice is informative in a way it almost certainly did not intend.
Start with the arithmetic, because everything else is downstream of it. The notice settles affected addresses at a uniform 40%. In credit markets, a haircut of that magnitude is not a courtesy extended to creditors; it is the estate stating, in the only language that matters, that it cannot cover claims in full. Think about the incentives for a moment. For any bridge able to make claimants whole, paying 100% immediately is the single cheapest reputation purchase available at any price — it converts a catastrophe into a footnote, and it costs exactly what it would have cost to do nothing while losing the protocol. The only coherent reason to settle at 40% is that 100% is not available. A 60% haircut isn't a refund policy, it's a solvency disclosure — and it is the only hard number in the entire document.

Then read the tiering, because segmentation thresholds leak the user census that projects never publish. Addresses below 5 ETH receive batch treatment. Addresses above 5 ETH are pulled out for individual review. At prevailing prices that threshold sits somewhere in the five-figure dollar range, which is a startlingly low bar for a whale tier. Bridges that serve real institutional flow set their high-touch thresholds well above that, because their median deposit is above that. A bridge whose large-account category begins at five figures is describing, without meaning to, a retail user base: many small balances, very few large ones, and no counterparties significant enough to warrant a named relationship. That has a direct consequence for the payout question. The entities that rescued Wormhole and Ronin were large, capitalized, and reputationally exposed. The issuer of this notice is evidently none of those things, which means this is a settlement among small claimants rather than a rescue financed from above. The tier boundary is not a fairness mechanism; it's a map of who was actually using the bridge.
And on reserves specifically, the absence is more than a gap — it is an unforced communication failure. Proof of reserves is not a novel technology in 2026. It is a routine, well-understood attestation, and any treasury that can fund even a partial distribution can be pointed at by an address the public is free to read. If the funds exist, showing them costs nothing and buys more credibility than the entire notice. If showing them is not possible, that silence is the answer.

Now read the verbs, because attribution is where post-incident notices do their real work. The document attributes a portion of the losses to phishing and to fraudulent cross-chain activity. Both phrases place causation at the user end of the transaction. I want to be careful here, because user-side approval phishing is a genuine and rapidly growing vector — I have written about it and I do not consider it a fiction invented by guilty protocols. But attribution is a claim, and claims require artifacts: attacker addresses, transaction hashes, a timeline, ideally a third-party review. Post-mortems for the major bridge failures published attacker addresses within days, because the community demanded them and because the analysis had been done. Their absence here is not neutral. When a protocol names user error without publishing on-chain evidence, it is performing burden-shifting rather than forensics — and burden-shifting carries a second-order cost that is worse than the money.
I have watched that cost land on a community before. During the Ampleforth era, when a rebasing mechanic confused holders and the framing from the top of the Discord was that users had misread the documentation, the server did not turn its anger upward. It turned inward. Holders argued with each other about who had been careless, and the mutual aid that would have organized a coherent response dissolved into self-recrimination. The framing did not just shift blame. It consumed the community's capacity to act. Attribution is not accounting. It is governance, and it is usually the first governance decision a failing protocol makes.
Next, list what the notice never says, because for bridges that list is the whole technical picture. Audit status. Administrator key scope. Whether the validator set is permissioned or open. Proof of reserves. Legal entity and jurisdiction. Independent verification of the contact channels. Every major bridge exploit of the last five years traces back to the answer to the key question — Ronin's validator set and its five-of-nine signing structure, Wormhole's guardian signature verification, Nomad's initialization bug. Announcing a refund schedule while withholding the key architecture is like announcing a settlement without saying who was holding the instrument. It is technically a disclosure and practically a fog.

Then read the sentence the notice repeats. Some version of it appears three times: the official process will never ask you to transfer funds, sign a transaction, or pay a fee. Insurance companies do not print “we will not take your house” on their letterhead. That sentence exists because a targeting campaign is already underway or being staged right now — fake support accounts, fake claim portals, fake administrators in fake Telegram groups. The impersonation infrastructure will outrun the real process, for a structural reason: a scam requires no legal review, no wallet infrastructure, no treasury, and no disclosure obligations. My 2021 research into early meme ecosystems established the general mechanism — narratives precede utility in adoption. The fraud corollary is uglier. Narratives precede extraction too, and a compensation narrative is currently the highest-conversion fraud script in this industry.
Notice also what is missing that would be trivially easy to include: a snapshot block height. Every credible distribution in the history of this space has been anchored to a snapshot at a specific block, because that is the thing that converts a promise into a defined claim. Without a snapshot, the affected set is not formally defined — which means it remains redefinable, and no user holds a fixed, checkable entitlement. “Further details will be announced in due course” is not a roadmap. It is an option, held by one side.
And note the process itself. The 40% rate, the 5 ETH threshold, the review criteria, the absence of an appeal path — all set unilaterally, with no vote, no forum, no comment period. In my 2026 work on AI agent DAOs, one finding repeated with unusual consistency: systems that act without narrating why they act lose their communities faster than systems that act badly but explain themselves. Human committees behave the same way. A unilateral decision accompanied by no explanatory narrative delivers the worst of both worlds, and it tells you where the authority actually sits.
Now the part where I disagree with most of what I have just implied.
The industry's reflex response to a notice like this is a demand for more disclosure: publish the audit, publish the proof of reserves, publish the root cause. I do not think that is the lesson, and I do not think it would work.
Bridge trust is not a gradient. It is a step function. Users do not gradually trust a bridge, and they do not gradually stop — they route funds through it or they don't, and the transition between those two states happens in a single block. This is why the recovery arc after Nomad looked nothing like the recovery arc after a lending protocol's bad-debt event. Nomad ran a real recovery, returned real money, and never regained real flow. Lending markets and DEXs can rebuild after a loss because their trust accrues per transaction, and a good trade repairs a small piece of it. Bridges cannot, because their trust accrues per second of custody, and custody cannot be proven one transaction at a time. Two protocols can look identical on a TVL chart and behave nothing alike in a recovery. No amount of transparency rewinds a step function.
There is a second, less comfortable point. A 40% haircut may be more honest than the industry's standard promise of full reimbursement delivered as a fraction of it over three years. Several high-profile insolvencies proved that the loudest 100% pledges were narrative instruments rather than financial commitments, and I would rather see a protocol state a number it can fund than a number that polls well. But honesty does not move flow, and a solvency disclosure is still a solvency disclosure.
The genuine blind spot, in every take I have read on this event, is that everyone is analyzing the bridge while nobody is analyzing the classes of claimant the threshold creates. A holder under 5 ETH facing a 60% loss on a five-figure position has no lawyer, no forum, no collective action, and no leverage. They will accept the terms because there is nothing to negotiate with. The threshold is not a fairness curve. It is a cost-of-negotiation curve, and the people beneath it were always going to be the ones paying for it.
So watch the next narrative, because it is already forming and it is not about this bridge. Cross-chain is quietly consolidating away from third-party validator sets and toward canonical rollup withdrawals and intent-based routing, where a user never has to price the question of who is holding the keys mid-route. That shift will be sold as a cost and speed story. It is really a trust-elimination story, which is a far better product.
The other narrative forming underneath it is smaller and unglamorous: user-side verification as a social ritual. Reading the snapshot height. Checking the contract address. Confirming the channel through a second, independent source before typing anything at all. It is the crypto equivalent of looking both ways before crossing, and it is being taught right now by people nobody is paying.
Which leaves one question worth sitting with. When the compensation notice has become the most dangerous document in the industry — the thing scammers forge first — who is actually teaching users to read it? Not the protocols. It is almost always a moderator at two in the morning, in a channel with no budget. The story isn't in the token. It never was.