xDAI Stake Bridge (Gnosis Chain)
The thin validator set supports rejection and remains a standing weakness. Gnosis Chain is an independent proof-of-stake EVM chain, not an Ethereum rollup, so its canonical bridge does not inherit Ethereum-native fraud-proof or validity-proof security the way every rollup bridge in this registry does. Instead, message execution requires signatures from only 4 of 7 bridge validators. That is a much smaller trust set than the already-rejected Wormhole/Portal’s 13-of-19 Guardian quorum, which suffered a $325M signature-forgery loss in 2022. A clean incident record to date does not offset a validator set this small securing an entire independent chain’s bridge with no cryptographic or economic backstop if those signatures were ever forged or the validators colluded.
- The message-signing threshold is confirmed to require mandatory trustless verification for every message, not optional redundancy alongside trusted signers
- The bridge validator set expands materially, for example doubling, with full public disclosure of validator identities and any conflicts of interest among the Bridge Governors
- Twelve consecutive months with no validator-signature compromise or forged-message incident, counted from this review’s date
- An independent, dated audit of the current validator-signing and governance-multisig configuration is published with no unresolved high-severity findings
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-17.
The research file
Mechanism
The bridge uses the Arbitrary Message Bridge design. A contract on the source chain emits an event, off-chain bridge validators observe it and submit signatures on the destination chain, and anyone can execute the message once the signature threshold is met. The Omnibridge, Gnosis Chain’s token bridge, is built on top of this same AMB mechanism and shares its validator set and trust model.
Control and governance
Message execution requires only 4 of 7 bridge validators. They include trusted entities (Gnosis DAO, Safe) and components described as trustless (Hashi, a message-hashing and attestation layer, and Telepathy, a ZK light-client verifier). This review could not confirm whether the trustless verification path is a mandatory gate or an optional check running alongside the trusted signers. Separately, 15 Bridge Governors control contract upgrades and bridge parameter changes and require 8-of-15 approval. Gnosis Safe multisigs on both the Ethereum and Gnosis Chain sides execute those decisions under a structure dating to October 2020.
Incident record
No confirmed direct exploit of the AMB or Omnibridge contracts was identified. Omnibridge and xDai bridge outflows were briefly halted as a precaution following the unrelated Balancer V2 exploit. This is evidence of a working pause capability, not a bridge-specific failure. Audits exist and are substantive: a ChainSecurity OmniBridge audit found no critical or high issues, and a Least Authority audit of the Hashi integration, completed 2024-06-27, found one high-severity issue among lower-severity findings, stated as resolved or acknowledged.
Exit
There is no optimistic-style challenge window. This is a signature-based bridge, not a fraud-proof or validity-proof system, so withdrawals process as soon as the 4-of-7 threshold is met, with fast underlying chain finality. That is a speed advantage in normal operation, but it also means there is no built-in delay in which a forged signature set could be caught before funds actually move. Correctness rests entirely on the honesty and security of seven named-but-not-fully-disclosed validators, not on a cryptographic or economic backstop independent of their good faith.
Comparison
Base, Arbitrum, and Optimism’s canonical bridges are all approved with limits in this registry. All inherit Ethereum-native fraud-proof or validity-proof security independent of any operator’s good faith. Gnosis Chain’s bridge is weaker because it depends entirely on a 7-node validator set, 4 of whom can execute any message. Compared with the already-rejected Wormhole/Portal, this bridge’s validator set is smaller still, though it has no comparable loss event on record. It has a thinner trust set with a cleaner history, not a thinner trust set with a worse one, but the standing weakness remains.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Gnosis Chain Docs — Omnibridge · primary · accessed 2026-08-17
Supports: mechanism - Gnosis Chain Docs — Arbitrary Message Bridge · primary · accessed 2026-08-17
Supports: AMB architecture - Gnosis Chain Docs — bridge validators · primary · accessed 2026-08-17
Supports: 4-of-7 signature threshold - Gnosis Chain Docs — bridge management · primary · accessed 2026-08-17
Supports: 15 Bridge Governors, 8-of-15 threshold - Gnosis Chain Docs — security audits · primary · accessed 2026-08-17
Supports: ChainSecurity and Least Authority audit findings
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Ethereum | Approved | No freeze key | No sequencer, no upgrade key, no operator who can be compelled. Rule changes require social consensus. |